{"timestamp": "2026-06-09T11:00:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=193.27.228.114 dport=443 bytes=310 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-09T11:01:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=193.27.228.114 dport=443 bytes=473 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-09T11:02:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=193.27.228.114 dport=443 bytes=807 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-09T11:03:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=193.27.228.114 dport=443 bytes=498 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-09T11:04:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=193.27.228.114 dport=443 bytes=830 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-09T11:04:50", "source": "nginx", "category": "benign", "severity": "info", "message": "39.112.216.61 - - \"GET /health HTTP/1.1\" 200 4404", "src_ip": "39.112.216.61", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T11:05:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=193.27.228.114 dport=443 bytes=738 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-09T11:05:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.45 port 54240 ssh2", "src_ip": "10.0.2.45", "user": "root", "action": "login_success"} {"timestamp": "2026-06-09T11:06:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.75 port 55468 ssh2", "src_ip": "10.0.1.75", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-09T11:06:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=193.27.228.114 dport=443 bytes=273 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-09T11:07:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=193.27.228.114 dport=443 bytes=827 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-09T11:07:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.91 port 49282 ssh2", "src_ip": "10.0.1.91", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-09T11:13:39", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "nattapong", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-09T11:13:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 43826 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:13:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 56511 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:13:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 42459 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:13:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 46335 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:13:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 41570 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:13:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 52294 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:13:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 49602 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:14:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 50972 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:14:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 41834 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:14:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 49150 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 54583 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 40264 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 53838 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 51258 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 52552 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 43356 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 50267 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 42320 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 52541 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 44681 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 44331 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:15:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 57383 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 49805 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 42840 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 44587 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 59319 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 51507 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 54496 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 40277 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 45377 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 54070 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 46981 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 44960 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:16:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 52583 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-09T11:17:48", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 200 391", "src_ip": "185.220.101.34", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T11:18:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.179 port 59191 ssh2", "src_ip": "10.0.4.179", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-09T11:22:16", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.188 dst=91.219.236.18 bytes=3165650944 proto=TCP dport=443 duration=166s", "src_ip": "10.0.5.188", "dst_ip": "91.219.236.18", "bytes_mb": 3019, "off_hours": false} {"timestamp": "2026-06-09T11:27:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=174.57.148.115 OUT= PROTO=TCP DPT=80", "src_ip": "174.57.148.115", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T11:30:06", "source": "nginx", "category": "benign", "severity": "info", "message": "152.82.213.216 - - \"GET /health HTTP/1.1\" 200 5245", "src_ip": "152.82.213.216", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T11:33:38", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.5.135 port 52646 ssh2", "src_ip": "10.0.5.135", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-09T11:34:47", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.2.39 port 52799 ssh2", "src_ip": "10.0.2.39", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-09T11:35:37", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 381", "src_ip": "209.141.56.12", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-09T11:41:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=145.201.49.205 OUT= PROTO=TCP DPT=443", "src_ip": "145.201.49.205", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T11:43:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.100 port 58602 ssh2", "src_ip": "10.0.0.100", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T11:43:15", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 200 115", "src_ip": "45.137.21.9", "status": 200, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T11:44:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.17 port 43883 ssh2", "src_ip": "10.0.4.17", "user": "root", "action": "login_success"} {"timestamp": "2026-06-09T11:45:16", "source": "nginx", "category": "benign", "severity": "info", "message": "168.209.209.26 - - \"GET /static/app.js HTTP/1.1\" 200 3727", "src_ip": "168.209.209.26", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T11:53:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=664 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:54:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=540 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:54:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=771 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:54:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=879 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:54:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=764 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:54:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.249 port 45864 ssh2", "src_ip": "10.0.2.249", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-09T11:55:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=265 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:55:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=504 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:55:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=144.46.62.65 OUT= PROTO=TCP DPT=80", "src_ip": "144.46.62.65", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T11:55:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=795 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:55:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=779 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:56:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=413 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:56:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=489 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:56:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=457 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:56:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=874 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:57:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=585 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:57:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=791 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:57:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=455 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:57:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=824 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:58:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.113 dst=185.220.101.34 dport=443 bytes=728 interval=30s", "src_ip": "10.0.4.113", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-09T11:58:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=826 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:58:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.97 dst=91.219.236.18 dport=443 bytes=609 interval=30s", "src_ip": "10.0.3.97", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-09T11:59:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=55.88.142.241 OUT= PROTO=TCP DPT=443", "src_ip": "55.88.142.241", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T12:00:58", "source": "nginx", "category": "benign", "severity": "info", "message": "43.230.49.10 - - \"GET /login HTTP/1.1\" 200 6308", "src_ip": "43.230.49.10", "status": 200, "path": "/login"} {"timestamp": "2026-06-09T12:20:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.18 port 53818 ssh2", "src_ip": "10.0.0.18", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-09T12:21:44", "source": "nginx", "category": "benign", "severity": "info", "message": "98.11.94.246 - - \"GET /static/app.js HTTP/1.1\" 200 971", "src_ip": "98.11.94.246", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T12:27:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=137.95.72.135 OUT= PROTO=TCP DPT=443", "src_ip": "137.95.72.135", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T12:33:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.1.47 port 56972 ssh2", "src_ip": "10.0.1.47", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-09T12:38:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=105.71.37.201 OUT= PROTO=TCP DPT=443", "src_ip": "105.71.37.201", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T12:39:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=128.168.152.91 OUT= PROTO=TCP DPT=80", "src_ip": "128.168.152.91", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T12:42:53", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "deploy", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-09T12:48:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=106.41.56.226 OUT= PROTO=TCP DPT=80", "src_ip": "106.41.56.226", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T12:50:36", "source": "nginx", "category": "benign", "severity": "info", "message": "141.240.253.42 - - \"GET /login HTTP/1.1\" 200 737", "src_ip": "141.240.253.42", "status": 200, "path": "/login"} {"timestamp": "2026-06-09T12:52:23", "source": "nginx", "category": "benign", "severity": "info", "message": "174.139.212.45 - - \"GET /static/app.js HTTP/1.1\" 200 3985", "src_ip": "174.139.212.45", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T12:54:15", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 403 225", "src_ip": "45.137.21.9", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T13:00:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=256 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:01:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=285 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:01:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=534 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:02:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=634 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:02:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=275 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:03:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=625 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:03:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=272 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:04:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=799 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:04:07", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "guest", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-09T13:04:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=670 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:04:41", "source": "nginx", "category": "benign", "severity": "info", "message": "205.143.33.6 - - \"GET / HTTP/1.1\" 200 5994", "src_ip": "205.143.33.6", "status": 200, "path": "/"} {"timestamp": "2026-06-09T13:05:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=45.137.21.9 dport=443 bytes=397 interval=30s", "src_ip": "10.0.5.22", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-09T13:06:27", "source": "nginx", "category": "benign", "severity": "info", "message": "208.247.252.11 - - \"GET /dashboard HTTP/1.1\" 200 4236", "src_ip": "208.247.252.11", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-09T13:10:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=148.241.64.227 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "148.241.64.227", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T13:10:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=148.241.64.227 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "148.241.64.227", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T13:10:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=148.241.64.227 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "148.241.64.227", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T13:10:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=148.241.64.227 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "148.241.64.227", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T13:10:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=148.241.64.227 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "148.241.64.227", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T13:10:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=148.241.64.227 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "148.241.64.227", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T13:10:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=148.241.64.227 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "148.241.64.227", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T13:10:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=148.241.64.227 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "148.241.64.227", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T13:11:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.218 port 54307 ssh2", "src_ip": "10.0.5.218", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-09T13:15:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.91 port 56525 ssh2", "src_ip": "10.0.1.91", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T13:24:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.208 port 50009 ssh2", "src_ip": "10.0.4.208", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-09T13:25:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.128 port 43024 ssh2", "src_ip": "10.0.3.128", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-09T13:29:34", "source": "nginx", "category": "benign", "severity": "info", "message": "54.139.10.129 - - \"GET /static/app.js HTTP/1.1\" 200 7530", "src_ip": "54.139.10.129", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T13:31:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=127.132.155.219 OUT= PROTO=TCP DPT=80", "src_ip": "127.132.155.219", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T13:38:40", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 435", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T13:41:13", "source": "nginx", "category": "benign", "severity": "info", "message": "30.252.108.162 - - \"GET /health HTTP/1.1\" 200 5809", "src_ip": "30.252.108.162", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T13:41:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=54.42.255.217 OUT= PROTO=TCP DPT=443", "src_ip": "54.42.255.217", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T13:42:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T13:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T13:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T13:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T13:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T13:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T13:42:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T13:42:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T13:46:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=19.170.166.28 OUT= PROTO=TCP DPT=80", "src_ip": "19.170.166.28", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T13:50:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=217.35.43.87 OUT= PROTO=TCP DPT=443", "src_ip": "217.35.43.87", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T13:59:37", "source": "nginx", "category": "benign", "severity": "info", "message": "23.45.132.86 - - \"GET /dashboard HTTP/1.1\" 200 5069", "src_ip": "23.45.132.86", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-09T14:01:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=13.34.6.106 OUT= PROTO=TCP DPT=80", "src_ip": "13.34.6.106", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T14:02:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T14:02:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T14:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T14:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T14:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T14:02:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T14:02:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T14:02:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T14:02:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T14:02:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T14:02:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T14:02:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T14:03:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.136 port 46386 ssh2", "src_ip": "10.0.2.136", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-09T14:03:37", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/bin/su -", "user": "www-data", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-09T14:06:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=203.78.71.28 OUT= PROTO=TCP DPT=443", "src_ip": "203.78.71.28", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T14:08:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.153 port 43875 ssh2", "src_ip": "10.0.0.153", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T14:09:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.184 port 58402 ssh2", "src_ip": "10.0.5.184", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-09T14:12:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=80.78.225.92 OUT= PROTO=TCP DPT=80", "src_ip": "80.78.225.92", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T14:15:11", "source": "nginx", "category": "benign", "severity": "info", "message": "169.77.28.133 - - \"GET /login HTTP/1.1\" 200 2113", "src_ip": "169.77.28.133", "status": 200, "path": "/login"} {"timestamp": "2026-06-09T14:17:25", "source": "nginx", "category": "benign", "severity": "info", "message": "159.183.37.157 - - \"GET /health HTTP/1.1\" 200 6943", "src_ip": "159.183.37.157", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T14:22:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=36.193.196.6 OUT= PROTO=TCP DPT=80", "src_ip": "36.193.196.6", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T14:25:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=55.240.186.232 OUT= PROTO=TCP DPT=443", "src_ip": "55.240.186.232", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T14:29:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.70 port 59188 ssh2", "src_ip": "10.0.5.70", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-09T14:29:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=220.116.103.94 OUT= PROTO=TCP DPT=80", "src_ip": "220.116.103.94", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T14:30:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.231 dst=193.27.228.114 dport=443 bytes=203 interval=300s", "src_ip": "10.0.5.231", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-09T14:34:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=223.213.76.196 OUT= PROTO=TCP DPT=80", "src_ip": "223.213.76.196", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T14:35:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.231 dst=193.27.228.114 dport=443 bytes=484 interval=300s", "src_ip": "10.0.5.231", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-09T14:36:56", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "guest", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-09T14:37:38", "source": "nginx", "category": "benign", "severity": "info", "message": "129.112.225.26 - - \"GET /static/app.js HTTP/1.1\" 200 4490", "src_ip": "129.112.225.26", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T14:39:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T14:39:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T14:39:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T14:39:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T14:39:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T14:39:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T14:39:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T14:39:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T14:39:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T14:39:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=23.0.108.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "23.0.108.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T14:40:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.231 dst=193.27.228.114 dport=443 bytes=556 interval=300s", "src_ip": "10.0.5.231", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-09T14:40:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=136.53.202.113 OUT= PROTO=TCP DPT=80", "src_ip": "136.53.202.113", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T14:45:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.231 dst=193.27.228.114 dport=443 bytes=329 interval=300s", "src_ip": "10.0.5.231", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-09T14:46:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.122 port 56297 ssh2", "src_ip": "10.0.2.122", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-09T14:47:34", "source": "nginx", "category": "benign", "severity": "info", "message": "39.79.30.226 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 463", "src_ip": "39.79.30.226", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-09T14:50:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.231 dst=193.27.228.114 dport=443 bytes=232 interval=300s", "src_ip": "10.0.5.231", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-09T14:54:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.33 port 45445 ssh2", "src_ip": "10.0.5.33", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-09T14:55:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=152.66.169.93 OUT= PROTO=TCP DPT=443", "src_ip": "152.66.169.93", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T14:57:11", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 403 166", "src_ip": "91.219.236.18", "status": 403, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-09T15:17:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.223 dst=45.137.21.9 dport=443 bytes=298 interval=300s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-09T15:17:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.202 port 58920 ssh2", "src_ip": "10.0.1.202", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-09T15:19:06", "source": "nginx", "category": "benign", "severity": "info", "message": "116.113.103.194 - - \"GET /login HTTP/1.1\" 200 741", "src_ip": "116.113.103.194", "status": 200, "path": "/login"} {"timestamp": "2026-06-09T15:22:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.223 dst=45.137.21.9 dport=443 bytes=339 interval=300s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-09T15:26:55", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 500 114", "src_ip": "193.27.228.114", "status": 500, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T15:27:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.223 dst=45.137.21.9 dport=443 bytes=877 interval=300s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-09T15:30:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=179.54.195.243 OUT= PROTO=TCP DPT=443", "src_ip": "179.54.195.243", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T15:30:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.27 port 59462 ssh2", "src_ip": "10.0.0.27", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-09T15:32:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.223 dst=45.137.21.9 dport=443 bytes=291 interval=300s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-09T15:33:42", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 265", "src_ip": "193.27.228.114", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-09T15:36:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.124 port 57486 ssh2", "src_ip": "10.0.1.124", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T15:37:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.223 dst=45.137.21.9 dport=443 bytes=353 interval=300s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-09T15:40:14", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 403 47", "src_ip": "45.137.21.9", "status": 403, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-09T15:40:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.118.156.33 OUT= PROTO=TCP DPT=443", "src_ip": "214.118.156.33", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T15:41:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T15:41:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T15:41:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T15:41:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T15:41:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T15:41:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T15:41:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T15:41:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T15:41:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T15:41:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T15:41:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T15:41:15", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 352", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T15:42:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.223 dst=45.137.21.9 dport=443 bytes=514 interval=300s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-09T15:43:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=20.173.28.87 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "20.173.28.87", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T15:43:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=20.173.28.87 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "20.173.28.87", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T15:43:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=20.173.28.87 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "20.173.28.87", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T15:43:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=20.173.28.87 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "20.173.28.87", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T15:43:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=20.173.28.87 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "20.173.28.87", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T15:43:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=20.173.28.87 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "20.173.28.87", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T15:43:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=20.173.28.87 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "20.173.28.87", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T15:43:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=20.173.28.87 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "20.173.28.87", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T15:47:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.223 dst=45.137.21.9 dport=443 bytes=275 interval=300s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-09T15:47:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=221.77.200.97 OUT= PROTO=TCP DPT=443", "src_ip": "221.77.200.97", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T15:48:07", "source": "nginx", "category": "benign", "severity": "info", "message": "183.162.86.232 - - \"GET /static/app.js HTTP/1.1\" 200 6115", "src_ip": "183.162.86.232", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T15:50:37", "source": "nginx", "category": "benign", "severity": "info", "message": "123.226.144.101 - - \"GET /login HTTP/1.1\" 200 676", "src_ip": "123.226.144.101", "status": 200, "path": "/login"} {"timestamp": "2026-06-09T15:52:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.223 dst=45.137.21.9 dport=443 bytes=406 interval=300s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-09T15:55:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=106.173.212.192 OUT= PROTO=TCP DPT=80", "src_ip": "106.173.212.192", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T15:57:11", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/bin/bash", "user": "postgres", "host": "web-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-09T15:58:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.105 port 47972 ssh2", "src_ip": "10.0.1.105", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-09T16:00:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=185.148.116.135 OUT= PROTO=TCP DPT=80", "src_ip": "185.148.116.135", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T16:12:39", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-09T16:14:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.208.212.26 OUT= PROTO=TCP DPT=80", "src_ip": "167.208.212.26", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T16:18:04", "source": "nginx", "category": "benign", "severity": "info", "message": "160.22.130.44 - - \"GET / HTTP/1.1\" 200 2526", "src_ip": "160.22.130.44", "status": 200, "path": "/"} {"timestamp": "2026-06-09T16:18:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T16:18:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T16:18:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T16:18:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T16:18:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T16:18:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T16:18:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T16:18:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T16:18:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T16:18:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T16:18:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T16:18:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T16:22:10", "source": "nginx", "category": "benign", "severity": "info", "message": "152.51.126.196 - - \"GET /static/app.js HTTP/1.1\" 200 5537", "src_ip": "152.51.126.196", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T16:22:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 58074 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 57808 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 59320 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 55469 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 55227 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 52861 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 44870 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 53001 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 47827 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 49535 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 56455 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 56725 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 45434 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:22:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 44599 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-09T16:24:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=70.38.25.189 OUT= PROTO=TCP DPT=80", "src_ip": "70.38.25.189", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T16:28:25", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 320", "src_ip": "91.219.236.18", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T16:30:29", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.100 dst=209.141.56.12 bytes=6810501120 proto=TCP dport=443 duration=341s", "src_ip": "10.0.1.100", "dst_ip": "209.141.56.12", "bytes_mb": 6495, "off_hours": false} {"timestamp": "2026-06-09T16:32:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 48856 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:32:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 52292 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:32:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 52019 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:32:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 51345 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:32:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 51210 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:32:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 53910 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:32:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 49228 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:32:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 48571 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:32:46", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 91.219.236.18 port 51234 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-09T16:32:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 46321 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-09T16:34:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.238 port 46357 ssh2", "src_ip": "10.0.3.238", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-09T16:38:03", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.124 dst=209.141.56.12 bytes=574619648 proto=TCP dport=443 duration=420s", "src_ip": "10.0.3.124", "dst_ip": "209.141.56.12", "bytes_mb": 548, "off_hours": false} {"timestamp": "2026-06-09T16:41:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.115 port 52460 ssh2", "src_ip": "10.0.3.115", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-09T16:48:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.165 port 52272 ssh2", "src_ip": "10.0.1.165", "user": "root", "action": "login_success"} {"timestamp": "2026-06-09T17:00:36", "source": "nginx", "category": "benign", "severity": "info", "message": "88.63.79.234 - - \"GET /health HTTP/1.1\" 200 1453", "src_ip": "88.63.79.234", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T17:04:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=124.6.77.101 OUT= PROTO=TCP DPT=443", "src_ip": "124.6.77.101", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T17:04:32", "source": "nginx", "category": "benign", "severity": "info", "message": "52.90.201.176 - - \"GET /static/app.js HTTP/1.1\" 200 1738", "src_ip": "52.90.201.176", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T17:05:00", "source": "nginx", "category": "web_attack", "severity": "high", "message": "176.17.27.177 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 327", "src_ip": "176.17.27.177", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T17:14:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=116.22.214.127 OUT= PROTO=TCP DPT=443", "src_ip": "116.22.214.127", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T17:18:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T17:18:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T17:18:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T17:18:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T17:18:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T17:18:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T17:18:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T17:18:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T17:18:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T17:18:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T17:18:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T17:19:05", "source": "nginx", "category": "benign", "severity": "info", "message": "157.176.184.98 - - \"GET / HTTP/1.1\" 200 4221", "src_ip": "157.176.184.98", "status": 200, "path": "/"} {"timestamp": "2026-06-09T17:25:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 42647 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 47041 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 51033 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 48542 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 51098 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 54681 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 57787 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 55742 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 53724 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 50675 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 49308 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 40655 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:25:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 56102 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 56553 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 58447 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 43143 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 54252 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 49585 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 40611 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 45921 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 46798 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:26:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 56945 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:27:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T17:27:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T17:27:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T17:27:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T17:27:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T17:27:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T17:27:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T17:27:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T17:27:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T17:27:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T17:27:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T17:27:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=223.246.175.22 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "223.246.175.22", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T17:30:24", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 102", "src_ip": "45.137.21.9", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T17:32:28", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "svc_backup", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-09T17:32:47", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.85.53.114 OUT= PROTO=TCP DPT=443", "src_ip": "214.85.53.114", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T17:37:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=124.106.78.106 OUT= PROTO=TCP DPT=443", "src_ip": "124.106.78.106", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T17:37:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 53371 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:37:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 58376 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:37:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 46908 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:37:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 52597 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:37:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 41371 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 56334 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 44459 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 48505 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 55386 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 45661 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 46408 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 53876 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 51910 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 58815 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:38:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 49446 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T17:39:51", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 405", "src_ip": "91.219.236.18", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-09T17:42:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T17:42:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T17:42:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T17:42:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T17:42:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T17:42:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T17:42:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T17:42:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T17:42:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T17:42:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T17:43:17", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.98 dst=45.137.21.9 bytes=3166699520 proto=TCP dport=443 duration=481s", "src_ip": "10.0.3.98", "dst_ip": "45.137.21.9", "bytes_mb": 3020, "off_hours": false} {"timestamp": "2026-06-09T17:45:34", "source": "nginx", "category": "benign", "severity": "info", "message": "196.0.222.78 - - \"GET /health HTTP/1.1\" 200 222", "src_ip": "196.0.222.78", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T17:46:26", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "www-data", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-09T17:54:34", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.90 dst=193.27.228.114 bytes=5986320384 proto=TCP dport=443 duration=69s", "src_ip": "10.0.4.90", "dst_ip": "193.27.228.114", "bytes_mb": 5709, "off_hours": false} {"timestamp": "2026-06-09T17:54:56", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 181", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T17:55:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.192 dst=209.141.56.12 dport=443 bytes=311 interval=300s", "src_ip": "10.0.0.192", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T17:55:54", "source": "nginx", "category": "benign", "severity": "info", "message": "171.60.106.205 - - \"GET /static/app.js HTTP/1.1\" 200 3596", "src_ip": "171.60.106.205", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T17:56:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=153.165.105.16 OUT= PROTO=TCP DPT=80", "src_ip": "153.165.105.16", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T18:00:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.192 dst=209.141.56.12 dport=443 bytes=245 interval=300s", "src_ip": "10.0.0.192", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T18:05:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.192 dst=209.141.56.12 dport=443 bytes=280 interval=300s", "src_ip": "10.0.0.192", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T18:08:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=66.190.12.115 OUT= PROTO=TCP DPT=443", "src_ip": "66.190.12.115", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T18:10:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.192 dst=209.141.56.12 dport=443 bytes=491 interval=300s", "src_ip": "10.0.0.192", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T18:11:44", "source": "nginx", "category": "benign", "severity": "info", "message": "208.118.228.95 - - \"GET /dashboard HTTP/1.1\" 200 4813", "src_ip": "208.118.228.95", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-09T18:12:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=69.237.59.171 OUT= PROTO=TCP DPT=80", "src_ip": "69.237.59.171", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T18:13:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=81.125.114.36 OUT= PROTO=TCP DPT=80", "src_ip": "81.125.114.36", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T18:15:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.192 dst=209.141.56.12 dport=443 bytes=627 interval=300s", "src_ip": "10.0.0.192", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T18:20:07", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 168", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T18:20:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.3.27 port 40632 ssh2", "src_ip": "10.0.3.27", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T18:22:58", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.56 dst=45.137.21.9 bytes=7464812544 proto=TCP dport=443 duration=380s", "src_ip": "10.0.4.56", "dst_ip": "45.137.21.9", "bytes_mb": 7119, "off_hours": false} {"timestamp": "2026-06-09T18:27:27", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 212", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T18:44:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.175 port 50713 ssh2", "src_ip": "10.0.4.175", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-09T18:49:26", "source": "nginx", "category": "benign", "severity": "info", "message": "134.225.108.6 - - \"GET /health HTTP/1.1\" 200 3514", "src_ip": "134.225.108.6", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T18:52:18", "source": "nginx", "category": "benign", "severity": "info", "message": "110.160.193.138 - - \"GET /static/app.js HTTP/1.1\" 200 3374", "src_ip": "110.160.193.138", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T18:54:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=187.12.15.22 OUT= PROTO=TCP DPT=443", "src_ip": "187.12.15.22", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T18:56:04", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 200 189", "src_ip": "209.141.56.12", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T18:57:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.219 port 42474 ssh2", "src_ip": "10.0.0.219", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T18:59:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.39 port 45928 ssh2", "src_ip": "10.0.2.39", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-09T19:03:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=96.45.51.40 OUT= PROTO=TCP DPT=443", "src_ip": "96.45.51.40", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T19:05:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.176 port 42070 ssh2", "src_ip": "10.0.1.176", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-09T19:10:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=124.35.92.119 OUT= PROTO=TCP DPT=443", "src_ip": "124.35.92.119", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T19:11:36", "source": "nginx", "category": "benign", "severity": "info", "message": "97.243.215.91 - - \"GET /login HTTP/1.1\" 200 7086", "src_ip": "97.243.215.91", "status": 200, "path": "/login"} {"timestamp": "2026-06-09T19:16:17", "source": "nginx", "category": "benign", "severity": "info", "message": "180.231.180.68 - - \"GET / HTTP/1.1\" 200 7793", "src_ip": "180.231.180.68", "status": 200, "path": "/"} {"timestamp": "2026-06-09T19:19:55", "source": "nginx", "category": "benign", "severity": "info", "message": "55.255.193.4 - - \"GET /login HTTP/1.1\" 200 2473", "src_ip": "55.255.193.4", "status": 200, "path": "/login"} {"timestamp": "2026-06-09T19:26:31", "source": "nginx", "category": "benign", "severity": "info", "message": "74.141.34.159 - - \"GET /dashboard HTTP/1.1\" 200 3410", "src_ip": "74.141.34.159", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-09T19:29:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.78 port 41627 ssh2", "src_ip": "10.0.2.78", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-09T19:31:27", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/bin/su -", "user": "postgres", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-09T19:33:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.167 dst=209.141.56.12 dport=443 bytes=391 interval=300s", "src_ip": "10.0.5.167", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T19:34:40", "source": "nginx", "category": "benign", "severity": "info", "message": "208.68.101.167 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7848", "src_ip": "208.68.101.167", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-09T19:38:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.167 dst=209.141.56.12 dport=443 bytes=319 interval=300s", "src_ip": "10.0.5.167", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T19:43:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.167 dst=209.141.56.12 dport=443 bytes=771 interval=300s", "src_ip": "10.0.5.167", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T19:45:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.91 port 55684 ssh2", "src_ip": "10.0.0.91", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-09T19:48:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.167 dst=209.141.56.12 dport=443 bytes=393 interval=300s", "src_ip": "10.0.5.167", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T19:49:20", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.163 dst=209.141.56.12 bytes=2851078144 proto=TCP dport=443 duration=568s", "src_ip": "10.0.1.163", "dst_ip": "209.141.56.12", "bytes_mb": 2719, "off_hours": false} {"timestamp": "2026-06-09T19:49:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.145 port 51128 ssh2", "src_ip": "10.0.2.145", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-09T19:51:51", "source": "nginx", "category": "benign", "severity": "info", "message": "97.251.150.74 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4637", "src_ip": "97.251.150.74", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-09T19:53:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.167 dst=209.141.56.12 dport=443 bytes=625 interval=300s", "src_ip": "10.0.5.167", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T19:56:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.72 port 47367 ssh2", "src_ip": "10.0.0.72", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-09T19:58:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.167 dst=209.141.56.12 dport=443 bytes=586 interval=300s", "src_ip": "10.0.5.167", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T20:01:30", "source": "nginx", "category": "benign", "severity": "info", "message": "107.84.199.48 - - \"GET /static/app.js HTTP/1.1\" 200 1157", "src_ip": "107.84.199.48", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T20:03:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.167 dst=209.141.56.12 dport=443 bytes=663 interval=300s", "src_ip": "10.0.5.167", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T20:06:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.125 port 59660 ssh2", "src_ip": "10.0.2.125", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-09T20:08:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.167 dst=209.141.56.12 dport=443 bytes=670 interval=300s", "src_ip": "10.0.5.167", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T20:08:56", "source": "nginx", "category": "benign", "severity": "info", "message": "41.196.230.81 - - \"GET /health HTTP/1.1\" 200 3282", "src_ip": "41.196.230.81", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T20:09:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.235.80.13 OUT= PROTO=TCP DPT=443", "src_ip": "47.235.80.13", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T20:14:22", "source": "nginx", "category": "benign", "severity": "info", "message": "31.232.64.79 - - \"GET / HTTP/1.1\" 200 6099", "src_ip": "31.232.64.79", "status": 200, "path": "/"} {"timestamp": "2026-06-09T20:22:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.215 port 51341 ssh2", "src_ip": "10.0.4.215", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-09T20:25:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T20:25:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T20:25:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T20:25:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T20:25:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T20:25:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T20:25:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T20:25:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T20:25:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T20:25:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T20:25:21", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 473", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T20:38:05", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 200 260", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T20:40:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.131 port 58166 ssh2", "src_ip": "10.0.4.131", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-09T20:46:38", "source": "nginx", "category": "benign", "severity": "info", "message": "198.36.111.77 - - \"GET / HTTP/1.1\" 200 336", "src_ip": "198.36.111.77", "status": 200, "path": "/"} {"timestamp": "2026-06-09T20:46:58", "source": "nginx", "category": "benign", "severity": "info", "message": "95.16.11.105 - - \"GET /login HTTP/1.1\" 200 3091", "src_ip": "95.16.11.105", "status": 200, "path": "/login"} {"timestamp": "2026-06-09T20:57:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=200.161.160.4 OUT= PROTO=TCP DPT=443", "src_ip": "200.161.160.4", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T20:58:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.110.226.179 OUT= PROTO=TCP DPT=80", "src_ip": "147.110.226.179", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T21:00:34", "source": "nginx", "category": "benign", "severity": "info", "message": "168.160.86.160 - - \"GET /static/app.js HTTP/1.1\" 200 6722", "src_ip": "168.160.86.160", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T21:01:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=126.87.82.24 OUT= PROTO=TCP DPT=80", "src_ip": "126.87.82.24", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T21:05:46", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/su -", "user": "guest", "host": "db-03", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-09T21:05:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=25.108.172.129 OUT= PROTO=TCP DPT=443", "src_ip": "25.108.172.129", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T21:08:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.69 port 54972 ssh2", "src_ip": "10.0.1.69", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-09T21:10:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T21:10:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T21:10:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T21:10:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T21:10:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T21:10:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T21:10:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T21:10:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T21:10:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T21:10:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T21:10:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T21:10:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T21:13:01", "source": "nginx", "category": "benign", "severity": "info", "message": "128.138.17.126 - - \"GET /static/app.js HTTP/1.1\" 200 3742", "src_ip": "128.138.17.126", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T21:21:00", "source": "nginx", "category": "benign", "severity": "info", "message": "76.34.31.73 - - \"GET / HTTP/1.1\" 200 2427", "src_ip": "76.34.31.73", "status": 200, "path": "/"} {"timestamp": "2026-06-09T21:21:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=212.53.35.184 OUT= PROTO=TCP DPT=443", "src_ip": "212.53.35.184", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T21:25:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.4.170 port 49930 ssh2", "src_ip": "10.0.4.170", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-09T21:29:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.156 port 53305 ssh2", "src_ip": "10.0.4.156", "user": "root", "action": "login_success"} {"timestamp": "2026-06-09T21:31:48", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.49 dst=91.219.236.18 bytes=6957301760 proto=TCP dport=443 duration=356s", "src_ip": "10.0.3.49", "dst_ip": "91.219.236.18", "bytes_mb": 6635, "off_hours": false} {"timestamp": "2026-06-09T21:35:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.56 port 51129 ssh2", "src_ip": "10.0.2.56", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-09T21:37:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T21:37:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T21:37:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T21:37:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T21:37:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T21:37:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T21:37:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T21:37:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T21:37:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T21:37:43", "source": "nginx", "category": "benign", "severity": "info", "message": "27.226.52.7 - - \"GET /dashboard HTTP/1.1\" 200 1867", "src_ip": "27.226.52.7", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-09T21:38:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.149 port 59768 ssh2", "src_ip": "10.0.5.149", "user": "root", "action": "login_success"} {"timestamp": "2026-06-09T21:39:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 42406 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:39:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 50902 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:39:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 50484 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:39:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 58091 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:39:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 47839 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:39:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 53430 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:40:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 55780 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:40:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 46873 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:40:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41108 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:40:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 45129 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:40:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 59256 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:40:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 46274 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:42:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T21:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T21:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T21:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T21:42:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T21:42:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T21:42:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T21:42:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T21:42:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T21:42:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T21:42:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T21:47:02", "source": "nginx", "category": "benign", "severity": "info", "message": "137.59.49.61 - - \"GET /static/app.js HTTP/1.1\" 200 1311", "src_ip": "137.59.49.61", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T21:48:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T21:48:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T21:48:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T21:48:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T21:48:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T21:48:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T21:48:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T21:48:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T21:48:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T21:48:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T21:48:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T21:48:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T21:49:41", "source": "nginx", "category": "benign", "severity": "info", "message": "174.130.24.153 - - \"GET / HTTP/1.1\" 200 5622", "src_ip": "174.130.24.153", "status": 200, "path": "/"} {"timestamp": "2026-06-09T21:58:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 58840 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:58:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 48475 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:58:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52715 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:58:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52763 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:58:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 53252 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:58:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 50367 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:58:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 42378 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49497 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 43876 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52812 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 40193 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 56476 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 42072 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 58137 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 59189 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 54341 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52947 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 45122 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49874 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 42834 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52226 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 41009 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 47204 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49665 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T21:59:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 44721 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-09T22:05:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.165 port 43313 ssh2", "src_ip": "10.0.5.165", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T22:12:13", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/su -", "user": "nattapong", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-09T22:17:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=109.64.28.78 OUT= PROTO=TCP DPT=80", "src_ip": "109.64.28.78", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T22:19:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=51.60.114.147 OUT= PROTO=TCP DPT=443", "src_ip": "51.60.114.147", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T22:22:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.134 dst=209.141.56.12 dport=443 bytes=394 interval=300s", "src_ip": "10.0.3.134", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T22:23:22", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 200 370", "src_ip": "209.141.56.12", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T22:24:11", "source": "nginx", "category": "benign", "severity": "info", "message": "186.5.16.75 - - \"GET /static/app.js HTTP/1.1\" 200 1824", "src_ip": "186.5.16.75", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-09T22:25:26", "source": "nginx", "category": "benign", "severity": "info", "message": "130.52.28.121 - - \"GET /health HTTP/1.1\" 200 2536", "src_ip": "130.52.28.121", "status": 200, "path": "/health"} {"timestamp": "2026-06-09T22:27:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.134 dst=209.141.56.12 dport=443 bytes=498 interval=300s", "src_ip": "10.0.3.134", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T22:27:59", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 283", "src_ip": "193.27.228.114", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T22:32:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.134 dst=209.141.56.12 dport=443 bytes=650 interval=300s", "src_ip": "10.0.3.134", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T22:33:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T22:33:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T22:33:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T22:33:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T22:33:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-09T22:33:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T22:33:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T22:33:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T22:36:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.198 dst=91.219.236.18 dport=443 bytes=635 interval=300s", "src_ip": "10.0.5.198", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-09T22:37:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.134 dst=209.141.56.12 dport=443 bytes=607 interval=300s", "src_ip": "10.0.3.134", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T22:40:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.216 port 40667 ssh2", "src_ip": "10.0.1.216", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-09T22:41:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.231 port 58170 ssh2", "src_ip": "10.0.2.231", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-09T22:41:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.198 dst=91.219.236.18 dport=443 bytes=743 interval=300s", "src_ip": "10.0.5.198", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-09T22:42:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.134 dst=209.141.56.12 dport=443 bytes=511 interval=300s", "src_ip": "10.0.3.134", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-09T22:43:25", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "nattapong", "host": "web-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-09T22:44:55", "source": "nginx", "category": "benign", "severity": "info", "message": "28.180.169.50 - - \"GET /api/products HTTP/1.1\" 200 7752", "src_ip": "28.180.169.50", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-09T22:45:53", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.181 dst=91.219.236.18 bytes=3908042752 proto=TCP dport=443 duration=216s", "src_ip": "10.0.1.181", "dst_ip": "91.219.236.18", "bytes_mb": 3727, "off_hours": false} {"timestamp": "2026-06-09T22:46:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.198 dst=91.219.236.18 dport=443 bytes=603 interval=300s", "src_ip": "10.0.5.198", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-09T22:49:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.172 port 48971 ssh2", "src_ip": "10.0.1.172", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-09T22:51:02", "source": "nginx", "category": "benign", "severity": "info", "message": "104.89.34.144 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6537", "src_ip": "104.89.34.144", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-09T22:51:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.246 port 57396 ssh2", "src_ip": "10.0.5.246", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T22:51:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.198 dst=91.219.236.18 dport=443 bytes=690 interval=300s", "src_ip": "10.0.5.198", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-09T22:52:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=205.237.123.8 OUT= PROTO=TCP DPT=80", "src_ip": "205.237.123.8", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T22:52:44", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 200 354", "src_ip": "91.219.236.18", "status": 200, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T22:53:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.92 port 54148 ssh2", "src_ip": "10.0.5.92", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-09T22:56:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.198 dst=91.219.236.18 dport=443 bytes=300 interval=300s", "src_ip": "10.0.5.198", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-09T23:02:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.235 port 57465 ssh2", "src_ip": "10.0.0.235", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-09T23:04:56", "source": "nginx", "category": "benign", "severity": "info", "message": "159.1.163.119 - - \"GET / HTTP/1.1\" 200 6529", "src_ip": "159.1.163.119", "status": 200, "path": "/"} {"timestamp": "2026-06-09T23:05:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=185.220.101.34 dport=443 bytes=233 interval=300s", "src_ip": "10.0.2.184", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-09T23:06:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.102 port 57601 ssh2", "src_ip": "10.0.4.102", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-09T23:07:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=199.194.160.101 OUT= PROTO=TCP DPT=80", "src_ip": "199.194.160.101", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T23:10:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=185.220.101.34 dport=443 bytes=595 interval=300s", "src_ip": "10.0.2.184", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-09T23:15:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=185.220.101.34 dport=443 bytes=823 interval=300s", "src_ip": "10.0.2.184", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-09T23:16:17", "source": "nginx", "category": "web_attack", "severity": "high", "message": "58.206.117.185 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 98", "src_ip": "58.206.117.185", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-09T23:18:45", "source": "nginx", "category": "benign", "severity": "info", "message": "108.240.20.130 - - \"GET /dashboard HTTP/1.1\" 200 4028", "src_ip": "108.240.20.130", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-09T23:20:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=185.220.101.34 dport=443 bytes=435 interval=300s", "src_ip": "10.0.2.184", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-09T23:20:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.173 port 47739 ssh2", "src_ip": "10.0.5.173", "user": "root", "action": "login_success"} {"timestamp": "2026-06-09T23:20:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=45.122.241.125 OUT= PROTO=TCP DPT=80", "src_ip": "45.122.241.125", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T23:23:40", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.22 port 48420 ssh2", "src_ip": "10.0.1.22", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-09T23:25:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=185.220.101.34 dport=443 bytes=532 interval=300s", "src_ip": "10.0.2.184", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-09T23:26:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 54739 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 47363 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 59627 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 44172 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 56696 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 45153 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 53674 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 58405 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 44769 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 42459 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 59654 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:26:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 49424 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:27:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 49089 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:27:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 49202 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:27:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 51189 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:27:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 57540 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:27:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 41309 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:27:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 55398 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:27:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 210.202.14.50 port 50718 ssh2", "src_ip": "210.202.14.50", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-09T23:30:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=185.220.101.34 dport=443 bytes=758 interval=300s", "src_ip": "10.0.2.184", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-09T23:32:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=58.114.44.196 OUT= PROTO=TCP DPT=80", "src_ip": "58.114.44.196", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T23:32:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.38 port 54554 ssh2", "src_ip": "10.0.2.38", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-09T23:35:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=146.219.117.241 OUT= PROTO=TCP DPT=443", "src_ip": "146.219.117.241", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T23:36:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=68.24.142.236 OUT= PROTO=TCP DPT=443", "src_ip": "68.24.142.236", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T23:40:05", "source": "nginx", "category": "benign", "severity": "info", "message": "23.193.74.149 - - \"GET / HTTP/1.1\" 200 871", "src_ip": "23.193.74.149", "status": 200, "path": "/"} {"timestamp": "2026-06-09T23:40:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 57498 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 50140 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 46357 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 58691 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 55128 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 59813 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 48192 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 52513 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 55747 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 56905 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 49340 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 45310 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 45253 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 57283 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 54782 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 58171 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 54723 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 43005 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 40873 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 41745 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:40:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 56449 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:41:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 185.220.101.34 port 44828 ssh2", "src_ip": "185.220.101.34", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-09T23:41:07", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 200 490", "src_ip": "193.27.228.114", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-09T23:46:02", "source": "nginx", "category": "benign", "severity": "info", "message": "152.127.90.125 - - \"GET /api/products HTTP/1.1\" 200 5722", "src_ip": "152.127.90.125", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-09T23:47:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=72.245.136.178 OUT= PROTO=TCP DPT=80", "src_ip": "72.245.136.178", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-09T23:50:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=176.204.169.248 OUT= PROTO=TCP DPT=443", "src_ip": "176.204.169.248", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-09T23:56:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-09T23:56:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-09T23:56:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-09T23:56:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-09T23:56:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-09T23:56:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-09T23:56:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-09T23:56:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-09T23:56:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-09T23:56:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-09T23:56:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-09T23:57:35", "source": "nginx", "category": "benign", "severity": "info", "message": "134.158.231.231 - - \"GET /api/products HTTP/1.1\" 200 6600", "src_ip": "134.158.231.231", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-09T23:58:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=71.179.55.20 OUT= PROTO=TCP DPT=443", "src_ip": "71.179.55.20", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T00:05:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.209 port 59135 ssh2", "src_ip": "10.0.2.209", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T00:05:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=102.227.130.68 OUT= PROTO=TCP DPT=443", "src_ip": "102.227.130.68", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T00:06:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=56.100.107.51 OUT= PROTO=TCP DPT=80", "src_ip": "56.100.107.51", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T00:07:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=96.24.114.8 OUT= PROTO=TCP DPT=443", "src_ip": "96.24.114.8", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T00:13:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=218.236.82.59 OUT= PROTO=TCP DPT=443", "src_ip": "218.236.82.59", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T00:15:15", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 200 105", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T00:16:59", "source": "nginx", "category": "web_attack", "severity": "high", "message": "15.136.76.179 - - \"GET /search?q= HTTP/1.1\" 200 18", "src_ip": "15.136.76.179", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T00:17:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.46 port 41637 ssh2", "src_ip": "10.0.0.46", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T00:18:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.208.184.133 OUT= PROTO=TCP DPT=80", "src_ip": "47.208.184.133", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T00:20:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=110.249.127.72 OUT= PROTO=TCP DPT=443", "src_ip": "110.249.127.72", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T00:23:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=211.150.227.36 OUT= PROTO=TCP DPT=443", "src_ip": "211.150.227.36", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T00:23:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.5 port 55241 ssh2", "src_ip": "10.0.3.5", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T00:24:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=161.96.150.203 OUT= PROTO=TCP DPT=80", "src_ip": "161.96.150.203", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T00:24:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.219 port 42386 ssh2", "src_ip": "10.0.4.219", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T00:27:17", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.15 dst=45.137.21.9 bytes=5669650432 proto=TCP dport=443 duration=219s", "src_ip": "10.0.3.15", "dst_ip": "45.137.21.9", "bytes_mb": 5407, "off_hours": true} {"timestamp": "2026-06-10T00:27:50", "source": "nginx", "category": "benign", "severity": "info", "message": "218.91.138.63 - - \"GET /static/app.js HTTP/1.1\" 200 7565", "src_ip": "218.91.138.63", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T00:31:49", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "postgres", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-10T00:41:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.132 port 40948 ssh2", "src_ip": "10.0.4.132", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T00:46:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 50251 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 54962 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 50008 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 54160 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 58296 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 49947 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 44632 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 41804 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 53741 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 52531 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46021 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 59593 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 51181 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 59366 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 50052 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 42688 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:46:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 43374 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T00:51:29", "source": "nginx", "category": "benign", "severity": "info", "message": "127.51.151.170 - - \"GET /health HTTP/1.1\" 200 4323", "src_ip": "127.51.151.170", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T00:51:43", "source": "nginx", "category": "benign", "severity": "info", "message": "70.157.225.33 - - \"GET /static/app.js HTTP/1.1\" 200 2160", "src_ip": "70.157.225.33", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T00:52:09", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 200 225", "src_ip": "185.220.101.34", "status": 200, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T00:58:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 51509 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 55711 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 52299 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 54787 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 41094 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 42431 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 47391 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 40657 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 48556 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 45574 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 41754 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 50849 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 45272 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 46225 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 59465 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 45406 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 42457 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 43050 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 55818 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 58157 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 41015 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:58:55", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for www-data from 91.219.236.18 port 51234 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-10T00:59:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 54227 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T00:59:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 57698 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T01:05:17", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=118.101.127.47 OUT= PROTO=TCP DPT=80", "src_ip": "118.101.127.47", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T01:07:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.114 port 47678 ssh2", "src_ip": "10.0.3.114", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T01:10:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.98 port 51316 ssh2", "src_ip": "10.0.1.98", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T01:13:01", "source": "nginx", "category": "benign", "severity": "info", "message": "90.87.192.187 - - \"GET / HTTP/1.1\" 200 4726", "src_ip": "90.87.192.187", "status": 200, "path": "/"} {"timestamp": "2026-06-10T01:13:14", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.130 dst=209.141.56.12 bytes=2829058048 proto=TCP dport=443 duration=189s", "src_ip": "10.0.2.130", "dst_ip": "209.141.56.12", "bytes_mb": 2698, "off_hours": true} {"timestamp": "2026-06-10T01:20:29", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "somchai", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-10T01:21:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.10 port 40432 ssh2", "src_ip": "10.0.2.10", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T01:23:11", "source": "nginx", "category": "web_attack", "severity": "high", "message": "70.58.19.48 - - \"GET /search?q= HTTP/1.1\" 403 21", "src_ip": "70.58.19.48", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T01:24:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=16.95.52.73 OUT= PROTO=TCP DPT=443", "src_ip": "16.95.52.73", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T01:30:58", "source": "nginx", "category": "benign", "severity": "info", "message": "22.181.117.183 - - \"GET / HTTP/1.1\" 200 2318", "src_ip": "22.181.117.183", "status": 200, "path": "/"} {"timestamp": "2026-06-10T01:31:01", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 500 27", "src_ip": "91.219.236.18", "status": 500, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T01:31:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 58260 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57627 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 49209 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 46787 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53357 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 43754 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 47965 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57283 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51485 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57137 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57170 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 40394 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55503 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 59525 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57552 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:31:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51544 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:32:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 50946 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:32:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51574 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:32:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 58245 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:32:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55683 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:32:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 41152 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:32:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 45114 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:32:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 59372 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:32:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 45253 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T01:36:40", "source": "nginx", "category": "benign", "severity": "info", "message": "157.103.201.156 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5322", "src_ip": "157.103.201.156", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T01:38:29", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/bash", "user": "somchai", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T01:41:06", "source": "nginx", "category": "benign", "severity": "info", "message": "109.214.127.247 - - \"GET /health HTTP/1.1\" 200 7591", "src_ip": "109.214.127.247", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T01:41:40", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.112 dst=193.27.228.114 bytes=7582253056 proto=TCP dport=443 duration=464s", "src_ip": "10.0.4.112", "dst_ip": "193.27.228.114", "bytes_mb": 7231, "off_hours": true} {"timestamp": "2026-06-10T01:42:53", "source": "nginx", "category": "benign", "severity": "info", "message": "193.76.112.219 - - \"GET /login HTTP/1.1\" 200 1269", "src_ip": "193.76.112.219", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T01:42:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.163 port 58823 ssh2", "src_ip": "10.0.0.163", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T01:44:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 59274 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 54422 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 54354 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 51134 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 55194 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 41436 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 51595 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 43273 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 46267 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 58046 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.13 port 40116 ssh2", "src_ip": "10.0.2.13", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-10T01:44:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.125 port 57516 ssh2", "src_ip": "10.0.0.125", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-10T01:44:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 59329 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 51998 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:44:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 92.56.172.55 port 40919 ssh2", "src_ip": "92.56.172.55", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T01:46:22", "source": "nginx", "category": "benign", "severity": "info", "message": "137.194.87.96 - - \"GET / HTTP/1.1\" 200 2968", "src_ip": "137.194.87.96", "status": 200, "path": "/"} {"timestamp": "2026-06-10T01:51:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T01:51:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T01:51:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T01:51:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T01:51:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T01:51:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T01:51:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T01:51:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T01:51:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T01:53:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T01:53:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T01:53:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T01:53:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T01:53:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T01:53:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T01:53:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T01:53:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T01:53:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T01:53:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T01:55:48", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 114", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T02:02:34", "source": "nginx", "category": "benign", "severity": "info", "message": "71.21.202.102 - - \"GET /login HTTP/1.1\" 200 3755", "src_ip": "71.21.202.102", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T02:05:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.68 port 52110 ssh2", "src_ip": "10.0.1.68", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T02:05:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.238 dst=209.141.56.12 dport=443 bytes=264 interval=30s", "src_ip": "10.0.5.238", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T02:06:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.238 dst=209.141.56.12 dport=443 bytes=727 interval=30s", "src_ip": "10.0.5.238", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T02:06:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.238 dst=209.141.56.12 dport=443 bytes=521 interval=30s", "src_ip": "10.0.5.238", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T02:07:21", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.34 dst=193.27.228.114 bytes=1311768576 proto=TCP dport=443 duration=237s", "src_ip": "10.0.1.34", "dst_ip": "193.27.228.114", "bytes_mb": 1251, "off_hours": true} {"timestamp": "2026-06-10T02:07:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.238 dst=209.141.56.12 dport=443 bytes=358 interval=30s", "src_ip": "10.0.5.238", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T02:07:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.238 dst=209.141.56.12 dport=443 bytes=683 interval=30s", "src_ip": "10.0.5.238", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T02:08:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.238 dst=209.141.56.12 dport=443 bytes=397 interval=30s", "src_ip": "10.0.5.238", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T02:10:46", "source": "nginx", "category": "benign", "severity": "info", "message": "145.228.172.134 - - \"GET /health HTTP/1.1\" 200 6829", "src_ip": "145.228.172.134", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T02:11:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=176.171.33.85 OUT= PROTO=TCP DPT=80", "src_ip": "176.171.33.85", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T02:18:38", "source": "nginx", "category": "benign", "severity": "info", "message": "34.160.182.52 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1433", "src_ip": "34.160.182.52", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T02:19:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.49 port 56456 ssh2", "src_ip": "10.0.0.49", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T02:22:27", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 375", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T02:26:28", "source": "nginx", "category": "benign", "severity": "info", "message": "169.224.254.152 - - \"GET /dashboard HTTP/1.1\" 200 729", "src_ip": "169.224.254.152", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T02:27:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.143.64.218 OUT= PROTO=TCP DPT=443", "src_ip": "214.143.64.218", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T02:31:11", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "nattapong", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-10T02:33:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.64 port 48776 ssh2", "src_ip": "10.0.1.64", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T02:36:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T02:36:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T02:36:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T02:36:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T02:36:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T02:36:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T02:36:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T02:36:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T02:36:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T02:36:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T02:36:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T02:42:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 44745 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 47147 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 44836 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 46411 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 58863 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 43147 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 40299 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 41719 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 56889 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 53995 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 53238 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 41113 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 47892 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 55527 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 52300 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:42:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 45512 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:43:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.216.244.241 OUT= PROTO=TCP DPT=80", "src_ip": "215.216.244.241", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T02:43:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 56011 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:43:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 51091 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:43:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 59534 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:43:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 54215 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:43:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 52520 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:43:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 54585 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:43:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 128.83.70.114 port 42936 ssh2", "src_ip": "128.83.70.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T02:44:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T02:44:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T02:44:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T02:44:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T02:44:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T02:44:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T02:44:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T02:44:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T02:44:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T02:44:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T02:44:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T02:45:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.145 port 59659 ssh2", "src_ip": "10.0.2.145", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T02:46:21", "source": "nginx", "category": "benign", "severity": "info", "message": "48.110.232.46 - - \"GET /dashboard HTTP/1.1\" 200 3259", "src_ip": "48.110.232.46", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T02:49:22", "source": "nginx", "category": "benign", "severity": "info", "message": "119.132.59.155 - - \"GET /health HTTP/1.1\" 200 6773", "src_ip": "119.132.59.155", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T02:51:30", "source": "nginx", "category": "benign", "severity": "info", "message": "135.112.173.163 - - \"GET /health HTTP/1.1\" 200 573", "src_ip": "135.112.173.163", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T02:53:56", "source": "nginx", "category": "benign", "severity": "info", "message": "170.11.242.40 - - \"GET /dashboard HTTP/1.1\" 200 5444", "src_ip": "170.11.242.40", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T02:54:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.79 dst=45.137.21.9 dport=443 bytes=461 interval=30s", "src_ip": "10.0.1.79", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-10T02:54:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.79 dst=45.137.21.9 dport=443 bytes=496 interval=30s", "src_ip": "10.0.1.79", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-10T02:55:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.79 dst=45.137.21.9 dport=443 bytes=535 interval=30s", "src_ip": "10.0.1.79", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-10T02:55:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.79 dst=45.137.21.9 dport=443 bytes=322 interval=30s", "src_ip": "10.0.1.79", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-10T02:55:38", "source": "nginx", "category": "benign", "severity": "info", "message": "208.225.15.245 - - \"GET /login HTTP/1.1\" 200 6423", "src_ip": "208.225.15.245", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T02:56:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.79 dst=45.137.21.9 dport=443 bytes=207 interval=30s", "src_ip": "10.0.1.79", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-10T02:56:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.79 dst=45.137.21.9 dport=443 bytes=709 interval=30s", "src_ip": "10.0.1.79", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-10T03:02:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.130 port 53099 ssh2", "src_ip": "10.0.2.130", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-10T03:03:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T03:03:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T03:03:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T03:03:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T03:03:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T03:03:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T03:03:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T03:03:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T03:03:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T03:03:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T03:03:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T03:04:34", "source": "nginx", "category": "benign", "severity": "info", "message": "120.209.12.14 - - \"GET / HTTP/1.1\" 200 1246", "src_ip": "120.209.12.14", "status": 200, "path": "/"} {"timestamp": "2026-06-10T03:13:02", "source": "nginx", "category": "web_attack", "severity": "high", "message": "202.70.60.247 - - \"GET /search?q= HTTP/1.1\" 200 356", "src_ip": "202.70.60.247", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T03:13:14", "source": "nginx", "category": "benign", "severity": "info", "message": "114.188.213.216 - - \"GET /dashboard HTTP/1.1\" 200 3972", "src_ip": "114.188.213.216", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T03:14:05", "source": "nginx", "category": "benign", "severity": "info", "message": "147.191.57.82 - - \"GET /static/app.js HTTP/1.1\" 200 3671", "src_ip": "147.191.57.82", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T03:17:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=98.141.189.113 OUT= PROTO=TCP DPT=443", "src_ip": "98.141.189.113", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T03:22:52", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "www-data", "host": "bastion-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-10T03:23:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.61 port 58877 ssh2", "src_ip": "10.0.2.61", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-10T03:28:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=143.190.36.247 OUT= PROTO=TCP DPT=443", "src_ip": "143.190.36.247", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T03:30:29", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/bash", "user": "guest", "host": "web-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T03:30:46", "source": "nginx", "category": "benign", "severity": "info", "message": "52.69.54.126 - - \"GET / HTTP/1.1\" 200 1104", "src_ip": "52.69.54.126", "status": 200, "path": "/"} {"timestamp": "2026-06-10T03:30:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=179.111.62.182 OUT= PROTO=TCP DPT=80", "src_ip": "179.111.62.182", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T03:33:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=213.125.4.40 OUT= PROTO=TCP DPT=80", "src_ip": "213.125.4.40", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T03:36:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=221.15.241.156 OUT= PROTO=TCP DPT=443", "src_ip": "221.15.241.156", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T03:37:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=219.5.182.57 OUT= PROTO=TCP DPT=443", "src_ip": "219.5.182.57", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T03:43:24", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 200 39", "src_ip": "185.220.101.34", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T03:45:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=129.157.11.102 OUT= PROTO=TCP DPT=443", "src_ip": "129.157.11.102", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T03:46:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 47284 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 47608 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 48229 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 43673 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 43346 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 53293 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 56528 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 57075 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 50812 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 41054 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 42080 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 51654 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:46:32", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for oppa from 91.219.236.18 port 51234 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-10T03:46:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 41474 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T03:47:00", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/su -", "user": "guest", "host": "db-03", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-10T03:48:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=144.155.38.235 OUT= PROTO=TCP DPT=80", "src_ip": "144.155.38.235", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T03:53:38", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.219 port 49101 ssh2", "src_ip": "10.0.4.219", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T03:58:51", "source": "nginx", "category": "benign", "severity": "info", "message": "90.156.68.215 - - \"GET /health HTTP/1.1\" 200 5719", "src_ip": "90.156.68.215", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T04:01:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.94 port 53288 ssh2", "src_ip": "10.0.4.94", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T04:02:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.9 dst=193.27.228.114 dport=443 bytes=338 interval=30s", "src_ip": "10.0.5.9", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:03:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.9 dst=193.27.228.114 dport=443 bytes=223 interval=30s", "src_ip": "10.0.5.9", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:03:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.9 dst=193.27.228.114 dport=443 bytes=822 interval=30s", "src_ip": "10.0.5.9", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:04:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.9 dst=193.27.228.114 dport=443 bytes=468 interval=30s", "src_ip": "10.0.5.9", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:04:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.9 dst=193.27.228.114 dport=443 bytes=547 interval=30s", "src_ip": "10.0.5.9", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:05:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.9 dst=193.27.228.114 dport=443 bytes=361 interval=30s", "src_ip": "10.0.5.9", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:05:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55906 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.9 dst=193.27.228.114 dport=443 bytes=404 interval=30s", "src_ip": "10.0.5.9", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:05:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57669 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 58711 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55498 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 43176 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55488 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 46239 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53193 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 48147 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53879 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55303 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:05:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 54124 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:06:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 41775 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:06:06", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-10T04:06:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 43224 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:06:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51118 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-10T04:06:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=94.92.13.183 OUT= PROTO=TCP DPT=80", "src_ip": "94.92.13.183", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T04:11:29", "source": "nginx", "category": "benign", "severity": "info", "message": "157.119.42.155 - - \"GET /health HTTP/1.1\" 200 3734", "src_ip": "157.119.42.155", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T04:12:27", "source": "nginx", "category": "benign", "severity": "info", "message": "41.129.22.17 - - \"GET /api/products HTTP/1.1\" 200 5668", "src_ip": "41.129.22.17", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T04:14:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T04:14:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T04:14:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T04:14:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T04:14:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T04:14:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T04:14:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T04:14:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T04:14:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T04:14:18", "source": "nginx", "category": "benign", "severity": "info", "message": "65.198.98.212 - - \"GET /static/app.js HTTP/1.1\" 200 2597", "src_ip": "65.198.98.212", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T04:14:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.59 port 51063 ssh2", "src_ip": "10.0.5.59", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-10T04:14:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.211 port 50800 ssh2", "src_ip": "10.0.4.211", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T04:15:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.22 port 49537 ssh2", "src_ip": "10.0.4.22", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T04:18:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=128.148.104.106 OUT= PROTO=TCP DPT=80", "src_ip": "128.148.104.106", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T04:21:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.249 port 47969 ssh2", "src_ip": "10.0.3.249", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-10T04:27:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T04:27:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T04:27:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T04:27:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T04:27:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T04:27:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T04:27:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T04:27:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T04:29:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=200.50.106.161 OUT= PROTO=TCP DPT=80", "src_ip": "200.50.106.161", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T04:29:57", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.173 dst=193.27.228.114 dport=443 bytes=594 interval=30s", "src_ip": "10.0.0.173", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:30:17", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 144", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T04:30:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.173 dst=193.27.228.114 dport=443 bytes=392 interval=30s", "src_ip": "10.0.0.173", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:30:57", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.173 dst=193.27.228.114 dport=443 bytes=699 interval=30s", "src_ip": "10.0.0.173", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:31:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.173 dst=193.27.228.114 dport=443 bytes=307 interval=30s", "src_ip": "10.0.0.173", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:31:57", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.173 dst=193.27.228.114 dport=443 bytes=548 interval=30s", "src_ip": "10.0.0.173", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:32:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.173 dst=193.27.228.114 dport=443 bytes=413 interval=30s", "src_ip": "10.0.0.173", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:32:57", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.173 dst=193.27.228.114 dport=443 bytes=804 interval=30s", "src_ip": "10.0.0.173", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:33:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.173 dst=193.27.228.114 dport=443 bytes=740 interval=30s", "src_ip": "10.0.0.173", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T04:36:20", "source": "nginx", "category": "benign", "severity": "info", "message": "129.208.33.124 - - \"GET / HTTP/1.1\" 200 3538", "src_ip": "129.208.33.124", "status": 200, "path": "/"} {"timestamp": "2026-06-10T04:37:31", "source": "nginx", "category": "benign", "severity": "info", "message": "153.212.188.204 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 677", "src_ip": "153.212.188.204", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T04:43:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T04:43:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T04:43:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T04:43:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T04:43:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T04:43:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T04:43:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T04:43:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T04:47:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=126.115.68.9 OUT= PROTO=TCP DPT=80", "src_ip": "126.115.68.9", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T04:54:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.212 port 53126 ssh2", "src_ip": "10.0.1.212", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T04:55:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.13 port 53722 ssh2", "src_ip": "10.0.4.13", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T05:02:02", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 15", "src_ip": "91.219.236.18", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T05:04:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.233 port 59139 ssh2", "src_ip": "10.0.3.233", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-10T05:05:59", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/bash", "user": "nattapong", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T05:14:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48877 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 44573 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 59067 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:11", "source": "nginx", "category": "benign", "severity": "info", "message": "223.213.237.235 - - \"GET /static/app.js HTTP/1.1\" 200 4884", "src_ip": "223.213.237.235", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T05:14:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 47791 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 43442 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 45024 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 56440 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 59375 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 41617 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 44576 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 54470 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 55274 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48235 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 44156 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 47741 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48335 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 50529 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:14:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 57684 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T05:16:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.167 port 51006 ssh2", "src_ip": "10.0.4.167", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T05:22:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=133.166.10.104 OUT= PROTO=TCP DPT=443", "src_ip": "133.166.10.104", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T05:24:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.56 port 43701 ssh2", "src_ip": "10.0.0.56", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T05:26:51", "source": "nginx", "category": "benign", "severity": "info", "message": "16.125.209.50 - - \"GET / HTTP/1.1\" 200 7424", "src_ip": "16.125.209.50", "status": 200, "path": "/"} {"timestamp": "2026-06-10T05:46:51", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.235 dst=185.220.101.34 bytes=6686769152 proto=TCP dport=443 duration=450s", "src_ip": "10.0.3.235", "dst_ip": "185.220.101.34", "bytes_mb": 6377, "off_hours": true} {"timestamp": "2026-06-10T05:51:40", "source": "nginx", "category": "benign", "severity": "info", "message": "166.133.80.165 - - \"GET /health HTTP/1.1\" 200 5933", "src_ip": "166.133.80.165", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T05:54:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.114 port 43941 ssh2", "src_ip": "10.0.4.114", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T05:59:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=176.23.178.126 OUT= PROTO=TCP DPT=443", "src_ip": "176.23.178.126", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T05:59:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=81.129.14.183 OUT= PROTO=TCP DPT=443", "src_ip": "81.129.14.183", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T06:01:24", "source": "nginx", "category": "benign", "severity": "info", "message": "40.172.86.6 - - \"GET /static/app.js HTTP/1.1\" 200 2871", "src_ip": "40.172.86.6", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T06:04:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=117.94.48.128 OUT= PROTO=TCP DPT=80", "src_ip": "117.94.48.128", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T06:06:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.75 port 47085 ssh2", "src_ip": "10.0.3.75", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T06:06:13", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 312", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T06:07:14", "source": "nginx", "category": "benign", "severity": "info", "message": "136.168.215.147 - - \"GET /health HTTP/1.1\" 200 304", "src_ip": "136.168.215.147", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T06:10:27", "source": "nginx", "category": "web_attack", "severity": "high", "message": "218.0.109.184 - - \"GET /search?q= HTTP/1.1\" 200 398", "src_ip": "218.0.109.184", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T06:12:09", "source": "nginx", "category": "benign", "severity": "info", "message": "189.223.122.15 - - \"GET /login HTTP/1.1\" 200 906", "src_ip": "189.223.122.15", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T06:22:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.225 port 41024 ssh2", "src_ip": "10.0.1.225", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T06:24:32", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.137 dst=91.219.236.18 bytes=4803526656 proto=TCP dport=443 duration=200s", "src_ip": "10.0.2.137", "dst_ip": "91.219.236.18", "bytes_mb": 4581, "off_hours": false} {"timestamp": "2026-06-10T06:24:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=125.104.138.79 OUT= PROTO=TCP DPT=443", "src_ip": "125.104.138.79", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T06:25:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=69.253.234.100 OUT= PROTO=TCP DPT=443", "src_ip": "69.253.234.100", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T06:29:07", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "svc_backup", "host": "web-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-10T06:29:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=30.47.57.137 OUT= PROTO=TCP DPT=80", "src_ip": "30.47.57.137", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T06:30:19", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 403 51", "src_ip": "45.137.21.9", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T06:31:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.100 port 58587 ssh2", "src_ip": "10.0.2.100", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T06:31:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.2.233 port 50858 ssh2", "src_ip": "10.0.2.233", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T06:32:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T06:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T06:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T06:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T06:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T06:32:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T06:32:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T06:32:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T06:32:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T06:32:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=105.44.219.251 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "105.44.219.251", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T06:33:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 43260 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 59551 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 56314 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 47549 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 51227 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 50983 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 47516 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:26", "source": "nginx", "category": "benign", "severity": "info", "message": "18.53.40.46 - - \"GET /api/products HTTP/1.1\" 200 6009", "src_ip": "18.53.40.46", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T06:33:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 51648 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 47774 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 46511 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 42126 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 59837 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 47777 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 44664 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 40997 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 44401 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 55953 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:33:52", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 86.49.211.54 port 51234 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-10T06:33:57", "source": "nginx", "category": "benign", "severity": "info", "message": "36.101.249.244 - - \"GET /api/products HTTP/1.1\" 200 3125", "src_ip": "36.101.249.244", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T06:34:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 55273 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:34:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 86.49.211.54 port 45652 ssh2", "src_ip": "86.49.211.54", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-10T06:34:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T06:34:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T06:34:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T06:34:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T06:34:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T06:34:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T06:34:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T06:34:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T06:34:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=72.223.189.113 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "72.223.189.113", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T06:35:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T06:35:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T06:35:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T06:35:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T06:35:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T06:35:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T06:35:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T06:35:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T06:35:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T06:35:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T06:35:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T06:35:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T06:38:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=63.173.106.187 OUT= PROTO=TCP DPT=443", "src_ip": "63.173.106.187", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T06:41:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.152 port 55913 ssh2", "src_ip": "10.0.3.152", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T06:41:57", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "guest", "host": "app-02", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-10T06:42:14", "source": "nginx", "category": "benign", "severity": "info", "message": "87.165.3.30 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2930", "src_ip": "87.165.3.30", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T06:47:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.108 port 44312 ssh2", "src_ip": "10.0.3.108", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T06:50:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.137 port 47110 ssh2", "src_ip": "10.0.0.137", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-10T06:55:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=718 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:00:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=759 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:05:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=558 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:05:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.94 port 59322 ssh2", "src_ip": "10.0.5.94", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T07:06:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.4 dst=91.219.236.18 dport=443 bytes=761 interval=300s", "src_ip": "10.0.0.4", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:09:55", "source": "nginx", "category": "benign", "severity": "info", "message": "100.204.169.241 - - \"GET / HTTP/1.1\" 200 1144", "src_ip": "100.204.169.241", "status": 200, "path": "/"} {"timestamp": "2026-06-10T07:10:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=861 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:10:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.33 port 40965 ssh2", "src_ip": "10.0.1.33", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-10T07:10:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=56.167.177.145 OUT= PROTO=TCP DPT=80", "src_ip": "56.167.177.145", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T07:11:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.4 dst=91.219.236.18 dport=443 bytes=776 interval=300s", "src_ip": "10.0.0.4", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:15:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=895 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:16:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.4 dst=91.219.236.18 dport=443 bytes=294 interval=300s", "src_ip": "10.0.0.4", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:20:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=225 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:21:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.4 dst=91.219.236.18 dport=443 bytes=833 interval=300s", "src_ip": "10.0.0.4", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:21:47", "source": "nginx", "category": "web_attack", "severity": "high", "message": "149.115.1.99 - - \"GET /search?q= HTTP/1.1\" 200 290", "src_ip": "149.115.1.99", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T07:24:56", "source": "nginx", "category": "benign", "severity": "info", "message": "38.137.65.201 - - \"GET / HTTP/1.1\" 200 7783", "src_ip": "38.137.65.201", "status": 200, "path": "/"} {"timestamp": "2026-06-10T07:25:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=290 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:26:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.4 dst=91.219.236.18 dport=443 bytes=317 interval=300s", "src_ip": "10.0.0.4", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:28:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.120 port 42516 ssh2", "src_ip": "10.0.1.120", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T07:30:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=234 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:31:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.4 dst=91.219.236.18 dport=443 bytes=718 interval=300s", "src_ip": "10.0.0.4", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:32:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.13 port 45037 ssh2", "src_ip": "10.0.2.13", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T07:35:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.136 dst=91.219.236.18 dport=443 bytes=577 interval=300s", "src_ip": "10.0.0.136", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-10T07:35:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.150 port 50681 ssh2", "src_ip": "10.0.4.150", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T07:35:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.127 port 42620 ssh2", "src_ip": "10.0.5.127", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T07:37:13", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 374", "src_ip": "193.27.228.114", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T07:43:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.2.60 port 50272 ssh2", "src_ip": "10.0.2.60", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T07:43:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=116.127.147.147 OUT= PROTO=TCP DPT=80", "src_ip": "116.127.147.147", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T07:44:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 58250 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 50626 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 47505 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 50336 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 46913 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 56358 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 48773 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 48679 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 48081 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 55035 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 44532 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 50311 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 41543 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:44:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45008 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:45:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 59121 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:45:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 51861 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:45:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 58394 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:45:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 48609 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:45:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 59155 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:45:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 56171 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T07:45:31", "source": "nginx", "category": "benign", "severity": "info", "message": "201.236.37.210 - - \"GET /login HTTP/1.1\" 200 2651", "src_ip": "201.236.37.210", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T07:48:47", "source": "nginx", "category": "benign", "severity": "info", "message": "209.220.165.176 - - \"GET /static/app.js HTTP/1.1\" 200 933", "src_ip": "209.220.165.176", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T07:50:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.11 port 56361 ssh2", "src_ip": "10.0.0.11", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-10T07:55:51", "source": "nginx", "category": "benign", "severity": "info", "message": "73.232.206.26 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4515", "src_ip": "73.232.206.26", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T08:04:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=163.80.193.201 OUT= PROTO=TCP DPT=80", "src_ip": "163.80.193.201", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T08:06:19", "source": "nginx", "category": "benign", "severity": "info", "message": "18.189.219.47 - - \"GET /api/products HTTP/1.1\" 200 3915", "src_ip": "18.189.219.47", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T08:07:05", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/bin/bash", "user": "www-data", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T08:10:24", "source": "nginx", "category": "benign", "severity": "info", "message": "206.191.15.237 - - \"GET /login HTTP/1.1\" 200 2830", "src_ip": "206.191.15.237", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T08:10:39", "source": "nginx", "category": "benign", "severity": "info", "message": "139.166.235.172 - - \"GET /login HTTP/1.1\" 200 3340", "src_ip": "139.166.235.172", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T08:12:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T08:12:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T08:12:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T08:12:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T08:12:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T08:12:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T08:12:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T08:12:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T08:15:05", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 403 313", "src_ip": "185.220.101.34", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T08:19:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.181.0.89 OUT= PROTO=TCP DPT=443", "src_ip": "214.181.0.89", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T08:27:32", "source": "nginx", "category": "benign", "severity": "info", "message": "99.153.217.177 - - \"GET /api/products HTTP/1.1\" 200 3942", "src_ip": "99.153.217.177", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T08:27:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=177.99.121.194 OUT= PROTO=TCP DPT=80", "src_ip": "177.99.121.194", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T08:29:54", "source": "nginx", "category": "benign", "severity": "info", "message": "209.31.195.100 - - \"GET /api/products HTTP/1.1\" 200 692", "src_ip": "209.31.195.100", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T08:31:10", "source": "nginx", "category": "benign", "severity": "info", "message": "192.251.125.194 - - \"GET /api/products HTTP/1.1\" 200 3005", "src_ip": "192.251.125.194", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T08:36:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=82.16.91.238 OUT= PROTO=TCP DPT=443", "src_ip": "82.16.91.238", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T08:43:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=712 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T08:44:21", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.109 dst=209.141.56.12 bytes=6383730688 proto=TCP dport=443 duration=505s", "src_ip": "10.0.5.109", "dst_ip": "209.141.56.12", "bytes_mb": 6088, "off_hours": false} {"timestamp": "2026-06-10T08:44:34", "source": "nginx", "category": "benign", "severity": "info", "message": "119.168.17.150 - - \"GET /login HTTP/1.1\" 200 6019", "src_ip": "119.168.17.150", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T08:45:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=200.122.20.220 OUT= PROTO=TCP DPT=443", "src_ip": "200.122.20.220", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T08:47:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.129 port 43191 ssh2", "src_ip": "10.0.5.129", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-10T08:48:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T08:48:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T08:48:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T08:48:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T08:48:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T08:48:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T08:48:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T08:48:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T08:48:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T08:48:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T08:48:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T08:48:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=519 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T08:50:33", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/bash", "user": "somchai", "host": "app-02", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T08:51:52", "source": "nginx", "category": "benign", "severity": "info", "message": "128.158.190.72 - - \"GET /login HTTP/1.1\" 200 737", "src_ip": "128.158.190.72", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T08:53:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=608 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T08:54:12", "source": "nginx", "category": "benign", "severity": "info", "message": "92.72.9.25 - - \"GET /health HTTP/1.1\" 200 3491", "src_ip": "92.72.9.25", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T08:54:59", "source": "nginx", "category": "benign", "severity": "info", "message": "196.17.203.103 - - \"GET /api/products HTTP/1.1\" 200 6181", "src_ip": "196.17.203.103", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T08:58:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=833 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T08:59:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=127.141.218.178 OUT= PROTO=TCP DPT=443", "src_ip": "127.141.218.178", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T09:03:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=258 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T09:05:27", "source": "nginx", "category": "benign", "severity": "info", "message": "204.241.106.167 - - \"GET /health HTTP/1.1\" 200 1903", "src_ip": "204.241.106.167", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T09:08:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=759 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T09:10:22", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.109 dst=193.27.228.114 bytes=3747610624 proto=TCP dport=443 duration=381s", "src_ip": "10.0.5.109", "dst_ip": "193.27.228.114", "bytes_mb": 3574, "off_hours": false} {"timestamp": "2026-06-10T09:13:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=313 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T09:14:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.132 port 53923 ssh2", "src_ip": "10.0.0.132", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-10T09:18:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=796 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T09:18:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 57611 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T09:18:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 42816 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T09:18:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 52464 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T09:18:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 55692 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T09:19:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 56720 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T09:19:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 40413 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T09:19:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 50035 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T09:19:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 55928 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T09:19:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=60.93.48.154 OUT= PROTO=TCP DPT=80", "src_ip": "60.93.48.154", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T09:23:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.63 dst=209.141.56.12 dport=443 bytes=682 interval=300s", "src_ip": "10.0.4.63", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-10T09:23:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=175.143.108.39 OUT= PROTO=TCP DPT=80", "src_ip": "175.143.108.39", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T09:25:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=96.64.48.239 OUT= PROTO=TCP DPT=443", "src_ip": "96.64.48.239", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T09:28:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T09:28:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T09:28:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T09:28:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T09:28:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T09:28:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T09:28:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T09:28:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T09:28:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T09:28:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T09:28:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T09:28:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T09:29:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=221.251.22.10 OUT= PROTO=TCP DPT=443", "src_ip": "221.251.22.10", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T09:29:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.8 port 42341 ssh2", "src_ip": "10.0.4.8", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-10T09:30:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.148 port 52168 ssh2", "src_ip": "10.0.2.148", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T09:31:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T09:31:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T09:31:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T09:31:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T09:31:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T09:31:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T09:31:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T09:31:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T09:31:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T09:31:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T09:42:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=216 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T09:47:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T09:47:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T09:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T09:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T09:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T09:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T09:47:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T09:47:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T09:47:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T09:47:51", "source": "nginx", "category": "benign", "severity": "info", "message": "101.196.98.249 - - \"GET /api/products HTTP/1.1\" 200 503", "src_ip": "101.196.98.249", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T09:47:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=497 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T09:48:27", "source": "nginx", "category": "benign", "severity": "info", "message": "34.101.35.133 - - \"GET / HTTP/1.1\" 200 1108", "src_ip": "34.101.35.133", "status": 200, "path": "/"} {"timestamp": "2026-06-10T09:50:30", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 149", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T09:52:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=835 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T09:53:13", "source": "nginx", "category": "benign", "severity": "info", "message": "174.154.216.103 - - \"GET / HTTP/1.1\" 200 1706", "src_ip": "174.154.216.103", "status": 200, "path": "/"} {"timestamp": "2026-06-10T09:53:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 47855 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 47266 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 46351 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 40758 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 48036 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 43635 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 41695 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 43508 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 52389 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 42718 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 49255 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 42535 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 52805 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 56090 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 53557 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 59526 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 58984 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45918 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 51842 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T09:53:59", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 91.219.236.18 port 51234 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-10T09:55:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.57 dst=209.141.56.12 dport=443 bytes=569 interval=30s", "src_ip": "10.0.4.57", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T09:55:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.57 dst=209.141.56.12 dport=443 bytes=765 interval=30s", "src_ip": "10.0.4.57", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T09:56:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.57 dst=209.141.56.12 dport=443 bytes=505 interval=30s", "src_ip": "10.0.4.57", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T09:56:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.57 dst=209.141.56.12 dport=443 bytes=393 interval=30s", "src_ip": "10.0.4.57", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T09:56:47", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=108.123.254.234 OUT= PROTO=TCP DPT=80", "src_ip": "108.123.254.234", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T09:57:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.57 dst=209.141.56.12 dport=443 bytes=465 interval=30s", "src_ip": "10.0.4.57", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T09:57:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.57 dst=209.141.56.12 dport=443 bytes=535 interval=30s", "src_ip": "10.0.4.57", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T09:57:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=567 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T09:58:16", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.57 dst=209.141.56.12 dport=443 bytes=606 interval=30s", "src_ip": "10.0.4.57", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T09:58:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=199.48.164.230 OUT= PROTO=TCP DPT=443", "src_ip": "199.48.164.230", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T09:59:58", "source": "nginx", "category": "benign", "severity": "info", "message": "13.104.84.174 - - \"GET / HTTP/1.1\" 200 843", "src_ip": "13.104.84.174", "status": 200, "path": "/"} {"timestamp": "2026-06-10T10:00:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.225.188.200 OUT= PROTO=TCP DPT=443", "src_ip": "147.225.188.200", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T10:02:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=665 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T10:05:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 48031 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 54944 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 41318 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 46226 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 57123 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 48708 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 47457 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 59191 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 49092 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 41994 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 42086 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 43220 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:05:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 125.126.125.66 port 55639 ssh2", "src_ip": "125.126.125.66", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T10:07:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=866 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T10:08:10", "source": "nginx", "category": "benign", "severity": "info", "message": "80.211.53.202 - - \"GET /login HTTP/1.1\" 200 7079", "src_ip": "80.211.53.202", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T10:08:33", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "postgres", "host": "web-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-10T10:11:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T10:11:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T10:11:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T10:11:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T10:11:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T10:11:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T10:11:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T10:11:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T10:11:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T10:11:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T10:11:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T10:12:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=653 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T10:13:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=208.94.67.113 OUT= PROTO=TCP DPT=443", "src_ip": "208.94.67.113", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T10:13:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=39.92.211.180 OUT= PROTO=TCP DPT=443", "src_ip": "39.92.211.180", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T10:17:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=641 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T10:18:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.200 port 52858 ssh2", "src_ip": "10.0.2.200", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T10:19:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T10:19:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T10:19:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T10:19:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T10:19:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T10:19:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T10:19:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T10:19:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T10:19:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T10:19:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T10:20:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=59.216.84.213 OUT= PROTO=TCP DPT=443", "src_ip": "59.216.84.213", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T10:22:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=383 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T10:23:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=157.209.11.84 OUT= PROTO=TCP DPT=80", "src_ip": "157.209.11.84", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T10:26:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=120.95.41.167 OUT= PROTO=TCP DPT=80", "src_ip": "120.95.41.167", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T10:27:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.172 dst=185.220.101.34 dport=443 bytes=523 interval=300s", "src_ip": "10.0.1.172", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T10:31:51", "source": "nginx", "category": "benign", "severity": "info", "message": "61.28.130.71 - - \"GET /api/products HTTP/1.1\" 200 618", "src_ip": "61.28.130.71", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T10:33:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.245 port 43219 ssh2", "src_ip": "10.0.3.245", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T10:33:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.209 port 51076 ssh2", "src_ip": "10.0.0.209", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T10:35:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.143 port 42459 ssh2", "src_ip": "10.0.1.143", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T10:39:25", "source": "nginx", "category": "benign", "severity": "info", "message": "213.33.85.131 - - \"GET /dashboard HTTP/1.1\" 200 6354", "src_ip": "213.33.85.131", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T10:40:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=121.252.39.124 OUT= PROTO=TCP DPT=80", "src_ip": "121.252.39.124", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T10:41:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=79.178.235.231 OUT= PROTO=TCP DPT=443", "src_ip": "79.178.235.231", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T10:42:52", "source": "nginx", "category": "benign", "severity": "info", "message": "68.14.163.239 - - \"GET / HTTP/1.1\" 200 7074", "src_ip": "68.14.163.239", "status": 200, "path": "/"} {"timestamp": "2026-06-10T10:49:43", "source": "nginx", "category": "benign", "severity": "info", "message": "193.227.226.39 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7475", "src_ip": "193.227.226.39", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T10:57:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T10:57:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T10:57:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T10:57:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T10:57:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T10:57:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T10:57:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T10:57:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T10:57:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T10:58:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.126 port 57938 ssh2", "src_ip": "10.0.5.126", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T11:00:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.173 port 56703 ssh2", "src_ip": "10.0.5.173", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T11:03:39", "source": "nginx", "category": "benign", "severity": "info", "message": "153.124.105.178 - - \"GET / HTTP/1.1\" 200 815", "src_ip": "153.124.105.178", "status": 200, "path": "/"} {"timestamp": "2026-06-10T11:03:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=140.17.140.3 OUT= PROTO=TCP DPT=80", "src_ip": "140.17.140.3", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T11:06:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.213 port 44638 ssh2", "src_ip": "10.0.0.213", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T11:07:18", "source": "nginx", "category": "benign", "severity": "info", "message": "178.140.56.215 - - \"GET /login HTTP/1.1\" 200 241", "src_ip": "178.140.56.215", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T11:08:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=45.137.21.9 dport=443 bytes=799 interval=60s", "src_ip": "10.0.0.184", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T11:09:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=45.137.21.9 dport=443 bytes=706 interval=60s", "src_ip": "10.0.0.184", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T11:10:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=56.0.42.171 OUT= PROTO=TCP DPT=80", "src_ip": "56.0.42.171", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T11:10:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=45.137.21.9 dport=443 bytes=426 interval=60s", "src_ip": "10.0.0.184", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T11:11:18", "source": "nginx", "category": "benign", "severity": "info", "message": "163.78.89.66 - - \"GET /dashboard HTTP/1.1\" 200 3998", "src_ip": "163.78.89.66", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T11:11:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T11:11:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T11:11:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T11:11:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T11:11:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T11:11:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T11:11:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T11:11:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T11:11:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T11:11:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T11:11:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=37.134.79.22 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "37.134.79.22", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T11:11:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=45.137.21.9 dport=443 bytes=805 interval=60s", "src_ip": "10.0.0.184", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T11:11:55", "source": "nginx", "category": "benign", "severity": "info", "message": "212.47.180.46 - - \"GET /dashboard HTTP/1.1\" 200 6807", "src_ip": "212.47.180.46", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T11:12:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=97.58.206.46 OUT= PROTO=TCP DPT=443", "src_ip": "97.58.206.46", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T11:12:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=45.137.21.9 dport=443 bytes=644 interval=60s", "src_ip": "10.0.0.184", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T11:13:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=45.137.21.9 dport=443 bytes=881 interval=60s", "src_ip": "10.0.0.184", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T11:25:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=161.132.38.6 OUT= PROTO=TCP DPT=80", "src_ip": "161.132.38.6", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T11:33:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=79.30.51.174 OUT= PROTO=TCP DPT=443", "src_ip": "79.30.51.174", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T11:34:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=203.243.181.217 OUT= PROTO=TCP DPT=443", "src_ip": "203.243.181.217", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T11:35:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.194.134.57 OUT= PROTO=TCP DPT=80", "src_ip": "164.194.134.57", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T11:35:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.142 port 52156 ssh2", "src_ip": "10.0.4.142", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T11:36:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=154.124.86.176 OUT= PROTO=TCP DPT=443", "src_ip": "154.124.86.176", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T11:38:37", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/bin/bash", "user": "postgres", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T11:42:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=155.22.247.12 OUT= PROTO=TCP DPT=80", "src_ip": "155.22.247.12", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T11:44:24", "source": "nginx", "category": "benign", "severity": "info", "message": "64.176.108.106 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7175", "src_ip": "64.176.108.106", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T11:45:21", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.144 dst=193.27.228.114 bytes=7090470912 proto=TCP dport=443 duration=486s", "src_ip": "10.0.0.144", "dst_ip": "193.27.228.114", "bytes_mb": 6762, "off_hours": false} {"timestamp": "2026-06-10T11:47:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=192.196.81.97 OUT= PROTO=TCP DPT=443", "src_ip": "192.196.81.97", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T11:49:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T11:49:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T11:49:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T11:49:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T11:49:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T11:49:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T11:49:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T11:49:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T11:49:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T11:54:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=86.126.37.22 OUT= PROTO=TCP DPT=443", "src_ip": "86.126.37.22", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T11:56:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.244 port 44839 ssh2", "src_ip": "10.0.1.244", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T12:02:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=206.91.23.38 OUT= PROTO=TCP DPT=443", "src_ip": "206.91.23.38", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T12:05:47", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=11.5.176.146 OUT= PROTO=TCP DPT=80", "src_ip": "11.5.176.146", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T12:06:50", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 474", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T12:19:52", "source": "nginx", "category": "benign", "severity": "info", "message": "196.205.45.51 - - \"GET /login HTTP/1.1\" 200 886", "src_ip": "196.205.45.51", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T12:29:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.47 port 45286 ssh2", "src_ip": "10.0.3.47", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T12:29:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T12:29:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T12:29:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T12:29:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T12:29:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T12:29:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T12:29:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T12:29:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T12:29:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T12:29:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T12:29:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T12:33:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T12:33:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T12:33:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T12:33:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T12:33:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T12:33:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T12:33:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T12:33:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T12:33:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T12:33:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T12:33:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T12:33:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=207.63.51.172 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "207.63.51.172", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T12:34:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=222.154.178.108 OUT= PROTO=TCP DPT=80", "src_ip": "222.154.178.108", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T12:36:53", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "www-data", "host": "web-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-10T12:37:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.99 port 40298 ssh2", "src_ip": "10.0.4.99", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T12:38:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=110.192.16.79 OUT= PROTO=TCP DPT=443", "src_ip": "110.192.16.79", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T12:41:08", "source": "nginx", "category": "benign", "severity": "info", "message": "96.95.22.85 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4392", "src_ip": "96.95.22.85", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T12:41:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.129 port 46822 ssh2", "src_ip": "10.0.0.129", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T12:42:15", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/bin/bash", "user": "postgres", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T12:43:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 58328 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:43:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 46305 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:43:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 55592 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:43:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 57754 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:44:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 57427 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:44:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 40621 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:44:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 41732 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:44:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 58990 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:44:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 57096 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:44:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 40611 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:44:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 192.12.158.144 port 46743 ssh2", "src_ip": "192.12.158.144", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T12:44:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=20.185.84.91 OUT= PROTO=TCP DPT=443", "src_ip": "20.185.84.91", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T12:46:31", "source": "nginx", "category": "benign", "severity": "info", "message": "82.249.142.168 - - \"GET /login HTTP/1.1\" 200 6189", "src_ip": "82.249.142.168", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T12:46:39", "source": "nginx", "category": "benign", "severity": "info", "message": "196.140.76.104 - - \"GET /dashboard HTTP/1.1\" 200 4812", "src_ip": "196.140.76.104", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T12:48:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.127 port 54293 ssh2", "src_ip": "10.0.5.127", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T12:48:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.2 port 53860 ssh2", "src_ip": "10.0.4.2", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-10T12:49:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 53040 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:49:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 45518 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:49:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 50095 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:49:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 42288 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:49:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 40051 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 45780 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 55940 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 56469 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 53691 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 53659 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 46107 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 49448 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 54121 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:50:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 173.176.73.69 port 44401 ssh2", "src_ip": "173.176.73.69", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T12:52:34", "source": "nginx", "category": "benign", "severity": "info", "message": "219.103.197.228 - - \"GET /api/products HTTP/1.1\" 200 3694", "src_ip": "219.103.197.228", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T12:54:32", "source": "nginx", "category": "benign", "severity": "info", "message": "200.96.59.147 - - \"GET /api/products HTTP/1.1\" 200 1243", "src_ip": "200.96.59.147", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T12:56:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=58.55.145.147 OUT= PROTO=TCP DPT=443", "src_ip": "58.55.145.147", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T12:57:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.235 port 53342 ssh2", "src_ip": "10.0.1.235", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T13:09:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T13:09:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T13:09:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T13:09:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T13:09:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T13:09:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T13:09:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T13:09:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T13:09:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T13:09:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T13:09:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T13:09:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=192.81.47.158 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "192.81.47.158", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T13:10:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T13:10:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T13:10:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T13:10:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T13:10:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T13:10:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T13:10:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T13:10:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T13:10:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T13:10:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T13:10:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T13:10:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T13:12:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 54419 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 42026 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 48377 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 44225 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 48037 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 42459 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 52300 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 43180 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 54494 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 58765 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 50695 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 51972 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 48694 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:12:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 55080 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:13:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 50481 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:13:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 55320 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:13:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 41783 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:13:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 42619 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:13:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 57193 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-10T13:14:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=163.196.236.149 OUT= PROTO=TCP DPT=80", "src_ip": "163.196.236.149", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T13:14:45", "source": "nginx", "category": "benign", "severity": "info", "message": "98.133.160.206 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 603", "src_ip": "98.133.160.206", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T13:16:56", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 202", "src_ip": "185.220.101.34", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T13:17:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=114.160.254.164 OUT= PROTO=TCP DPT=80", "src_ip": "114.160.254.164", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T13:20:52", "source": "nginx", "category": "benign", "severity": "info", "message": "51.50.248.76 - - \"GET /login HTTP/1.1\" 200 5117", "src_ip": "51.50.248.76", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T13:32:07", "source": "nginx", "category": "benign", "severity": "info", "message": "109.124.211.253 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3373", "src_ip": "109.124.211.253", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T13:38:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.108 dst=45.137.21.9 dport=443 bytes=500 interval=300s", "src_ip": "10.0.4.108", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-10T13:43:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.108 dst=45.137.21.9 dport=443 bytes=405 interval=300s", "src_ip": "10.0.4.108", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-10T13:43:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 53995 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:43:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 51380 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:43:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 49890 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:43:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 57693 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:43:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 49827 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:43:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 40609 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:43:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46556 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:43:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 58902 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:43:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 53182 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 56887 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 57942 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 47876 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 49839 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46978 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 57456 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 56915 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 55154 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 55312 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 53443 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 42111 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 54212 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 41962 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46574 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:44:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46670 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T13:48:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.108 dst=45.137.21.9 dport=443 bytes=281 interval=300s", "src_ip": "10.0.4.108", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-10T13:48:38", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.54 port 49913 ssh2", "src_ip": "10.0.5.54", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T13:49:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=729 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:50:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=854 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:51:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=597 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:52:38", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 96", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T13:52:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=261 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:53:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.108 dst=45.137.21.9 dport=443 bytes=685 interval=300s", "src_ip": "10.0.4.108", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-10T13:53:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=206 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:54:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=749 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:55:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=215 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:56:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=310 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:56:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.192 port 53263 ssh2", "src_ip": "10.0.1.192", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T13:57:34", "source": "nginx", "category": "benign", "severity": "info", "message": "125.232.157.69 - - \"GET /dashboard HTTP/1.1\" 200 2086", "src_ip": "125.232.157.69", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T13:57:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.210 dst=185.220.101.34 dport=443 bytes=685 interval=60s", "src_ip": "10.0.4.210", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T13:58:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.108 dst=45.137.21.9 dport=443 bytes=290 interval=300s", "src_ip": "10.0.4.108", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-10T13:59:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T13:59:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T13:59:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T13:59:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T13:59:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T13:59:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T13:59:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T13:59:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T14:01:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=115.242.110.164 OUT= PROTO=TCP DPT=80", "src_ip": "115.242.110.164", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T14:02:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=194.166.205.247 OUT= PROTO=TCP DPT=443", "src_ip": "194.166.205.247", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T14:03:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.166.197.4 OUT= PROTO=TCP DPT=443", "src_ip": "164.166.197.4", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T14:04:29", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 495", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T14:06:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=75.47.33.161 OUT= PROTO=TCP DPT=80", "src_ip": "75.47.33.161", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T14:06:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.188 port 57250 ssh2", "src_ip": "10.0.5.188", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T14:08:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.208 port 46525 ssh2", "src_ip": "10.0.1.208", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T14:12:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=155.110.191.13 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "155.110.191.13", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T14:12:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=155.110.191.13 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "155.110.191.13", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T14:12:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=155.110.191.13 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "155.110.191.13", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T14:12:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=155.110.191.13 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "155.110.191.13", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T14:12:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=155.110.191.13 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "155.110.191.13", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T14:12:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=155.110.191.13 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "155.110.191.13", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T14:12:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=155.110.191.13 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "155.110.191.13", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T14:12:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=155.110.191.13 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "155.110.191.13", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T14:13:18", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 477", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T14:17:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 48432 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:17:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 55941 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:17:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 51937 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 40444 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 49867 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 53445 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 44641 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 48007 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 43694 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 50935 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 57016 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 52379 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 59521 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 56312 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 40679 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 46760 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 54113 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 42925 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 45197 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 88.171.231.126 port 43536 ssh2", "src_ip": "88.171.231.126", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 41382 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 58008 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 51810 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 47136 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 55768 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 47732 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 44002 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:18:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 49047 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 41376 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 49791 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 40493 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 47965 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 54226 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:21", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for guest from 181.106.242.100 port 51234 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-10T14:19:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 43920 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 55573 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 181.106.242.100 port 59536 ssh2", "src_ip": "181.106.242.100", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-10T14:19:35", "source": "nginx", "category": "benign", "severity": "info", "message": "108.172.123.155 - - \"GET /dashboard HTTP/1.1\" 200 481", "src_ip": "108.172.123.155", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T14:36:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=22.216.189.212 OUT= PROTO=TCP DPT=80", "src_ip": "22.216.189.212", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T14:39:03", "source": "nginx", "category": "benign", "severity": "info", "message": "196.154.140.82 - - \"GET /health HTTP/1.1\" 200 3032", "src_ip": "196.154.140.82", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T14:42:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=737 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:43:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=208 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:44:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=210 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:45:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=389 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:46:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=413 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:47:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=227 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:48:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=230 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:49:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=800 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:50:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.221 dst=91.219.236.18 dport=443 bytes=309 interval=60s", "src_ip": "10.0.4.221", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T14:52:15", "source": "nginx", "category": "benign", "severity": "info", "message": "184.255.105.161 - - \"GET /health HTTP/1.1\" 200 1698", "src_ip": "184.255.105.161", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T14:55:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=42.17.5.78 OUT= PROTO=TCP DPT=443", "src_ip": "42.17.5.78", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T14:56:38", "source": "nginx", "category": "benign", "severity": "info", "message": "114.168.22.67 - - \"GET /dashboard HTTP/1.1\" 200 1220", "src_ip": "114.168.22.67", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T15:00:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.204 port 55270 ssh2", "src_ip": "10.0.3.204", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-10T15:03:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.152 port 46554 ssh2", "src_ip": "10.0.1.152", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-10T15:04:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=200.190.66.143 OUT= PROTO=TCP DPT=80", "src_ip": "200.190.66.143", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T15:04:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=53.85.22.107 OUT= PROTO=TCP DPT=80", "src_ip": "53.85.22.107", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T15:07:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.208 port 40787 ssh2", "src_ip": "10.0.3.208", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T15:17:01", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/bin/bash", "user": "www-data", "host": "app-02", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T15:18:53", "source": "nginx", "category": "benign", "severity": "info", "message": "155.246.169.222 - - \"GET / HTTP/1.1\" 200 1194", "src_ip": "155.246.169.222", "status": 200, "path": "/"} {"timestamp": "2026-06-10T15:33:11", "source": "nginx", "category": "web_attack", "severity": "high", "message": "69.68.153.250 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 373", "src_ip": "69.68.153.250", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T15:34:29", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 366", "src_ip": "91.219.236.18", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T15:35:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.25 port 45275 ssh2", "src_ip": "10.0.1.25", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T15:39:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.186.203.187 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.186.203.187", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T15:39:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.186.203.187 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.186.203.187", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T15:39:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.186.203.187 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.186.203.187", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T15:39:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.186.203.187 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.186.203.187", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T15:39:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.186.203.187 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.186.203.187", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T15:39:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.186.203.187 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.186.203.187", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T15:39:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.186.203.187 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.186.203.187", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T15:39:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.186.203.187 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.186.203.187", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T15:39:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=35.60.122.93 OUT= PROTO=TCP DPT=443", "src_ip": "35.60.122.93", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T15:39:59", "source": "nginx", "category": "benign", "severity": "info", "message": "67.113.228.96 - - \"GET /dashboard HTTP/1.1\" 200 3993", "src_ip": "67.113.228.96", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T15:42:23", "source": "nginx", "category": "benign", "severity": "info", "message": "47.211.165.67 - - \"GET /dashboard HTTP/1.1\" 200 7913", "src_ip": "47.211.165.67", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T15:43:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T15:43:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T15:43:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T15:43:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T15:43:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T15:43:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T15:43:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T15:43:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T15:43:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T15:43:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T15:43:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T15:43:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T15:43:58", "source": "nginx", "category": "benign", "severity": "info", "message": "179.158.206.6 - - \"GET / HTTP/1.1\" 200 4846", "src_ip": "179.158.206.6", "status": 200, "path": "/"} {"timestamp": "2026-06-10T15:44:04", "source": "nginx", "category": "benign", "severity": "info", "message": "140.34.138.142 - - \"GET /static/app.js HTTP/1.1\" 200 7135", "src_ip": "140.34.138.142", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T15:50:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.168 port 40538 ssh2", "src_ip": "10.0.0.168", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T15:59:18", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 500 240", "src_ip": "193.27.228.114", "status": 500, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-10T15:59:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.118 port 43740 ssh2", "src_ip": "10.0.0.118", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T15:59:30", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=173.235.3.25 OUT= PROTO=TCP DPT=443", "src_ip": "173.235.3.25", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T16:02:49", "source": "nginx", "category": "benign", "severity": "info", "message": "151.201.108.234 - - \"GET /dashboard HTTP/1.1\" 200 5675", "src_ip": "151.201.108.234", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T16:03:36", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.202 port 47508 ssh2", "src_ip": "10.0.2.202", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T16:06:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.25 port 53758 ssh2", "src_ip": "10.0.1.25", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T16:12:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.204 port 58297 ssh2", "src_ip": "10.0.0.204", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T16:14:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.170 port 51553 ssh2", "src_ip": "10.0.1.170", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T16:17:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.129 port 41231 ssh2", "src_ip": "10.0.5.129", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T16:17:39", "source": "nginx", "category": "benign", "severity": "info", "message": "58.129.251.94 - - \"GET /api/products HTTP/1.1\" 200 2693", "src_ip": "58.129.251.94", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T16:26:47", "source": "nginx", "category": "benign", "severity": "info", "message": "106.27.179.120 - - \"GET /dashboard HTTP/1.1\" 200 7466", "src_ip": "106.27.179.120", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T16:29:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=119.42.78.247 OUT= PROTO=TCP DPT=80", "src_ip": "119.42.78.247", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T16:32:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T16:32:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T16:32:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T16:32:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T16:32:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T16:32:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T16:32:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T16:32:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T16:32:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T16:32:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T16:32:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T16:35:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=40.126.177.171 OUT= PROTO=TCP DPT=80", "src_ip": "40.126.177.171", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T16:44:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=77.205.64.235 OUT= PROTO=TCP DPT=80", "src_ip": "77.205.64.235", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T16:45:00", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "deploy", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-10T16:47:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=105.231.9.156 OUT= PROTO=TCP DPT=80", "src_ip": "105.231.9.156", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T17:01:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=54.23.84.48 OUT= PROTO=TCP DPT=80", "src_ip": "54.23.84.48", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T17:03:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 54.76.121.168 port 52655 ssh2", "src_ip": "54.76.121.168", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T17:03:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 54.76.121.168 port 49282 ssh2", "src_ip": "54.76.121.168", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T17:03:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 54.76.121.168 port 58266 ssh2", "src_ip": "54.76.121.168", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T17:03:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 54.76.121.168 port 40143 ssh2", "src_ip": "54.76.121.168", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T17:03:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 54.76.121.168 port 51557 ssh2", "src_ip": "54.76.121.168", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T17:03:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 54.76.121.168 port 52156 ssh2", "src_ip": "54.76.121.168", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T17:03:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 54.76.121.168 port 50611 ssh2", "src_ip": "54.76.121.168", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T17:03:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 54.76.121.168 port 59026 ssh2", "src_ip": "54.76.121.168", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-10T17:04:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.164 port 51070 ssh2", "src_ip": "10.0.2.164", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-10T17:08:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=199.170.68.12 OUT= PROTO=TCP DPT=443", "src_ip": "199.170.68.12", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T17:12:53", "source": "nginx", "category": "benign", "severity": "info", "message": "138.188.135.208 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6742", "src_ip": "138.188.135.208", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T17:14:13", "source": "nginx", "category": "benign", "severity": "info", "message": "133.35.184.202 - - \"GET /static/app.js HTTP/1.1\" 200 3651", "src_ip": "133.35.184.202", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T17:23:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.32 port 41045 ssh2", "src_ip": "10.0.0.32", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T17:24:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.179 port 56235 ssh2", "src_ip": "10.0.3.179", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T17:28:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=69.178.114.120 OUT= PROTO=TCP DPT=443", "src_ip": "69.178.114.120", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T17:34:05", "source": "nginx", "category": "benign", "severity": "info", "message": "187.223.115.44 - - \"GET / HTTP/1.1\" 200 1765", "src_ip": "187.223.115.44", "status": 200, "path": "/"} {"timestamp": "2026-06-10T17:34:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.141 port 40469 ssh2", "src_ip": "10.0.1.141", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T17:40:51", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "www-data", "host": "bastion-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-10T17:43:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.82 port 53320 ssh2", "src_ip": "10.0.3.82", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T17:49:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.124 port 59916 ssh2", "src_ip": "10.0.5.124", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T17:50:25", "source": "nginx", "category": "benign", "severity": "info", "message": "50.14.41.118 - - \"GET /health HTTP/1.1\" 200 5997", "src_ip": "50.14.41.118", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T17:52:24", "source": "nginx", "category": "benign", "severity": "info", "message": "72.238.62.69 - - \"GET /dashboard HTTP/1.1\" 200 2230", "src_ip": "72.238.62.69", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T17:52:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.203 port 44302 ssh2", "src_ip": "10.0.3.203", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T17:53:33", "source": "nginx", "category": "benign", "severity": "info", "message": "194.132.52.9 - - \"GET / HTTP/1.1\" 200 776", "src_ip": "194.132.52.9", "status": 200, "path": "/"} {"timestamp": "2026-06-10T17:53:47", "source": "nginx", "category": "benign", "severity": "info", "message": "89.0.157.73 - - \"GET /login HTTP/1.1\" 200 6338", "src_ip": "89.0.157.73", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T17:54:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T17:55:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T17:55:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T17:55:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T17:55:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T17:55:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T17:55:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T17:55:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T17:55:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T17:55:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T17:55:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T17:58:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.200 port 45215 ssh2", "src_ip": "10.0.2.200", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T18:01:29", "source": "nginx", "category": "benign", "severity": "info", "message": "143.199.217.252 - - \"GET /health HTTP/1.1\" 200 4438", "src_ip": "143.199.217.252", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T18:03:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.114 port 53381 ssh2", "src_ip": "10.0.2.114", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T18:03:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T18:03:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T18:03:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T18:03:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T18:03:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T18:03:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T18:03:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T18:03:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T18:03:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T18:03:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T18:04:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=121.254.247.172 OUT= PROTO=TCP DPT=80", "src_ip": "121.254.247.172", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T18:06:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T18:06:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T18:06:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T18:06:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T18:06:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T18:06:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T18:06:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T18:06:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T18:06:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T18:06:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T18:06:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T18:07:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.87 dst=209.141.56.12 dport=443 bytes=574 interval=30s", "src_ip": "10.0.0.87", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T18:08:25", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.87 dst=209.141.56.12 dport=443 bytes=711 interval=30s", "src_ip": "10.0.0.87", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T18:08:45", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.66 dst=193.27.228.114 bytes=7479492608 proto=TCP dport=443 duration=310s", "src_ip": "10.0.2.66", "dst_ip": "193.27.228.114", "bytes_mb": 7133, "off_hours": false} {"timestamp": "2026-06-10T18:08:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.87 dst=209.141.56.12 dport=443 bytes=840 interval=30s", "src_ip": "10.0.0.87", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T18:09:25", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.87 dst=209.141.56.12 dport=443 bytes=409 interval=30s", "src_ip": "10.0.0.87", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T18:09:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.87 dst=209.141.56.12 dport=443 bytes=516 interval=30s", "src_ip": "10.0.0.87", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-10T18:19:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 51264 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42918 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44619 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47115 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58245 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40192 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48295 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57731 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48981 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48410 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58081 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44012 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48951 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:19:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53338 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:20:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58478 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:20:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42469 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:20:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48638 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:20:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=22.37.181.244 OUT= PROTO=TCP DPT=443", "src_ip": "22.37.181.244", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T18:20:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 56369 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:20:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58547 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T18:25:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.101 dst=91.219.236.18 dport=443 bytes=343 interval=60s", "src_ip": "10.0.3.101", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T18:26:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.101 dst=91.219.236.18 dport=443 bytes=385 interval=60s", "src_ip": "10.0.3.101", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T18:27:19", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 52", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T18:27:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.101 dst=91.219.236.18 dport=443 bytes=325 interval=60s", "src_ip": "10.0.3.101", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T18:28:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.101 dst=91.219.236.18 dport=443 bytes=570 interval=60s", "src_ip": "10.0.3.101", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T18:29:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.101 dst=91.219.236.18 dport=443 bytes=255 interval=60s", "src_ip": "10.0.3.101", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T18:31:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.156 port 50992 ssh2", "src_ip": "10.0.2.156", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T18:37:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=219.194.167.127 OUT= PROTO=TCP DPT=80", "src_ip": "219.194.167.127", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T18:39:50", "source": "nginx", "category": "benign", "severity": "info", "message": "209.13.108.187 - - \"GET /login HTTP/1.1\" 200 3150", "src_ip": "209.13.108.187", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T18:44:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.42.205.10 OUT= PROTO=TCP DPT=443", "src_ip": "167.42.205.10", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T18:48:05", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-10T18:52:11", "source": "nginx", "category": "benign", "severity": "info", "message": "160.157.13.153 - - \"GET /dashboard HTTP/1.1\" 200 2375", "src_ip": "160.157.13.153", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T18:56:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=74.82.21.18 OUT= PROTO=TCP DPT=443", "src_ip": "74.82.21.18", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T18:59:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T18:59:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T18:59:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T18:59:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T18:59:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T18:59:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T18:59:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T18:59:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T18:59:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T18:59:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T18:59:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T19:01:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.93 port 42499 ssh2", "src_ip": "10.0.2.93", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T19:04:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T19:04:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T19:04:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T19:04:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T19:04:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T19:04:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T19:04:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T19:04:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T19:06:58", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.108 dst=45.137.21.9 bytes=7216300032 proto=TCP dport=443 duration=159s", "src_ip": "10.0.3.108", "dst_ip": "45.137.21.9", "bytes_mb": 6882, "off_hours": false} {"timestamp": "2026-06-10T19:12:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T19:12:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T19:12:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T19:12:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T19:12:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T19:12:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T19:12:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T19:12:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T19:12:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T19:14:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.75 port 49653 ssh2", "src_ip": "10.0.4.75", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T19:16:02", "source": "nginx", "category": "benign", "severity": "info", "message": "64.156.233.62 - - \"GET /api/products HTTP/1.1\" 200 6831", "src_ip": "64.156.233.62", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T19:18:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.231 port 41169 ssh2", "src_ip": "10.0.0.231", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T19:20:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=108.62.146.44 OUT= PROTO=TCP DPT=80", "src_ip": "108.62.146.44", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T19:22:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.43 port 44587 ssh2", "src_ip": "10.0.5.43", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T19:23:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.49 port 42739 ssh2", "src_ip": "10.0.3.49", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T19:31:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.4.11 port 52098 ssh2", "src_ip": "10.0.4.11", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T19:31:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 50039 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:31:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 53338 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:31:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 44741 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:31:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 49880 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:31:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 51814 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:31:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 43042 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 44317 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 44720 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 59258 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 40557 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 45984 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 45933 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 44277 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 53019 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 42696 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 54617 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 45907 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 40740 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 51571 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 43092 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 48899 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 53401 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-10T19:32:36", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for deploy from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-10T19:34:42", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 483", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T19:39:52", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.221 dst=209.141.56.12 bytes=1470103552 proto=TCP dport=443 duration=235s", "src_ip": "10.0.3.221", "dst_ip": "209.141.56.12", "bytes_mb": 1402, "off_hours": false} {"timestamp": "2026-06-10T19:41:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=650 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:42:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=337 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:43:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=817 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:44:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=852 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:45:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=200 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:45:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=106.78.222.140 OUT= PROTO=TCP DPT=443", "src_ip": "106.78.222.140", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T19:46:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=112.215.106.228 OUT= PROTO=TCP DPT=443", "src_ip": "112.215.106.228", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T19:46:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=518 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:47:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=687 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:48:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=680 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:48:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.148 dst=45.137.21.9 dport=443 bytes=649 interval=60s", "src_ip": "10.0.4.148", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T19:49:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.253 dst=91.219.236.18 dport=443 bytes=463 interval=60s", "src_ip": "10.0.3.253", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T19:49:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.148 dst=45.137.21.9 dport=443 bytes=564 interval=60s", "src_ip": "10.0.4.148", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T19:50:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.148 dst=45.137.21.9 dport=443 bytes=793 interval=60s", "src_ip": "10.0.4.148", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T19:51:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.148 dst=45.137.21.9 dport=443 bytes=733 interval=60s", "src_ip": "10.0.4.148", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T19:51:38", "source": "nginx", "category": "benign", "severity": "info", "message": "210.108.225.75 - - \"GET / HTTP/1.1\" 200 7909", "src_ip": "210.108.225.75", "status": 200, "path": "/"} {"timestamp": "2026-06-10T19:52:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.148 dst=45.137.21.9 dport=443 bytes=406 interval=60s", "src_ip": "10.0.4.148", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T19:52:57", "source": "nginx", "category": "benign", "severity": "info", "message": "157.12.233.94 - - \"GET /health HTTP/1.1\" 200 2463", "src_ip": "157.12.233.94", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T19:53:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.148 dst=45.137.21.9 dport=443 bytes=879 interval=60s", "src_ip": "10.0.4.148", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T19:54:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 55235 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.148 dst=45.137.21.9 dport=443 bytes=403 interval=60s", "src_ip": "10.0.4.148", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T19:54:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 42563 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 48035 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 59990 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 42558 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 55363 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=171.103.141.27 OUT= PROTO=TCP DPT=443", "src_ip": "171.103.141.27", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T19:54:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 57668 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 41157 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 57531 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 50239 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 56798 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 41729 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 58807 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 51564 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:54:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 49476 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 50863 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 42012 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 59583 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 49963 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 58471 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 55504 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:26", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.148 dst=45.137.21.9 dport=443 bytes=363 interval=60s", "src_ip": "10.0.4.148", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-10T19:55:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 45540 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 41691 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:55:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 134.40.72.187 port 49560 ssh2", "src_ip": "134.40.72.187", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T19:59:35", "source": "nginx", "category": "benign", "severity": "info", "message": "41.78.255.239 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2590", "src_ip": "41.78.255.239", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T20:01:04", "source": "nginx", "category": "benign", "severity": "info", "message": "75.37.99.108 - - \"GET /api/products HTTP/1.1\" 200 2374", "src_ip": "75.37.99.108", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T20:03:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.45 port 57189 ssh2", "src_ip": "10.0.3.45", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-10T20:06:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.21 port 53959 ssh2", "src_ip": "10.0.3.21", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T20:06:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.5.248 port 47642 ssh2", "src_ip": "10.0.5.248", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-10T20:07:13", "source": "nginx", "category": "benign", "severity": "info", "message": "176.26.52.98 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7170", "src_ip": "176.26.52.98", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T20:14:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.192 port 43151 ssh2", "src_ip": "10.0.0.192", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T20:15:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.19 port 46008 ssh2", "src_ip": "10.0.3.19", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T20:21:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=130.64.199.232 OUT= PROTO=TCP DPT=443", "src_ip": "130.64.199.232", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T20:27:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T20:27:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T20:27:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T20:27:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T20:27:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T20:28:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T20:28:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T20:28:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T20:28:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T20:33:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=72.227.209.93 OUT= PROTO=TCP DPT=80", "src_ip": "72.227.209.93", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T20:37:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.50 dst=91.219.236.18 dport=443 bytes=646 interval=60s", "src_ip": "10.0.4.50", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T20:38:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.50 dst=91.219.236.18 dport=443 bytes=201 interval=60s", "src_ip": "10.0.4.50", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T20:39:18", "source": "nginx", "category": "benign", "severity": "info", "message": "92.35.106.2 - - \"GET /api/products HTTP/1.1\" 200 2984", "src_ip": "92.35.106.2", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-10T20:39:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.50 dst=91.219.236.18 dport=443 bytes=732 interval=60s", "src_ip": "10.0.4.50", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T20:40:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.50 dst=91.219.236.18 dport=443 bytes=751 interval=60s", "src_ip": "10.0.4.50", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T20:41:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.50 dst=91.219.236.18 dport=443 bytes=886 interval=60s", "src_ip": "10.0.4.50", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-10T20:43:43", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "www-data", "host": "web-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-10T20:45:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T20:45:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T20:45:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T20:45:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T20:45:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T20:45:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T20:45:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T20:45:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T20:45:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T20:45:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T20:45:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T20:45:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.84.71.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "36.84.71.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T20:47:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.156 port 52095 ssh2", "src_ip": "10.0.5.156", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T20:47:58", "source": "nginx", "category": "benign", "severity": "info", "message": "56.203.202.186 - - \"GET / HTTP/1.1\" 200 1972", "src_ip": "56.203.202.186", "status": 200, "path": "/"} {"timestamp": "2026-06-10T20:48:39", "source": "nginx", "category": "benign", "severity": "info", "message": "28.195.112.174 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2083", "src_ip": "28.195.112.174", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-10T20:59:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.34 port 54447 ssh2", "src_ip": "10.0.4.34", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T21:05:27", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/bash", "user": "deploy", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-10T21:07:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.179 dst=193.27.228.114 dport=443 bytes=768 interval=30s", "src_ip": "10.0.4.179", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T21:07:38", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.179 dst=193.27.228.114 dport=443 bytes=657 interval=30s", "src_ip": "10.0.4.179", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T21:08:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.179 dst=193.27.228.114 dport=443 bytes=521 interval=30s", "src_ip": "10.0.4.179", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T21:08:38", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.179 dst=193.27.228.114 dport=443 bytes=325 interval=30s", "src_ip": "10.0.4.179", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T21:09:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.179 dst=193.27.228.114 dport=443 bytes=240 interval=30s", "src_ip": "10.0.4.179", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-10T21:09:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.116 port 44862 ssh2", "src_ip": "10.0.4.116", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-10T21:14:16", "source": "nginx", "category": "benign", "severity": "info", "message": "40.54.254.51 - - \"GET /static/app.js HTTP/1.1\" 200 1836", "src_ip": "40.54.254.51", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T21:15:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.103 port 46437 ssh2", "src_ip": "10.0.2.103", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T21:18:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.131 port 44862 ssh2", "src_ip": "10.0.3.131", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-10T21:22:50", "source": "nginx", "category": "benign", "severity": "info", "message": "89.81.207.176 - - \"GET /static/app.js HTTP/1.1\" 200 7762", "src_ip": "89.81.207.176", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T21:23:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=86.180.100.174 OUT= PROTO=TCP DPT=80", "src_ip": "86.180.100.174", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T21:24:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=69.212.169.185 OUT= PROTO=TCP DPT=80", "src_ip": "69.212.169.185", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T21:25:02", "source": "nginx", "category": "benign", "severity": "info", "message": "32.22.77.46 - - \"GET /dashboard HTTP/1.1\" 200 4545", "src_ip": "32.22.77.46", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-10T21:29:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.38 port 47424 ssh2", "src_ip": "10.0.5.38", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-10T21:30:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 48676 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:30:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 57840 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:30:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 45158 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:30:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 46403 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:30:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 43812 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:30:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 50378 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:30:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 46995 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:30:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 58565 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:30:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 41829 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T21:35:52", "source": "nginx", "category": "benign", "severity": "info", "message": "83.24.38.182 - - \"GET /login HTTP/1.1\" 200 875", "src_ip": "83.24.38.182", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T21:36:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=80.190.211.5 OUT= PROTO=TCP DPT=443", "src_ip": "80.190.211.5", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T21:41:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.105 port 41059 ssh2", "src_ip": "10.0.5.105", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-10T21:43:51", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 335", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T21:45:26", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "www-data", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-10T21:46:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.189 dst=185.220.101.34 dport=443 bytes=465 interval=300s", "src_ip": "10.0.4.189", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T21:51:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.189 dst=185.220.101.34 dport=443 bytes=366 interval=300s", "src_ip": "10.0.4.189", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T21:56:04", "source": "nginx", "category": "web_attack", "severity": "high", "message": "63.188.205.62 - - \"GET /search?q= HTTP/1.1\" 403 374", "src_ip": "63.188.205.62", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T21:56:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.189 dst=185.220.101.34 dport=443 bytes=795 interval=300s", "src_ip": "10.0.4.189", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T21:57:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.200 dst=185.220.101.34 dport=443 bytes=754 interval=60s", "src_ip": "10.0.1.200", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T21:58:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=45.93.93.108 OUT= PROTO=TCP DPT=443", "src_ip": "45.93.93.108", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T21:58:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.200 dst=185.220.101.34 dport=443 bytes=352 interval=60s", "src_ip": "10.0.1.200", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T21:59:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.200 dst=185.220.101.34 dport=443 bytes=446 interval=60s", "src_ip": "10.0.1.200", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T22:00:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.200 dst=185.220.101.34 dport=443 bytes=801 interval=60s", "src_ip": "10.0.1.200", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T22:01:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.200 dst=185.220.101.34 dport=443 bytes=518 interval=60s", "src_ip": "10.0.1.200", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T22:01:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.189 dst=185.220.101.34 dport=443 bytes=259 interval=300s", "src_ip": "10.0.4.189", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T22:02:00", "source": "nginx", "category": "benign", "severity": "info", "message": "218.117.13.2 - - \"GET /static/app.js HTTP/1.1\" 200 5058", "src_ip": "218.117.13.2", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T22:02:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.200 dst=185.220.101.34 dport=443 bytes=721 interval=60s", "src_ip": "10.0.1.200", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T22:03:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.200 dst=185.220.101.34 dport=443 bytes=478 interval=60s", "src_ip": "10.0.1.200", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T22:04:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.200 dst=185.220.101.34 dport=443 bytes=841 interval=60s", "src_ip": "10.0.1.200", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-10T22:05:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=68.249.132.88 OUT= PROTO=TCP DPT=443", "src_ip": "68.249.132.88", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T22:06:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.117 port 49894 ssh2", "src_ip": "10.0.0.117", "user": "root", "action": "login_success"} {"timestamp": "2026-06-10T22:06:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.189 dst=185.220.101.34 dport=443 bytes=349 interval=300s", "src_ip": "10.0.4.189", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-10T22:07:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=217.81.102.98 OUT= PROTO=TCP DPT=80", "src_ip": "217.81.102.98", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T22:10:45", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 486", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T22:11:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 53054 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:11:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 41307 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:11:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 53088 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:11:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 44783 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:11:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 45536 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:11:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 56762 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:11:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 44065 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:11:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 54419 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:11:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 176.12.224.124 port 58999 ssh2", "src_ip": "176.12.224.124", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-10T22:18:33", "source": "nginx", "category": "benign", "severity": "info", "message": "169.52.14.58 - - \"GET / HTTP/1.1\" 200 6962", "src_ip": "169.52.14.58", "status": 200, "path": "/"} {"timestamp": "2026-06-10T22:21:12", "source": "nginx", "category": "web_attack", "severity": "high", "message": "134.196.32.164 - - \"GET /search?q= HTTP/1.1\" 200 79", "src_ip": "134.196.32.164", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T22:28:08", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 235", "src_ip": "91.219.236.18", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-10T22:28:30", "source": "nginx", "category": "benign", "severity": "info", "message": "146.182.85.37 - - \"GET / HTTP/1.1\" 200 850", "src_ip": "146.182.85.37", "status": 200, "path": "/"} {"timestamp": "2026-06-10T22:31:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.144 port 46557 ssh2", "src_ip": "10.0.5.144", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-10T22:43:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=120.233.186.239 OUT= PROTO=TCP DPT=80", "src_ip": "120.233.186.239", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T22:45:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.226 port 54154 ssh2", "src_ip": "10.0.2.226", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-10T22:47:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=71.99.165.183 OUT= PROTO=TCP DPT=443", "src_ip": "71.99.165.183", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T22:49:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=174.146.55.139 OUT= PROTO=TCP DPT=443", "src_ip": "174.146.55.139", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T22:51:30", "source": "nginx", "category": "benign", "severity": "info", "message": "205.249.221.196 - - \"GET /static/app.js HTTP/1.1\" 200 496", "src_ip": "205.249.221.196", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-10T22:53:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.3 port 54100 ssh2", "src_ip": "10.0.2.3", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-10T22:53:59", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-10T22:55:05", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.188 dst=193.27.228.114 bytes=8044675072 proto=TCP dport=443 duration=373s", "src_ip": "10.0.4.188", "dst_ip": "193.27.228.114", "bytes_mb": 7672, "off_hours": false} {"timestamp": "2026-06-10T22:56:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 47412 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 43571 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 42461 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 41014 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 44868 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 55908 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 46449 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 43760 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 47473 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 47289 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 47111 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 59390 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 55256 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 57396 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 44952 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T22:56:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 49952 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-10T23:04:45", "source": "nginx", "category": "benign", "severity": "info", "message": "71.219.124.159 - - \"GET / HTTP/1.1\" 200 690", "src_ip": "71.219.124.159", "status": 200, "path": "/"} {"timestamp": "2026-06-10T23:09:25", "source": "nginx", "category": "benign", "severity": "info", "message": "20.10.134.150 - - \"GET /login HTTP/1.1\" 200 4655", "src_ip": "20.10.134.150", "status": 200, "path": "/login"} {"timestamp": "2026-06-10T23:12:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=548 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:13:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=242 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:14:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=730 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:15:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=421 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:16:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=711 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:16:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=87.186.87.109 OUT= PROTO=TCP DPT=80", "src_ip": "87.186.87.109", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T23:17:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=490 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:17:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=66.215.42.224 OUT= PROTO=TCP DPT=80", "src_ip": "66.215.42.224", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-10T23:18:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=581 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:18:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=201.232.78.19 OUT= PROTO=TCP DPT=443", "src_ip": "201.232.78.19", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T23:19:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=612 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:20:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.184 dst=209.141.56.12 dport=443 bytes=237 interval=60s", "src_ip": "10.0.2.184", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-10T23:21:59", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/su -", "user": "guest", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-10T23:24:39", "source": "nginx", "category": "web_attack", "severity": "high", "message": "198.161.193.245 - - \"GET /search?q= HTTP/1.1\" 403 371", "src_ip": "198.161.193.245", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T23:26:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.36 port 51108 ssh2", "src_ip": "10.0.3.36", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-10T23:30:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=88.108.154.165 OUT= PROTO=TCP DPT=443", "src_ip": "88.108.154.165", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T23:39:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=48.252.220.229 OUT= PROTO=TCP DPT=443", "src_ip": "48.252.220.229", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-10T23:42:15", "source": "nginx", "category": "benign", "severity": "info", "message": "203.16.110.32 - - \"GET /health HTTP/1.1\" 200 2089", "src_ip": "203.16.110.32", "status": 200, "path": "/health"} {"timestamp": "2026-06-10T23:44:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-10T23:44:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-10T23:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-10T23:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-10T23:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-10T23:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-10T23:44:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-10T23:44:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-10T23:44:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-10T23:44:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-10T23:44:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-10T23:44:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-10T23:48:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.210 port 54685 ssh2", "src_ip": "10.0.2.210", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-10T23:48:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 58071 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:48:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49644 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:48:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 56246 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:48:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 56798 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:48:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49210 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 46326 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 45667 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 55985 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 43371 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 45428 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 54619 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 59253 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 59540 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 43524 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 46544 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 42105 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 48902 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 52551 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:49:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 51564 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-10T23:50:00", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 266", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-10T23:51:14", "source": "nginx", "category": "benign", "severity": "info", "message": "57.144.22.81 - - \"GET /api/products HTTP/1.1\" 200 5134", "src_ip": "57.144.22.81", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T00:02:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=68.1.11.251 OUT= PROTO=TCP DPT=443", "src_ip": "68.1.11.251", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T00:02:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.66 port 51924 ssh2", "src_ip": "10.0.3.66", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T00:03:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 156.116.140.50 port 57463 ssh2", "src_ip": "156.116.140.50", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T00:03:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 156.116.140.50 port 48287 ssh2", "src_ip": "156.116.140.50", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T00:03:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T00:03:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T00:03:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T00:03:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T00:03:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T00:03:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 156.116.140.50 port 58353 ssh2", "src_ip": "156.116.140.50", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T00:03:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 156.116.140.50 port 40064 ssh2", "src_ip": "156.116.140.50", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T00:03:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T00:03:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T00:03:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T00:03:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 156.116.140.50 port 56983 ssh2", "src_ip": "156.116.140.50", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T00:03:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 156.116.140.50 port 41699 ssh2", "src_ip": "156.116.140.50", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T00:03:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 156.116.140.50 port 54173 ssh2", "src_ip": "156.116.140.50", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T00:03:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 156.116.140.50 port 48979 ssh2", "src_ip": "156.116.140.50", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T00:08:43", "source": "nginx", "category": "benign", "severity": "info", "message": "45.178.135.202 - - \"GET /login HTTP/1.1\" 200 523", "src_ip": "45.178.135.202", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T00:15:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.56 port 48850 ssh2", "src_ip": "10.0.4.56", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T00:22:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.47 port 52235 ssh2", "src_ip": "10.0.0.47", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T00:27:05", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/su -", "user": "nattapong", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T00:27:58", "source": "nginx", "category": "benign", "severity": "info", "message": "217.97.237.241 - - \"GET / HTTP/1.1\" 200 1385", "src_ip": "217.97.237.241", "status": 200, "path": "/"} {"timestamp": "2026-06-11T00:29:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=43.219.88.54 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "43.219.88.54", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T00:29:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=43.219.88.54 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "43.219.88.54", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T00:29:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=43.219.88.54 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "43.219.88.54", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T00:29:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=43.219.88.54 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "43.219.88.54", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T00:29:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=43.219.88.54 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "43.219.88.54", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T00:29:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=43.219.88.54 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "43.219.88.54", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T00:29:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=43.219.88.54 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "43.219.88.54", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T00:29:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=43.219.88.54 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "43.219.88.54", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T00:30:00", "source": "nginx", "category": "benign", "severity": "info", "message": "22.31.97.190 - - \"GET /health HTTP/1.1\" 200 3456", "src_ip": "22.31.97.190", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T00:33:22", "source": "nginx", "category": "benign", "severity": "info", "message": "29.66.23.31 - - \"GET /health HTTP/1.1\" 200 4806", "src_ip": "29.66.23.31", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T00:33:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=92.202.141.28 OUT= PROTO=TCP DPT=443", "src_ip": "92.202.141.28", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T00:37:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 45139 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:37:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 59713 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:37:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 52102 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:37:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 52110 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:37:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 43615 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:37:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 57130 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:38:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 43858 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:38:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 49489 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:38:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 49991 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T00:38:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=83.174.191.207 OUT= PROTO=TCP DPT=80", "src_ip": "83.174.191.207", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T00:39:40", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 204", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T00:42:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.97 port 52525 ssh2", "src_ip": "10.0.0.97", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T00:47:00", "source": "nginx", "category": "benign", "severity": "info", "message": "179.94.56.179 - - \"GET /login HTTP/1.1\" 200 2275", "src_ip": "179.94.56.179", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T00:48:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.168 port 43507 ssh2", "src_ip": "10.0.4.168", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T00:48:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.206 dst=209.141.56.12 dport=443 bytes=876 interval=30s", "src_ip": "10.0.2.206", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T00:48:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.206 dst=209.141.56.12 dport=443 bytes=226 interval=30s", "src_ip": "10.0.2.206", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T00:49:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.206 dst=209.141.56.12 dport=443 bytes=334 interval=30s", "src_ip": "10.0.2.206", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T00:49:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.206 dst=209.141.56.12 dport=443 bytes=215 interval=30s", "src_ip": "10.0.2.206", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T00:50:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.206 dst=209.141.56.12 dport=443 bytes=566 interval=30s", "src_ip": "10.0.2.206", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T00:53:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T00:53:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T00:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T00:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T00:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T00:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T00:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T00:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T00:53:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T00:53:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T00:55:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.52 port 55986 ssh2", "src_ip": "10.0.4.52", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T00:58:19", "source": "nginx", "category": "benign", "severity": "info", "message": "91.18.49.202 - - \"GET / HTTP/1.1\" 200 902", "src_ip": "91.18.49.202", "status": 200, "path": "/"} {"timestamp": "2026-06-11T01:00:05", "source": "nginx", "category": "benign", "severity": "info", "message": "135.57.210.113 - - \"GET / HTTP/1.1\" 200 718", "src_ip": "135.57.210.113", "status": 200, "path": "/"} {"timestamp": "2026-06-11T01:01:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.219 port 50322 ssh2", "src_ip": "10.0.2.219", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T01:02:31", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 500", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T01:02:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=78.82.226.142 OUT= PROTO=TCP DPT=443", "src_ip": "78.82.226.142", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T01:06:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.106 port 55204 ssh2", "src_ip": "10.0.0.106", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T01:09:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=80.43.39.19 OUT= PROTO=TCP DPT=443", "src_ip": "80.43.39.19", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T01:10:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.81 port 51880 ssh2", "src_ip": "10.0.2.81", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T01:14:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=101.50.175.48 OUT= PROTO=TCP DPT=443", "src_ip": "101.50.175.48", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T01:19:28", "source": "nginx", "category": "benign", "severity": "info", "message": "174.245.217.67 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2292", "src_ip": "174.245.217.67", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T01:20:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.118 port 50170 ssh2", "src_ip": "10.0.0.118", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T01:23:17", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.109 dst=91.219.236.18 bytes=3662675968 proto=TCP dport=443 duration=236s", "src_ip": "10.0.4.109", "dst_ip": "91.219.236.18", "bytes_mb": 3493, "off_hours": true} {"timestamp": "2026-06-11T01:24:03", "source": "nginx", "category": "benign", "severity": "info", "message": "99.215.227.189 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 375", "src_ip": "99.215.227.189", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T01:25:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.5.242 port 44833 ssh2", "src_ip": "10.0.5.242", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T01:26:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=104.139.84.66 OUT= PROTO=TCP DPT=443", "src_ip": "104.139.84.66", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T01:28:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 54025 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 53770 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 52165 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 41311 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 53265 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 56657 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 45239 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 40079 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 43423 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 53488 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 51692 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 58798 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 48757 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 53223 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 59497 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 59208 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:28:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 42325 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:29:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 59619 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:29:10", "source": "nginx", "category": "benign", "severity": "info", "message": "189.50.202.102 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4977", "src_ip": "189.50.202.102", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T01:29:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 47129 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:29:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 58701 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:29:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 55872 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:29:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 58819 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:29:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 49102 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:29:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 42535 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T01:35:13", "source": "nginx", "category": "benign", "severity": "info", "message": "102.87.103.89 - - \"GET /dashboard HTTP/1.1\" 200 1090", "src_ip": "102.87.103.89", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T01:36:01", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.63 dst=185.220.101.34 bytes=6086983680 proto=TCP dport=443 duration=152s", "src_ip": "10.0.2.63", "dst_ip": "185.220.101.34", "bytes_mb": 5805, "off_hours": true} {"timestamp": "2026-06-11T01:37:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.119 port 54743 ssh2", "src_ip": "10.0.5.119", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T01:43:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.24.166.129 OUT= PROTO=TCP DPT=80", "src_ip": "214.24.166.129", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T01:43:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 45376 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47624 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 45913 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47587 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 53854 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 46092 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 40568 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 49117 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47928 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 57531 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T01:44:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=190.200.5.96 OUT= PROTO=TCP DPT=80", "src_ip": "190.200.5.96", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T01:47:17", "source": "nginx", "category": "benign", "severity": "info", "message": "66.231.158.138 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5726", "src_ip": "66.231.158.138", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T01:50:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T01:50:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T01:50:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T01:50:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T01:50:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T01:50:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T01:50:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T01:50:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T01:50:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T01:50:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T01:50:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=113.167.144.210 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "113.167.144.210", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T01:52:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T01:52:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T01:52:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T01:52:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T01:52:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T01:52:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T01:52:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T01:52:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T01:52:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T01:53:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=11.243.2.231 OUT= PROTO=TCP DPT=80", "src_ip": "11.243.2.231", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T01:56:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.64 port 56266 ssh2", "src_ip": "10.0.1.64", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T02:00:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=50.228.224.199 OUT= PROTO=TCP DPT=443", "src_ip": "50.228.224.199", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T02:03:30", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=29.166.211.212 OUT= PROTO=TCP DPT=80", "src_ip": "29.166.211.212", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T02:03:37", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.229 dst=185.220.101.34 bytes=1442840576 proto=TCP dport=443 duration=219s", "src_ip": "10.0.0.229", "dst_ip": "185.220.101.34", "bytes_mb": 1376, "off_hours": true} {"timestamp": "2026-06-11T02:08:09", "source": "nginx", "category": "benign", "severity": "info", "message": "100.106.133.217 - - \"GET /dashboard HTTP/1.1\" 200 7652", "src_ip": "100.106.133.217", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T02:08:42", "source": "nginx", "category": "benign", "severity": "info", "message": "135.38.137.190 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4554", "src_ip": "135.38.137.190", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T02:09:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 54861 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 50500 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.5.15 port 42235 ssh2", "src_ip": "10.0.5.15", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T02:09:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 45790 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 49743 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 58485 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 43175 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 59270 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 51177 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 41374 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 51381 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 49347 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 52585 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 57209 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 45846 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 56653 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 57011 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 58846 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:45", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for oppa from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-11T02:09:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 46903 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:09:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 50301 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T02:11:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.92.29.217 OUT= PROTO=TCP DPT=443", "src_ip": "164.92.29.217", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T02:11:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.12 port 41709 ssh2", "src_ip": "10.0.2.12", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T02:15:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=87.201.76.29 OUT= PROTO=TCP DPT=80", "src_ip": "87.201.76.29", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T02:15:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.41 port 44334 ssh2", "src_ip": "10.0.3.41", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T02:24:42", "source": "nginx", "category": "benign", "severity": "info", "message": "52.27.139.93 - - \"GET /dashboard HTTP/1.1\" 200 5412", "src_ip": "52.27.139.93", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T02:24:51", "source": "nginx", "category": "benign", "severity": "info", "message": "172.197.134.119 - - \"GET /login HTTP/1.1\" 200 410", "src_ip": "172.197.134.119", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T02:26:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.3.241.105 OUT= PROTO=TCP DPT=80", "src_ip": "47.3.241.105", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T02:28:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T02:28:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T02:28:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T02:28:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T02:28:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T02:28:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T02:28:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T02:28:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T02:28:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T02:29:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.208 port 53626 ssh2", "src_ip": "10.0.5.208", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-11T02:32:20", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 421", "src_ip": "45.137.21.9", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-11T02:35:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T02:35:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T02:35:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T02:35:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T02:35:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T02:35:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T02:35:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T02:35:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T02:35:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T02:35:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T02:36:51", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/su -", "user": "guest", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T02:37:51", "source": "nginx", "category": "benign", "severity": "info", "message": "29.199.191.2 - - \"GET /dashboard HTTP/1.1\" 200 739", "src_ip": "29.199.191.2", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T02:38:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=112.65.48.169 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "112.65.48.169", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T02:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=112.65.48.169 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "112.65.48.169", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T02:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=112.65.48.169 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "112.65.48.169", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T02:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=112.65.48.169 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "112.65.48.169", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T02:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=112.65.48.169 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "112.65.48.169", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T02:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=112.65.48.169 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "112.65.48.169", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T02:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=112.65.48.169 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "112.65.48.169", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T02:38:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=112.65.48.169 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "112.65.48.169", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T02:39:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.75.205.176 OUT= PROTO=TCP DPT=80", "src_ip": "214.75.205.176", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T02:41:53", "source": "nginx", "category": "benign", "severity": "info", "message": "182.237.248.119 - - \"GET / HTTP/1.1\" 200 876", "src_ip": "182.237.248.119", "status": 200, "path": "/"} {"timestamp": "2026-06-11T02:47:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=35.20.158.202 OUT= PROTO=TCP DPT=443", "src_ip": "35.20.158.202", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T02:49:39", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 380", "src_ip": "91.219.236.18", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-11T02:49:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 59176 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:49:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 56190 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:49:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 40879 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:49:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 45047 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:49:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 55186 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:49:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 49426 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:49:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 49835 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:49:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 45877 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:49:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 55484 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T02:52:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.193 port 58246 ssh2", "src_ip": "10.0.2.193", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T02:57:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=189.194.114.83 OUT= PROTO=TCP DPT=80", "src_ip": "189.194.114.83", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T02:57:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.121 port 46808 ssh2", "src_ip": "10.0.1.121", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T02:58:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T02:58:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T02:58:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T02:58:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T02:58:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T02:58:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T02:58:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T02:58:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T02:58:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T02:58:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T02:58:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.113.42.113 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "159.113.42.113", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T03:00:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.218 port 43314 ssh2", "src_ip": "10.0.2.218", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T03:02:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=92.165.198.194 OUT= PROTO=TCP DPT=443", "src_ip": "92.165.198.194", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T03:04:26", "source": "nginx", "category": "benign", "severity": "info", "message": "79.90.83.37 - - \"GET /static/app.js HTTP/1.1\" 200 7925", "src_ip": "79.90.83.37", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T03:07:54", "source": "nginx", "category": "benign", "severity": "info", "message": "86.197.94.201 - - \"GET / HTTP/1.1\" 200 991", "src_ip": "86.197.94.201", "status": 200, "path": "/"} {"timestamp": "2026-06-11T03:10:17", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/bash", "user": "nattapong", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-11T03:14:47", "source": "nginx", "category": "benign", "severity": "info", "message": "165.64.111.229 - - \"GET /static/app.js HTTP/1.1\" 200 3732", "src_ip": "165.64.111.229", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T03:15:34", "source": "nginx", "category": "benign", "severity": "info", "message": "104.127.119.66 - - \"GET /health HTTP/1.1\" 200 2660", "src_ip": "104.127.119.66", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T03:24:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=204.0.75.170 OUT= PROTO=TCP DPT=80", "src_ip": "204.0.75.170", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T03:27:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=101.202.179.206 OUT= PROTO=TCP DPT=80", "src_ip": "101.202.179.206", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T03:28:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T03:28:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T03:28:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T03:28:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T03:28:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T03:28:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T03:28:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T03:28:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T03:28:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T03:40:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.154.202.63 OUT= PROTO=TCP DPT=80", "src_ip": "214.154.202.63", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T03:42:10", "source": "nginx", "category": "benign", "severity": "info", "message": "207.140.9.210 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1856", "src_ip": "207.140.9.210", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T03:43:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.8 port 47242 ssh2", "src_ip": "10.0.2.8", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T03:45:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=146.153.240.106 OUT= PROTO=TCP DPT=443", "src_ip": "146.153.240.106", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T03:46:34", "source": "nginx", "category": "benign", "severity": "info", "message": "57.142.236.64 - - \"GET /health HTTP/1.1\" 200 7763", "src_ip": "57.142.236.64", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T03:52:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.149 port 51567 ssh2", "src_ip": "10.0.2.149", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T03:54:05", "source": "nginx", "category": "benign", "severity": "info", "message": "93.127.3.67 - - \"GET /dashboard HTTP/1.1\" 200 2129", "src_ip": "93.127.3.67", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T03:55:35", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 232", "src_ip": "45.137.21.9", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-11T04:07:23", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "guest", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-11T04:10:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=216.145.125.44 OUT= PROTO=TCP DPT=80", "src_ip": "216.145.125.44", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T04:10:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=70.101.188.140 OUT= PROTO=TCP DPT=80", "src_ip": "70.101.188.140", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T04:16:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=141.47.168.1 OUT= PROTO=TCP DPT=80", "src_ip": "141.47.168.1", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T04:17:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.69 port 43182 ssh2", "src_ip": "10.0.1.69", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T04:20:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 42033 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 54553 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 51048 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 54144 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 43413 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 42199 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 40765 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 59840 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 41267 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 46789 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 43532 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 55146 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:20:49", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for www-data from 155.8.94.243 port 51234 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-11T04:20:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 155.8.94.243 port 46841 ssh2", "src_ip": "155.8.94.243", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-11T04:24:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=81.101.233.85 OUT= PROTO=TCP DPT=80", "src_ip": "81.101.233.85", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T04:28:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T04:28:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T04:28:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T04:28:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T04:28:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T04:28:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T04:28:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T04:28:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T04:28:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T04:28:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T04:28:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T04:28:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T04:29:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T04:29:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T04:29:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T04:29:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T04:29:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T04:29:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T04:29:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T04:29:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T04:29:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T04:29:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T04:29:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T04:30:45", "source": "nginx", "category": "benign", "severity": "info", "message": "118.106.216.35 - - \"GET /health HTTP/1.1\" 200 4370", "src_ip": "118.106.216.35", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T04:30:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=116.216.155.17 OUT= PROTO=TCP DPT=443", "src_ip": "116.216.155.17", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T04:37:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.239 port 47529 ssh2", "src_ip": "10.0.4.239", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T04:38:50", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.84 dst=209.141.56.12 dport=443 bytes=620 interval=30s", "src_ip": "10.0.0.84", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T04:39:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.84 dst=209.141.56.12 dport=443 bytes=509 interval=30s", "src_ip": "10.0.0.84", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T04:39:50", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.84 dst=209.141.56.12 dport=443 bytes=335 interval=30s", "src_ip": "10.0.0.84", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T04:40:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.84 dst=209.141.56.12 dport=443 bytes=573 interval=30s", "src_ip": "10.0.0.84", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T04:40:50", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.84 dst=209.141.56.12 dport=443 bytes=541 interval=30s", "src_ip": "10.0.0.84", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T04:41:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.84 dst=209.141.56.12 dport=443 bytes=230 interval=30s", "src_ip": "10.0.0.84", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T04:41:50", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.84 dst=209.141.56.12 dport=443 bytes=691 interval=30s", "src_ip": "10.0.0.84", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T04:42:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.84 dst=209.141.56.12 dport=443 bytes=770 interval=30s", "src_ip": "10.0.0.84", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T04:44:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.99 port 40112 ssh2", "src_ip": "10.0.0.99", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T04:47:17", "source": "nginx", "category": "web_attack", "severity": "high", "message": "187.245.108.202 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 132", "src_ip": "187.245.108.202", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-11T04:59:26", "source": "nginx", "category": "benign", "severity": "info", "message": "25.211.213.143 - - \"GET /static/app.js HTTP/1.1\" 200 1298", "src_ip": "25.211.213.143", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T05:04:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.207 dst=185.220.101.34 dport=443 bytes=483 interval=30s", "src_ip": "10.0.3.207", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T05:04:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.207 dst=185.220.101.34 dport=443 bytes=387 interval=30s", "src_ip": "10.0.3.207", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T05:05:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.207 dst=185.220.101.34 dport=443 bytes=642 interval=30s", "src_ip": "10.0.3.207", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T05:05:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.207 dst=185.220.101.34 dport=443 bytes=554 interval=30s", "src_ip": "10.0.3.207", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T05:06:27", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 392", "src_ip": "193.27.228.114", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-11T05:06:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.207 dst=185.220.101.34 dport=443 bytes=496 interval=30s", "src_ip": "10.0.3.207", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T05:06:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.207 dst=185.220.101.34 dport=443 bytes=266 interval=30s", "src_ip": "10.0.3.207", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T05:07:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.207 dst=185.220.101.34 dport=443 bytes=647 interval=30s", "src_ip": "10.0.3.207", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T05:07:44", "source": "nginx", "category": "benign", "severity": "info", "message": "170.117.169.218 - - \"GET /login HTTP/1.1\" 200 7417", "src_ip": "170.117.169.218", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T05:08:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.163 port 58731 ssh2", "src_ip": "10.0.3.163", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T05:15:08", "source": "nginx", "category": "benign", "severity": "info", "message": "166.124.205.77 - - \"GET /api/products HTTP/1.1\" 200 578", "src_ip": "166.124.205.77", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T05:15:18", "source": "nginx", "category": "benign", "severity": "info", "message": "107.51.49.86 - - \"GET /static/app.js HTTP/1.1\" 200 2458", "src_ip": "107.51.49.86", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T05:18:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=221.230.101.166 OUT= PROTO=TCP DPT=443", "src_ip": "221.230.101.166", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T05:19:45", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.147 dst=193.27.228.114 bytes=792723456 proto=TCP dport=443 duration=449s", "src_ip": "10.0.2.147", "dst_ip": "193.27.228.114", "bytes_mb": 756, "off_hours": true} {"timestamp": "2026-06-11T05:20:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.146 port 45900 ssh2", "src_ip": "10.0.3.146", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T05:23:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.148 port 51037 ssh2", "src_ip": "10.0.2.148", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T05:31:40", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.131 port 43154 ssh2", "src_ip": "10.0.4.131", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-11T05:38:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 200 329", "src_ip": "193.27.228.114", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T05:39:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.211 port 42287 ssh2", "src_ip": "10.0.2.211", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T05:39:32", "source": "nginx", "category": "benign", "severity": "info", "message": "35.20.69.226 - - \"GET /dashboard HTTP/1.1\" 200 4073", "src_ip": "35.20.69.226", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T05:41:18", "source": "nginx", "category": "benign", "severity": "info", "message": "218.156.201.251 - - \"GET /health HTTP/1.1\" 200 6415", "src_ip": "218.156.201.251", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T05:43:18", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/su -", "user": "guest", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T05:48:01", "source": "nginx", "category": "benign", "severity": "info", "message": "185.76.148.160 - - \"GET /static/app.js HTTP/1.1\" 200 5642", "src_ip": "185.76.148.160", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T05:49:57", "source": "nginx", "category": "benign", "severity": "info", "message": "162.183.75.112 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2379", "src_ip": "162.183.75.112", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T05:54:01", "source": "nginx", "category": "benign", "severity": "info", "message": "184.7.214.84 - - \"GET / HTTP/1.1\" 200 3784", "src_ip": "184.7.214.84", "status": 200, "path": "/"} {"timestamp": "2026-06-11T06:01:04", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.83 dst=209.141.56.12 dport=443 bytes=289 interval=300s", "src_ip": "10.0.2.83", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T06:02:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=508 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:02:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=324 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:03:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=225 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:03:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=614 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:04:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=711 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:04:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=348 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:04:50", "source": "nginx", "category": "benign", "severity": "info", "message": "43.21.157.94 - - \"GET /health HTTP/1.1\" 200 7250", "src_ip": "43.21.157.94", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T06:05:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=669 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:05:38", "source": "nginx", "category": "benign", "severity": "info", "message": "45.138.26.165 - - \"GET /login HTTP/1.1\" 200 6945", "src_ip": "45.138.26.165", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T06:05:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=527 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:06:04", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.83 dst=209.141.56.12 dport=443 bytes=597 interval=300s", "src_ip": "10.0.2.83", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T06:06:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.140 dst=185.220.101.34 dport=443 bytes=359 interval=30s", "src_ip": "10.0.3.140", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-11T06:11:04", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.83 dst=209.141.56.12 dport=443 bytes=769 interval=300s", "src_ip": "10.0.2.83", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T06:14:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.11 port 55409 ssh2", "src_ip": "10.0.1.11", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T06:16:04", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.83 dst=209.141.56.12 dport=443 bytes=606 interval=300s", "src_ip": "10.0.2.83", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T06:17:07", "source": "nginx", "category": "benign", "severity": "info", "message": "11.193.217.173 - - \"GET /login HTTP/1.1\" 200 4397", "src_ip": "11.193.217.173", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T06:18:56", "source": "nginx", "category": "benign", "severity": "info", "message": "71.179.215.22 - - \"GET /dashboard HTTP/1.1\" 200 3557", "src_ip": "71.179.215.22", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T06:20:09", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/su -", "user": "deploy", "host": "web-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T06:20:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=94.45.209.100 OUT= PROTO=TCP DPT=80", "src_ip": "94.45.209.100", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T06:20:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T06:20:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T06:20:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T06:20:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T06:20:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T06:20:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T06:20:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T06:20:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T06:20:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T06:20:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T06:21:04", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.83 dst=209.141.56.12 dport=443 bytes=765 interval=300s", "src_ip": "10.0.2.83", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T06:24:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=158.85.178.170 OUT= PROTO=TCP DPT=80", "src_ip": "158.85.178.170", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T06:24:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=132.254.90.41 OUT= PROTO=TCP DPT=80", "src_ip": "132.254.90.41", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T06:33:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=62.109.247.44 OUT= PROTO=TCP DPT=443", "src_ip": "62.109.247.44", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T06:39:27", "source": "nginx", "category": "benign", "severity": "info", "message": "206.40.39.246 - - \"GET /login HTTP/1.1\" 200 4831", "src_ip": "206.40.39.246", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T06:39:42", "source": "nginx", "category": "benign", "severity": "info", "message": "166.61.100.92 - - \"GET /dashboard HTTP/1.1\" 200 3962", "src_ip": "166.61.100.92", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T06:40:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.98 dst=209.141.56.12 dport=443 bytes=805 interval=30s", "src_ip": "10.0.2.98", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T06:40:53", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.98 dst=209.141.56.12 dport=443 bytes=398 interval=30s", "src_ip": "10.0.2.98", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T06:41:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.98 dst=209.141.56.12 dport=443 bytes=575 interval=30s", "src_ip": "10.0.2.98", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T06:41:53", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.98 dst=209.141.56.12 dport=443 bytes=558 interval=30s", "src_ip": "10.0.2.98", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T06:42:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.98 dst=209.141.56.12 dport=443 bytes=589 interval=30s", "src_ip": "10.0.2.98", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-11T06:45:47", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/bin/su -", "user": "www-data", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T06:47:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.121 port 55298 ssh2", "src_ip": "10.0.3.121", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T06:54:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=49.59.106.41 OUT= PROTO=TCP DPT=80", "src_ip": "49.59.106.41", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T06:54:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.3.176 port 43564 ssh2", "src_ip": "10.0.3.176", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T06:58:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=125.189.89.67 OUT= PROTO=TCP DPT=80", "src_ip": "125.189.89.67", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T06:59:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.173 port 59170 ssh2", "src_ip": "10.0.0.173", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-11T07:04:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.175 port 58782 ssh2", "src_ip": "10.0.3.175", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T07:10:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.97 port 49701 ssh2", "src_ip": "10.0.0.97", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-11T07:11:08", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.122 dst=45.137.21.9 bytes=2048917504 proto=TCP dport=443 duration=93s", "src_ip": "10.0.0.122", "dst_ip": "45.137.21.9", "bytes_mb": 1954, "off_hours": false} {"timestamp": "2026-06-11T07:12:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.246 port 47712 ssh2", "src_ip": "10.0.3.246", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T07:13:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.138 port 53424 ssh2", "src_ip": "10.0.0.138", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-11T07:14:56", "source": "nginx", "category": "benign", "severity": "info", "message": "20.64.169.223 - - \"GET / HTTP/1.1\" 200 7361", "src_ip": "20.64.169.223", "status": 200, "path": "/"} {"timestamp": "2026-06-11T07:15:40", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "somchai", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-11T07:17:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 55067 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:17:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 41465 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:17:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 40291 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:17:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 57944 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:17:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 57803 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:17:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 41331 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:17:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 51037 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:17:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 40755 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:17:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 55729 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 54239 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 52730 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 43171 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 57150 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 50431 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 59796 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 58786 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 59316 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 42702 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 49087 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 47180 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 56424 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 48005 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 44917 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 52103 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:18:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 48491 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T07:19:58", "source": "nginx", "category": "benign", "severity": "info", "message": "98.172.148.233 - - \"GET /dashboard HTTP/1.1\" 200 4469", "src_ip": "98.172.148.233", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T07:21:50", "source": "nginx", "category": "benign", "severity": "info", "message": "184.194.62.236 - - \"GET /api/products HTTP/1.1\" 200 6655", "src_ip": "184.194.62.236", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T07:24:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=132.34.46.213 OUT= PROTO=TCP DPT=80", "src_ip": "132.34.46.213", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T07:28:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=30.90.252.119 OUT= PROTO=TCP DPT=443", "src_ip": "30.90.252.119", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T07:32:59", "source": "nginx", "category": "benign", "severity": "info", "message": "148.184.114.37 - - \"GET /api/products HTTP/1.1\" 200 5419", "src_ip": "148.184.114.37", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T07:33:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=199.90.67.22 OUT= PROTO=TCP DPT=443", "src_ip": "199.90.67.22", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T07:37:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.124 port 41201 ssh2", "src_ip": "10.0.3.124", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-11T07:38:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=126.189.190.114 OUT= PROTO=TCP DPT=80", "src_ip": "126.189.190.114", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T07:40:53", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 49", "src_ip": "45.137.21.9", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-11T07:44:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.202 port 59647 ssh2", "src_ip": "10.0.3.202", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T07:49:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 43383 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:49:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 55558 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:49:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 45133 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:49:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 57925 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:49:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 50616 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:49:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 54996 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:49:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 53708 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:49:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 46963 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:50:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 57974 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:50:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 56390 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:50:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 49391 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:50:08", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-11T07:50:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 54062 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T07:50:41", "source": "nginx", "category": "benign", "severity": "info", "message": "203.211.196.61 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3805", "src_ip": "203.211.196.61", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T07:52:16", "source": "nginx", "category": "benign", "severity": "info", "message": "21.223.248.220 - - \"GET /api/products HTTP/1.1\" 200 7829", "src_ip": "21.223.248.220", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T07:52:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.199 port 45424 ssh2", "src_ip": "10.0.5.199", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-11T07:52:39", "source": "nginx", "category": "benign", "severity": "info", "message": "114.8.67.51 - - \"GET /api/products HTTP/1.1\" 200 6751", "src_ip": "114.8.67.51", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T07:52:43", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 403 336", "src_ip": "45.137.21.9", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T07:52:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=110.162.184.28 OUT= PROTO=TCP DPT=80", "src_ip": "110.162.184.28", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T07:53:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=199.126.110.83 OUT= PROTO=TCP DPT=443", "src_ip": "199.126.110.83", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T08:00:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.222 port 56406 ssh2", "src_ip": "10.0.0.222", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T08:05:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=221.45.106.115 OUT= PROTO=TCP DPT=80", "src_ip": "221.45.106.115", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T08:05:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.23 port 59975 ssh2", "src_ip": "10.0.1.23", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T08:20:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=113.101.77.106 OUT= PROTO=TCP DPT=443", "src_ip": "113.101.77.106", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T08:20:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.82 dst=209.141.56.12 dport=443 bytes=587 interval=300s", "src_ip": "10.0.4.82", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T08:21:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.52 port 42447 ssh2", "src_ip": "10.0.2.52", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T08:22:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.175 port 56143 ssh2", "src_ip": "10.0.0.175", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T08:25:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.82 dst=209.141.56.12 dport=443 bytes=696 interval=300s", "src_ip": "10.0.4.82", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T08:25:59", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.125 dst=45.137.21.9 bytes=985661440 proto=TCP dport=443 duration=492s", "src_ip": "10.0.1.125", "dst_ip": "45.137.21.9", "bytes_mb": 940, "off_hours": false} {"timestamp": "2026-06-11T08:30:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.82 dst=209.141.56.12 dport=443 bytes=863 interval=300s", "src_ip": "10.0.4.82", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T08:35:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=109.221.92.242 OUT= PROTO=TCP DPT=443", "src_ip": "109.221.92.242", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T08:35:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.82 dst=209.141.56.12 dport=443 bytes=373 interval=300s", "src_ip": "10.0.4.82", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T08:36:42", "source": "nginx", "category": "web_attack", "severity": "high", "message": "181.247.247.31 - - \"GET /search?q= HTTP/1.1\" 200 208", "src_ip": "181.247.247.31", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T08:37:00", "source": "nginx", "category": "benign", "severity": "info", "message": "34.193.64.191 - - \"GET /login HTTP/1.1\" 200 3480", "src_ip": "34.193.64.191", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T08:37:25", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.188 dst=45.137.21.9 bytes=7146045440 proto=TCP dport=443 duration=91s", "src_ip": "10.0.5.188", "dst_ip": "45.137.21.9", "bytes_mb": 6815, "off_hours": false} {"timestamp": "2026-06-11T08:39:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=131.253.84.20 OUT= PROTO=TCP DPT=443", "src_ip": "131.253.84.20", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T08:40:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.82 dst=209.141.56.12 dport=443 bytes=737 interval=300s", "src_ip": "10.0.4.82", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T08:42:48", "source": "nginx", "category": "web_attack", "severity": "high", "message": "94.242.213.200 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 478", "src_ip": "94.242.213.200", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-11T08:45:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.82 dst=209.141.56.12 dport=443 bytes=693 interval=300s", "src_ip": "10.0.4.82", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T08:47:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=89.115.9.126 OUT= PROTO=TCP DPT=443", "src_ip": "89.115.9.126", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T08:49:19", "source": "nginx", "category": "benign", "severity": "info", "message": "156.185.209.45 - - \"GET /static/app.js HTTP/1.1\" 200 6896", "src_ip": "156.185.209.45", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T08:50:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.82 dst=209.141.56.12 dport=443 bytes=379 interval=300s", "src_ip": "10.0.4.82", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-11T09:01:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.226.180.232 OUT= PROTO=TCP DPT=443", "src_ip": "164.226.180.232", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T09:01:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=113.37.114.100 OUT= PROTO=TCP DPT=443", "src_ip": "113.37.114.100", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T09:04:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=200.130.62.50 OUT= PROTO=TCP DPT=80", "src_ip": "200.130.62.50", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T09:05:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=163.215.193.105 OUT= PROTO=TCP DPT=80", "src_ip": "163.215.193.105", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T09:08:29", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.81 dst=185.220.101.34 bytes=6399459328 proto=TCP dport=443 duration=499s", "src_ip": "10.0.5.81", "dst_ip": "185.220.101.34", "bytes_mb": 6103, "off_hours": false} {"timestamp": "2026-06-11T09:11:00", "source": "nginx", "category": "benign", "severity": "info", "message": "106.144.198.105 - - \"GET /health HTTP/1.1\" 200 2971", "src_ip": "106.144.198.105", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T09:18:34", "source": "nginx", "category": "web_attack", "severity": "high", "message": "70.49.54.128 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 200 407", "src_ip": "70.49.54.128", "status": 200, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-11T09:21:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=70.238.71.230 OUT= PROTO=TCP DPT=80", "src_ip": "70.238.71.230", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T09:23:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=35.71.169.28 OUT= PROTO=TCP DPT=80", "src_ip": "35.71.169.28", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T09:23:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 40532 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T09:23:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 50819 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T09:23:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 47062 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T09:23:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 58796 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T09:23:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 40326 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T09:23:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 40719 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T09:23:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 46464 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T09:24:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 53378 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T09:28:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.6 port 40275 ssh2", "src_ip": "10.0.3.6", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T09:32:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.4.175 port 54358 ssh2", "src_ip": "10.0.4.175", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-11T09:33:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=75.68.63.104 OUT= PROTO=TCP DPT=80", "src_ip": "75.68.63.104", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T09:34:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.65 port 59564 ssh2", "src_ip": "10.0.4.65", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T09:38:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=198.20.122.132 OUT= PROTO=TCP DPT=443", "src_ip": "198.20.122.132", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T09:40:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=91.67.187.37 OUT= PROTO=TCP DPT=80", "src_ip": "91.67.187.37", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T09:45:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.203.151.69 OUT= PROTO=TCP DPT=443", "src_ip": "167.203.151.69", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T09:46:43", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.48 dst=209.141.56.12 bytes=2030043136 proto=TCP dport=443 duration=217s", "src_ip": "10.0.2.48", "dst_ip": "209.141.56.12", "bytes_mb": 1936, "off_hours": false} {"timestamp": "2026-06-11T09:49:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.215 port 48281 ssh2", "src_ip": "10.0.4.215", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T09:52:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.230 port 58752 ssh2", "src_ip": "10.0.0.230", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T09:56:53", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.79 dst=91.219.236.18 bytes=7672430592 proto=TCP dport=443 duration=402s", "src_ip": "10.0.1.79", "dst_ip": "91.219.236.18", "bytes_mb": 7317, "off_hours": false} {"timestamp": "2026-06-11T09:57:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.166 port 52594 ssh2", "src_ip": "10.0.0.166", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T10:06:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=33.212.37.121 OUT= PROTO=TCP DPT=443", "src_ip": "33.212.37.121", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T10:07:01", "source": "nginx", "category": "benign", "severity": "info", "message": "87.233.180.108 - - \"GET /login HTTP/1.1\" 200 7258", "src_ip": "87.233.180.108", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T10:07:03", "source": "nginx", "category": "benign", "severity": "info", "message": "70.253.142.16 - - \"GET /login HTTP/1.1\" 200 5107", "src_ip": "70.253.142.16", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T10:15:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=95.190.81.179 OUT= PROTO=TCP DPT=80", "src_ip": "95.190.81.179", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T10:16:44", "source": "nginx", "category": "benign", "severity": "info", "message": "94.114.139.172 - - \"GET /dashboard HTTP/1.1\" 200 5346", "src_ip": "94.114.139.172", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T10:19:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=122.195.145.217 OUT= PROTO=TCP DPT=443", "src_ip": "122.195.145.217", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T10:28:31", "source": "nginx", "category": "benign", "severity": "info", "message": "204.51.64.212 - - \"GET /dashboard HTTP/1.1\" 200 5673", "src_ip": "204.51.64.212", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T10:32:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.148 port 59187 ssh2", "src_ip": "10.0.3.148", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-11T10:38:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T10:38:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T10:38:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T10:38:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T10:38:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T10:38:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T10:38:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T10:38:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T10:38:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T10:38:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T10:38:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T10:38:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T10:42:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.243 port 47925 ssh2", "src_ip": "10.0.5.243", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T10:42:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=198.63.46.30 OUT= PROTO=TCP DPT=443", "src_ip": "198.63.46.30", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T10:45:20", "source": "nginx", "category": "web_attack", "severity": "high", "message": "136.220.68.80 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 345", "src_ip": "136.220.68.80", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-11T10:45:32", "source": "nginx", "category": "benign", "severity": "info", "message": "46.209.54.66 - - \"GET /static/app.js HTTP/1.1\" 200 1804", "src_ip": "46.209.54.66", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T10:48:29", "source": "nginx", "category": "benign", "severity": "info", "message": "26.201.18.170 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1436", "src_ip": "26.201.18.170", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T10:50:38", "source": "nginx", "category": "benign", "severity": "info", "message": "190.151.176.193 - - \"GET /dashboard HTTP/1.1\" 200 1880", "src_ip": "190.151.176.193", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T10:58:27", "source": "nginx", "category": "benign", "severity": "info", "message": "51.167.192.219 - - \"GET / HTTP/1.1\" 200 1024", "src_ip": "51.167.192.219", "status": 200, "path": "/"} {"timestamp": "2026-06-11T10:59:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.97 port 59059 ssh2", "src_ip": "10.0.4.97", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T11:02:31", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.225 dst=185.220.101.34 bytes=5734662144 proto=TCP dport=443 duration=493s", "src_ip": "10.0.4.225", "dst_ip": "185.220.101.34", "bytes_mb": 5469, "off_hours": false} {"timestamp": "2026-06-11T11:07:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=33.104.42.58 OUT= PROTO=TCP DPT=80", "src_ip": "33.104.42.58", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T11:10:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 43190 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 50416 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 49474 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 41034 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 40925 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 42070 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 55867 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 53644 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 42140 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 44154 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:10:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 48476 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T11:11:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=173.115.77.139 OUT= PROTO=TCP DPT=443", "src_ip": "173.115.77.139", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T11:14:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.171 port 57112 ssh2", "src_ip": "10.0.2.171", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T11:23:44", "source": "nginx", "category": "benign", "severity": "info", "message": "57.207.9.225 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6163", "src_ip": "57.207.9.225", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T11:24:31", "source": "nginx", "category": "benign", "severity": "info", "message": "202.11.170.88 - - \"GET /api/products HTTP/1.1\" 200 6010", "src_ip": "202.11.170.88", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T11:26:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.242 port 44862 ssh2", "src_ip": "10.0.5.242", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T11:33:25", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.34 dst=209.141.56.12 bytes=7437549568 proto=TCP dport=443 duration=97s", "src_ip": "10.0.3.34", "dst_ip": "209.141.56.12", "bytes_mb": 7093, "off_hours": false} {"timestamp": "2026-06-11T11:33:29", "source": "nginx", "category": "benign", "severity": "info", "message": "146.245.26.44 - - \"GET /api/products HTTP/1.1\" 200 4927", "src_ip": "146.245.26.44", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T11:34:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=39.5.157.86 OUT= PROTO=TCP DPT=80", "src_ip": "39.5.157.86", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T11:40:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 45491 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 53066 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 49875 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 52445 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 57449 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 57381 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 48605 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 52781 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 40388 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 54706 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:40:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 50344 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T11:41:22", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 94", "src_ip": "209.141.56.12", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-11T11:41:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=76.203.145.138 OUT= PROTO=TCP DPT=443", "src_ip": "76.203.145.138", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T11:50:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=543 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T11:55:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.31 port 57386 ssh2", "src_ip": "10.0.5.31", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T11:55:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=657 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T11:56:22", "source": "nginx", "category": "benign", "severity": "info", "message": "155.253.57.147 - - \"GET / HTTP/1.1\" 200 2394", "src_ip": "155.253.57.147", "status": 200, "path": "/"} {"timestamp": "2026-06-11T12:00:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=211 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T12:03:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T12:03:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T12:03:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T12:03:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T12:03:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T12:03:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T12:03:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T12:03:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T12:03:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T12:05:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=471 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T12:06:25", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.229 dst=45.137.21.9 bytes=1169162240 proto=TCP dport=443 duration=552s", "src_ip": "10.0.1.229", "dst_ip": "45.137.21.9", "bytes_mb": 1115, "off_hours": false} {"timestamp": "2026-06-11T12:10:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=414 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T12:11:14", "source": "nginx", "category": "benign", "severity": "info", "message": "214.120.88.9 - - \"GET /health HTTP/1.1\" 200 4707", "src_ip": "214.120.88.9", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T12:15:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=455 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T12:19:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.24 port 49419 ssh2", "src_ip": "10.0.2.24", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T12:20:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=269 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T12:20:59", "source": "nginx", "category": "web_attack", "severity": "high", "message": "152.114.108.236 - - \"GET /search?q= HTTP/1.1\" 200 229", "src_ip": "152.114.108.236", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T12:25:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=558 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T12:26:33", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.220 dst=209.141.56.12 bytes=2496659456 proto=TCP dport=443 duration=148s", "src_ip": "10.0.4.220", "dst_ip": "209.141.56.12", "bytes_mb": 2381, "off_hours": false} {"timestamp": "2026-06-11T12:30:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=462 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T12:33:36", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.73 port 55722 ssh2", "src_ip": "10.0.1.73", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T12:35:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.254 port 51874 ssh2", "src_ip": "10.0.5.254", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T12:35:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.173 dst=45.137.21.9 dport=443 bytes=310 interval=300s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-11T12:36:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.41 port 40574 ssh2", "src_ip": "10.0.4.41", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T12:37:35", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 85", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T12:37:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 39", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T12:41:41", "source": "nginx", "category": "benign", "severity": "info", "message": "207.178.65.131 - - \"GET / HTTP/1.1\" 200 3523", "src_ip": "207.178.65.131", "status": 200, "path": "/"} {"timestamp": "2026-06-11T12:42:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=85.41.242.217 OUT= PROTO=TCP DPT=80", "src_ip": "85.41.242.217", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T12:43:08", "source": "nginx", "category": "benign", "severity": "info", "message": "155.76.83.223 - - \"GET /login HTTP/1.1\" 200 1665", "src_ip": "155.76.83.223", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T12:43:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.203 port 44079 ssh2", "src_ip": "10.0.4.203", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T12:48:40", "source": "nginx", "category": "benign", "severity": "info", "message": "67.151.80.203 - - \"GET /health HTTP/1.1\" 200 5426", "src_ip": "67.151.80.203", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T12:51:07", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.116 dst=45.137.21.9 bytes=5325717504 proto=TCP dport=443 duration=118s", "src_ip": "10.0.4.116", "dst_ip": "45.137.21.9", "bytes_mb": 5079, "off_hours": false} {"timestamp": "2026-06-11T12:51:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.222.33.31 OUT= PROTO=TCP DPT=80", "src_ip": "215.222.33.31", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T12:55:55", "source": "nginx", "category": "benign", "severity": "info", "message": "161.149.80.8 - - \"GET /login HTTP/1.1\" 200 6081", "src_ip": "161.149.80.8", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T13:03:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.178 port 49057 ssh2", "src_ip": "10.0.5.178", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-11T13:06:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=205.100.23.179 OUT= PROTO=TCP DPT=443", "src_ip": "205.100.23.179", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T13:09:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.140 port 45502 ssh2", "src_ip": "10.0.3.140", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T13:10:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T13:10:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T13:10:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T13:10:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T13:10:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T13:10:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T13:10:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T13:10:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T13:10:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T13:10:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T13:10:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T13:10:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=198.154.250.55 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "198.154.250.55", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T13:12:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.114 port 54398 ssh2", "src_ip": "10.0.5.114", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T13:14:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.244 port 52707 ssh2", "src_ip": "10.0.3.244", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-11T13:25:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=122.165.71.175 OUT= PROTO=TCP DPT=80", "src_ip": "122.165.71.175", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T13:28:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.25 port 54571 ssh2", "src_ip": "10.0.3.25", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T13:28:34", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/su -", "user": "nattapong", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T13:29:36", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.2 port 47824 ssh2", "src_ip": "10.0.0.2", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T13:30:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=52.5.202.214 OUT= PROTO=TCP DPT=443", "src_ip": "52.5.202.214", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T13:37:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=109.215.32.16 OUT= PROTO=TCP DPT=443", "src_ip": "109.215.32.16", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T13:39:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=182.52.191.48 OUT= PROTO=TCP DPT=443", "src_ip": "182.52.191.48", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T13:42:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=102.177.124.233 OUT= PROTO=TCP DPT=443", "src_ip": "102.177.124.233", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T13:42:59", "source": "nginx", "category": "benign", "severity": "info", "message": "57.193.59.204 - - \"GET /login HTTP/1.1\" 200 1496", "src_ip": "57.193.59.204", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T13:47:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=188.19.92.184 OUT= PROTO=TCP DPT=443", "src_ip": "188.19.92.184", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T13:49:57", "source": "nginx", "category": "benign", "severity": "info", "message": "22.24.253.92 - - \"GET / HTTP/1.1\" 200 3676", "src_ip": "22.24.253.92", "status": 200, "path": "/"} {"timestamp": "2026-06-11T13:50:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T13:50:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T13:50:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T13:50:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T13:50:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T13:50:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T13:50:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T13:50:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T13:55:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=13.6.213.101 OUT= PROTO=TCP DPT=80", "src_ip": "13.6.213.101", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T13:56:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=129.245.93.208 OUT= PROTO=TCP DPT=80", "src_ip": "129.245.93.208", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T13:57:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.19 port 59607 ssh2", "src_ip": "10.0.1.19", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T13:58:23", "source": "nginx", "category": "benign", "severity": "info", "message": "143.226.142.47 - - \"GET /static/app.js HTTP/1.1\" 200 3770", "src_ip": "143.226.142.47", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T14:00:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.144 port 59996 ssh2", "src_ip": "10.0.5.144", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T14:02:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 56059 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:02:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 59881 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:02:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 56115 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:02:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 53858 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:02:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 41874 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:02:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 45164 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:02:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 41061 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:02:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 53920 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 43736 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 59153 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 48788 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 46133 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 45904 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 57799 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 43134 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 45758 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 53243 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 58135 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 40257 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 46041 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 53540 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:03:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 58009 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:06:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.37 port 40371 ssh2", "src_ip": "10.0.5.37", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T14:07:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 40614 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:07:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 42551 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:07:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 58866 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:07:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 58789 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:07:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 53686 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:07:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 43774 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:07:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 40683 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:07:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 45631 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:07:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 55076 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 48666 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 56310 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 52263 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 48472 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 50652 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 54070 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 54411 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 52511 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:08:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 45823 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:09:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 47168 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:09:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 41507 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:09:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 49825 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T14:10:34", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/su -", "user": "nattapong", "host": "web-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T14:11:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T14:11:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T14:11:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T14:11:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T14:11:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T14:11:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T14:11:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T14:11:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T14:11:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T14:12:53", "source": "nginx", "category": "benign", "severity": "info", "message": "46.38.87.235 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4486", "src_ip": "46.38.87.235", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T14:14:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.3.243 port 45911 ssh2", "src_ip": "10.0.3.243", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T14:25:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.55 port 43342 ssh2", "src_ip": "10.0.4.55", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T14:26:56", "source": "nginx", "category": "benign", "severity": "info", "message": "173.29.2.116 - - \"GET /api/products HTTP/1.1\" 200 1915", "src_ip": "173.29.2.116", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T14:27:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.63 port 59344 ssh2", "src_ip": "10.0.5.63", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T14:28:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.120 port 50513 ssh2", "src_ip": "10.0.3.120", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T14:35:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T14:35:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T14:35:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T14:35:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T14:35:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T14:35:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T14:35:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T14:35:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T14:35:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T14:35:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T14:35:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T14:35:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T14:40:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.98 port 57063 ssh2", "src_ip": "10.0.5.98", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-11T14:44:17", "source": "nginx", "category": "benign", "severity": "info", "message": "178.240.230.61 - - \"GET /health HTTP/1.1\" 200 7769", "src_ip": "178.240.230.61", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T14:44:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.219 port 52552 ssh2", "src_ip": "10.0.0.219", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T14:47:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.253 dst=91.219.236.18 dport=443 bytes=522 interval=300s", "src_ip": "10.0.0.253", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-11T14:47:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 45803 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 48498 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 54404 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 43028 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 51637 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 59176 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 54216 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 57139 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 51212 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 45586 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 51914 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 45102 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:47:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 49459 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:48:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 58635 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:48:05", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-11T14:48:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 56507 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:48:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 48812 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 51965 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 47744 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 58011 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 53166 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 52059 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 53900 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 46486 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 55951 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 48191 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:36", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for guest from 91.160.50.102 port 51234 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-11T14:49:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 51666 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 57274 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:49:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.160.50.102 port 53353 ssh2", "src_ip": "91.160.50.102", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T14:52:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.253 dst=91.219.236.18 dport=443 bytes=390 interval=300s", "src_ip": "10.0.0.253", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-11T14:55:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=136.55.73.139 OUT= PROTO=TCP DPT=443", "src_ip": "136.55.73.139", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T14:57:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.253 dst=91.219.236.18 dport=443 bytes=637 interval=300s", "src_ip": "10.0.0.253", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-11T15:02:07", "source": "nginx", "category": "benign", "severity": "info", "message": "177.154.53.39 - - \"GET /health HTTP/1.1\" 200 6630", "src_ip": "177.154.53.39", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T15:02:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.253 dst=91.219.236.18 dport=443 bytes=282 interval=300s", "src_ip": "10.0.0.253", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-11T15:02:50", "source": "nginx", "category": "benign", "severity": "info", "message": "162.103.232.24 - - \"GET /api/products HTTP/1.1\" 200 2854", "src_ip": "162.103.232.24", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T15:03:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=202.212.54.197 OUT= PROTO=TCP DPT=443", "src_ip": "202.212.54.197", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T15:05:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T15:05:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T15:05:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T15:05:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T15:05:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T15:05:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T15:05:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T15:05:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T15:07:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.253 dst=91.219.236.18 dport=443 bytes=244 interval=300s", "src_ip": "10.0.0.253", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-11T15:09:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T15:09:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T15:09:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T15:09:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T15:09:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T15:09:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T15:09:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T15:09:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T15:09:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T15:09:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T15:09:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T15:09:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T15:10:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.239 port 56219 ssh2", "src_ip": "10.0.5.239", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T15:14:36", "source": "nginx", "category": "benign", "severity": "info", "message": "167.115.29.56 - - \"GET /login HTTP/1.1\" 200 7123", "src_ip": "167.115.29.56", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T15:18:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.88 port 44921 ssh2", "src_ip": "10.0.0.88", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T15:23:30", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=22.142.219.208 OUT= PROTO=TCP DPT=80", "src_ip": "22.142.219.208", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T15:25:46", "source": "nginx", "category": "benign", "severity": "info", "message": "168.219.48.246 - - \"GET / HTTP/1.1\" 200 6768", "src_ip": "168.219.48.246", "status": 200, "path": "/"} {"timestamp": "2026-06-11T15:26:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.22 port 55008 ssh2", "src_ip": "10.0.3.22", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T15:28:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=192.132.66.179 OUT= PROTO=TCP DPT=443", "src_ip": "192.132.66.179", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T15:30:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=86.164.52.21 OUT= PROTO=TCP DPT=443", "src_ip": "86.164.52.21", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T15:33:53", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 403 471", "src_ip": "45.137.21.9", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T15:37:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 43196 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 57443 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 47006 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 56751 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 51226 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 51079 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 41898 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 54750 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 58108 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 59435 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:37:54", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-11T15:37:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 57690 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T15:38:41", "source": "nginx", "category": "benign", "severity": "info", "message": "125.219.232.151 - - \"GET /static/app.js HTTP/1.1\" 200 4498", "src_ip": "125.219.232.151", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T15:38:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=125.251.178.164 OUT= PROTO=TCP DPT=443", "src_ip": "125.251.178.164", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T15:44:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=83.139.2.105 OUT= PROTO=TCP DPT=80", "src_ip": "83.139.2.105", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T15:46:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.27.236.166 OUT= PROTO=TCP DPT=80", "src_ip": "215.27.236.166", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T15:46:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=119.76.154.160 OUT= PROTO=TCP DPT=443", "src_ip": "119.76.154.160", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T15:50:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.156 port 41292 ssh2", "src_ip": "10.0.4.156", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T15:50:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T15:50:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T15:50:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T15:50:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T15:50:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T15:50:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T15:50:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T15:50:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T15:50:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T15:55:27", "source": "nginx", "category": "benign", "severity": "info", "message": "107.114.10.243 - - \"GET / HTTP/1.1\" 200 7762", "src_ip": "107.114.10.243", "status": 200, "path": "/"} {"timestamp": "2026-06-11T15:56:09", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.109 dst=185.220.101.34 bytes=7250903040 proto=TCP dport=443 duration=427s", "src_ip": "10.0.0.109", "dst_ip": "185.220.101.34", "bytes_mb": 6915, "off_hours": false} {"timestamp": "2026-06-11T15:57:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=194.208.34.56 OUT= PROTO=TCP DPT=80", "src_ip": "194.208.34.56", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T16:00:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=218.137.55.254 OUT= PROTO=TCP DPT=443", "src_ip": "218.137.55.254", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T16:02:25", "source": "nginx", "category": "benign", "severity": "info", "message": "39.81.210.7 - - \"GET /health HTTP/1.1\" 200 1254", "src_ip": "39.81.210.7", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T16:03:13", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.104 dst=193.27.228.114 bytes=1339031552 proto=TCP dport=443 duration=283s", "src_ip": "10.0.5.104", "dst_ip": "193.27.228.114", "bytes_mb": 1277, "off_hours": false} {"timestamp": "2026-06-11T16:04:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 42442 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 40640 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 41509 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 54183 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 42419 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 52877 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 42958 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 48803 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 52777 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 49800 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 57130 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 54086 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 40051 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 57748 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 43295 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 59381 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 47366 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 55382 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 58405 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:04:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 105.142.168.244 port 40492 ssh2", "src_ip": "105.142.168.244", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-11T16:12:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T16:12:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T16:12:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T16:12:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T16:12:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T16:12:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T16:12:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T16:12:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T16:12:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T16:12:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T16:16:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T16:16:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T16:16:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T16:16:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T16:16:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T16:16:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T16:16:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T16:16:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T16:16:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T16:24:24", "source": "nginx", "category": "benign", "severity": "info", "message": "172.3.33.223 - - \"GET /dashboard HTTP/1.1\" 200 773", "src_ip": "172.3.33.223", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T16:28:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=159.174.220.26 OUT= PROTO=TCP DPT=443", "src_ip": "159.174.220.26", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T16:41:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.10 port 50385 ssh2", "src_ip": "10.0.5.10", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T16:44:43", "source": "nginx", "category": "benign", "severity": "info", "message": "171.192.135.140 - - \"GET /dashboard HTTP/1.1\" 200 5250", "src_ip": "171.192.135.140", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T16:58:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=116.59.20.60 OUT= PROTO=TCP DPT=80", "src_ip": "116.59.20.60", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T17:00:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.82 port 49153 ssh2", "src_ip": "10.0.2.82", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T17:02:34", "source": "nginx", "category": "benign", "severity": "info", "message": "18.206.240.86 - - \"GET /dashboard HTTP/1.1\" 200 6394", "src_ip": "18.206.240.86", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T17:07:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=135.24.202.107 OUT= PROTO=TCP DPT=80", "src_ip": "135.24.202.107", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T17:10:03", "source": "nginx", "category": "benign", "severity": "info", "message": "101.4.51.111 - - \"GET /dashboard HTTP/1.1\" 200 1818", "src_ip": "101.4.51.111", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T17:10:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.147 port 46329 ssh2", "src_ip": "10.0.2.147", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T17:11:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.69 port 58243 ssh2", "src_ip": "10.0.2.69", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T17:15:32", "source": "nginx", "category": "benign", "severity": "info", "message": "123.40.56.226 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4832", "src_ip": "123.40.56.226", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T17:20:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.117 dst=45.137.21.9 dport=443 bytes=279 interval=60s", "src_ip": "10.0.4.117", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T17:21:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=61.228.191.143 OUT= PROTO=TCP DPT=443", "src_ip": "61.228.191.143", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T17:21:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.117 dst=45.137.21.9 dport=443 bytes=828 interval=60s", "src_ip": "10.0.4.117", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T17:22:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 55528 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 43377 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 59372 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 56460 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 43947 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 53149 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 48973 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 45937 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 44790 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 41669 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 44873 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 51015 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.117 dst=45.137.21.9 dport=443 bytes=265 interval=60s", "src_ip": "10.0.4.117", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T17:22:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 56707 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 40578 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 53346 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 46541 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 55702 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:22:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 41692 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:23:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 43606 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:23:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 50041 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:23:02", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-11T17:23:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 47583 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T17:23:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.117 dst=45.137.21.9 dport=443 bytes=842 interval=60s", "src_ip": "10.0.4.117", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T17:24:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.117 dst=45.137.21.9 dport=443 bytes=879 interval=60s", "src_ip": "10.0.4.117", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T17:25:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.117 dst=45.137.21.9 dport=443 bytes=672 interval=60s", "src_ip": "10.0.4.117", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T17:26:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.117 dst=45.137.21.9 dport=443 bytes=706 interval=60s", "src_ip": "10.0.4.117", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T17:27:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.117 dst=45.137.21.9 dport=443 bytes=825 interval=60s", "src_ip": "10.0.4.117", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T17:34:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=166.231.41.119 OUT= PROTO=TCP DPT=80", "src_ip": "166.231.41.119", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T17:34:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.146 port 56407 ssh2", "src_ip": "10.0.5.146", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-11T17:41:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.164 port 51803 ssh2", "src_ip": "10.0.0.164", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T17:43:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.247 port 44397 ssh2", "src_ip": "10.0.1.247", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T17:43:55", "source": "nginx", "category": "benign", "severity": "info", "message": "162.191.230.165 - - \"GET /api/products HTTP/1.1\" 200 3621", "src_ip": "162.191.230.165", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T17:45:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=165.61.151.188 OUT= PROTO=TCP DPT=80", "src_ip": "165.61.151.188", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T17:46:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T17:46:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T17:46:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T17:46:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T17:46:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T17:46:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T17:46:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T17:46:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T17:46:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T17:47:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.30 port 49131 ssh2", "src_ip": "10.0.0.30", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T17:48:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=212.71.151.49 OUT= PROTO=TCP DPT=443", "src_ip": "212.71.151.49", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T17:49:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=168.58.213.118 OUT= PROTO=TCP DPT=80", "src_ip": "168.58.213.118", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T17:50:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=206.57.16.208 OUT= PROTO=TCP DPT=443", "src_ip": "206.57.16.208", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T17:50:47", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.65 port 53339 ssh2", "src_ip": "10.0.0.65", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T17:53:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T17:53:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T17:53:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T17:53:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T17:53:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T17:53:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T17:53:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T17:53:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T18:01:18", "source": "nginx", "category": "benign", "severity": "info", "message": "159.174.66.245 - - \"GET /static/app.js HTTP/1.1\" 200 2928", "src_ip": "159.174.66.245", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T18:05:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T18:05:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T18:05:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T18:05:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T18:05:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T18:05:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T18:05:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T18:05:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T18:05:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T18:10:03", "source": "nginx", "category": "benign", "severity": "info", "message": "102.34.178.109 - - \"GET /api/products HTTP/1.1\" 200 3802", "src_ip": "102.34.178.109", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T18:14:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=184.121.111.241 OUT= PROTO=TCP DPT=443", "src_ip": "184.121.111.241", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T18:30:56", "source": "nginx", "category": "benign", "severity": "info", "message": "200.190.38.72 - - \"GET /dashboard HTTP/1.1\" 200 5554", "src_ip": "200.190.38.72", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T18:34:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=60.186.237.141 OUT= PROTO=TCP DPT=443", "src_ip": "60.186.237.141", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T18:39:08", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/su -", "user": "deploy", "host": "web-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T18:44:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T18:44:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T18:44:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T18:44:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T18:44:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T18:44:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T18:44:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T18:44:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T18:44:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T18:44:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T18:44:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T18:44:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T18:46:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=196.31.134.174 OUT= PROTO=TCP DPT=443", "src_ip": "196.31.134.174", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T18:50:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T18:50:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T18:50:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T18:50:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T18:50:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T18:50:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T18:50:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T18:50:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T18:50:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.160 port 51858 ssh2", "src_ip": "10.0.0.160", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T18:50:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.120 port 55905 ssh2", "src_ip": "10.0.2.120", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T18:57:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T18:57:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T18:57:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T18:57:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T18:57:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T18:57:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T18:57:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T18:57:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T18:57:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T18:59:38", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.3 port 45497 ssh2", "src_ip": "10.0.1.3", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T19:02:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.31 port 54625 ssh2", "src_ip": "10.0.4.31", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T19:03:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=819 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:08:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=367 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:10:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.187 port 47841 ssh2", "src_ip": "10.0.2.187", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T19:13:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=629 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:18:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=357 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:18:20", "source": "nginx", "category": "benign", "severity": "info", "message": "125.90.38.48 - - \"GET /login HTTP/1.1\" 200 6221", "src_ip": "125.90.38.48", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T19:18:30", "source": "nginx", "category": "benign", "severity": "info", "message": "190.27.1.148 - - \"GET /health HTTP/1.1\" 200 4625", "src_ip": "190.27.1.148", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T19:23:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=523 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:25:55", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/bin/su -", "user": "svc_backup", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T19:28:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=644 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:29:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=102.138.103.86 OUT= PROTO=TCP DPT=80", "src_ip": "102.138.103.86", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T19:33:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=588 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:35:44", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.51 dst=91.219.236.18 bytes=4110417920 proto=TCP dport=443 duration=215s", "src_ip": "10.0.4.51", "dst_ip": "91.219.236.18", "bytes_mb": 3920, "off_hours": false} {"timestamp": "2026-06-11T19:38:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=226 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:43:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.170 dst=185.220.101.34 dport=443 bytes=818 interval=300s", "src_ip": "10.0.4.170", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-11T19:43:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 40357 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 48552 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 44720 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 53809 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 52079 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 40828 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 44837 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 52518 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 59217 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 50577 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 44060 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 50699 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 43530 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 54940 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 45143 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:43:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 46480 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:44:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 54553 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:44:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 49331 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:44:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 59875 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:44:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 44644 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:44:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 55633 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-11T19:47:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=145.113.142.51 OUT= PROTO=TCP DPT=80", "src_ip": "145.113.142.51", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T19:54:10", "source": "nginx", "category": "benign", "severity": "info", "message": "38.69.155.2 - - \"GET /dashboard HTTP/1.1\" 200 2921", "src_ip": "38.69.155.2", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T20:00:01", "source": "nginx", "category": "benign", "severity": "info", "message": "137.236.3.74 - - \"GET /api/products HTTP/1.1\" 200 4236", "src_ip": "137.236.3.74", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T20:02:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=433 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:03:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=572 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:04:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=843 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:05:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T20:05:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T20:05:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T20:05:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T20:05:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T20:05:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T20:05:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T20:05:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T20:05:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=647 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:05:24", "source": "nginx", "category": "benign", "severity": "info", "message": "69.194.125.128 - - \"GET /static/app.js HTTP/1.1\" 200 5562", "src_ip": "69.194.125.128", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T20:06:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=573 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:07:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=13.64.6.33 OUT= PROTO=TCP DPT=80", "src_ip": "13.64.6.33", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T20:07:04", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 48", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-11T20:07:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=774 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:07:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.24 port 48637 ssh2", "src_ip": "10.0.3.24", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T20:08:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=357 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:09:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=599 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:10:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=225 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:11:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.15 dst=45.137.21.9 dport=443 bytes=725 interval=60s", "src_ip": "10.0.5.15", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-11T20:13:01", "source": "nginx", "category": "benign", "severity": "info", "message": "56.237.240.169 - - \"GET /dashboard HTTP/1.1\" 200 4487", "src_ip": "56.237.240.169", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T20:13:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=42.107.143.94 OUT= PROTO=TCP DPT=443", "src_ip": "42.107.143.94", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T20:25:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 49120 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 42050 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 54993 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 43334 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 48596 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 50681 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 46126 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 56039 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 50269 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 51533 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 45653 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 52734 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 52862 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:25:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 162.219.199.2 port 43743 ssh2", "src_ip": "162.219.199.2", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-11T20:26:11", "source": "nginx", "category": "benign", "severity": "info", "message": "69.142.137.131 - - \"GET /dashboard HTTP/1.1\" 200 2415", "src_ip": "69.142.137.131", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T20:28:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.1.157 port 48158 ssh2", "src_ip": "10.0.1.157", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-11T20:38:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.44 port 43958 ssh2", "src_ip": "10.0.0.44", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-11T20:44:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T20:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T20:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T20:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T20:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T20:44:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T20:44:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T20:44:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T20:44:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T20:44:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T20:44:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-11T20:44:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T20:45:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.12 port 44380 ssh2", "src_ip": "10.0.2.12", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T20:46:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 53716 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:46:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 45074 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:46:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 56231 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:46:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 50975 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:46:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 44399 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:46:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 59980 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:46:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 49715 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:46:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 42104 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:47:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 57958 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:47:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 45372 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:47:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 56942 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:47:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 55416 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T20:48:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=140.209.88.163 OUT= PROTO=TCP DPT=80", "src_ip": "140.209.88.163", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T20:51:41", "source": "nginx", "category": "benign", "severity": "info", "message": "81.98.29.157 - - \"GET /health HTTP/1.1\" 200 1808", "src_ip": "81.98.29.157", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T20:56:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.50 port 40121 ssh2", "src_ip": "10.0.3.50", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T20:57:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.16 port 47187 ssh2", "src_ip": "10.0.0.16", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T20:58:17", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 11", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T21:02:27", "source": "nginx", "category": "benign", "severity": "info", "message": "93.146.30.233 - - \"GET /health HTTP/1.1\" 200 932", "src_ip": "93.146.30.233", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T21:02:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.127.9.254 OUT= PROTO=TCP DPT=443", "src_ip": "215.127.9.254", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T21:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-11T21:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-11T21:02:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-11T21:02:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-11T21:02:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-11T21:02:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-11T21:02:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-11T21:02:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-11T21:02:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-11T21:02:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-11T21:02:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-11T21:02:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.3.27 port 53630 ssh2", "src_ip": "10.0.3.27", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T21:08:13", "source": "nginx", "category": "benign", "severity": "info", "message": "44.150.33.229 - - \"GET / HTTP/1.1\" 200 1895", "src_ip": "44.150.33.229", "status": 200, "path": "/"} {"timestamp": "2026-06-11T21:10:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.166 dst=185.220.101.34 dport=443 bytes=513 interval=60s", "src_ip": "10.0.4.166", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-11T21:11:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.166 dst=185.220.101.34 dport=443 bytes=678 interval=60s", "src_ip": "10.0.4.166", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-11T21:12:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.166 dst=185.220.101.34 dport=443 bytes=788 interval=60s", "src_ip": "10.0.4.166", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-11T21:12:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=36.199.178.71 OUT= PROTO=TCP DPT=443", "src_ip": "36.199.178.71", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T21:13:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.166 dst=185.220.101.34 dport=443 bytes=813 interval=60s", "src_ip": "10.0.4.166", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-11T21:14:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=146.97.43.40 OUT= PROTO=TCP DPT=80", "src_ip": "146.97.43.40", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T21:14:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.166 dst=185.220.101.34 dport=443 bytes=749 interval=60s", "src_ip": "10.0.4.166", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-11T21:15:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.166 dst=185.220.101.34 dport=443 bytes=477 interval=60s", "src_ip": "10.0.4.166", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-11T21:16:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.166 dst=185.220.101.34 dport=443 bytes=600 interval=60s", "src_ip": "10.0.4.166", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-11T21:17:19", "source": "nginx", "category": "benign", "severity": "info", "message": "61.168.128.78 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6881", "src_ip": "61.168.128.78", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T21:17:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.166 dst=185.220.101.34 dport=443 bytes=225 interval=60s", "src_ip": "10.0.4.166", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-11T21:17:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=101.78.96.198 OUT= PROTO=TCP DPT=80", "src_ip": "101.78.96.198", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T21:18:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=114.80.225.237 OUT= PROTO=TCP DPT=443", "src_ip": "114.80.225.237", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T21:26:51", "source": "nginx", "category": "benign", "severity": "info", "message": "91.90.203.248 - - \"GET /api/products HTTP/1.1\" 200 2587", "src_ip": "91.90.203.248", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T21:37:33", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-11T21:41:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 444", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T21:42:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.53 port 42994 ssh2", "src_ip": "10.0.1.53", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-11T21:42:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=419 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:43:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=494 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:43:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=471 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:44:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=248 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:44:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=504 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:45:00", "source": "nginx", "category": "benign", "severity": "info", "message": "117.3.125.214 - - \"GET /health HTTP/1.1\" 200 4080", "src_ip": "117.3.125.214", "status": 200, "path": "/health"} {"timestamp": "2026-06-11T21:45:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=787 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:45:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=611 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:46:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=431 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:46:42", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.218 dst=91.219.236.18 dport=443 bytes=839 interval=30s", "src_ip": "10.0.5.218", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-11T21:49:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 45522 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 40521 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 46219 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 43059 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 50175 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 59594 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 58347 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 58365 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 42488 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 45829 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 50611 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 44776 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:49:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 44359 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:50:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 53259 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:50:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 43395 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:50:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 51146 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:50:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 51593 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:50:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 49630 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:50:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 58681 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T21:52:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.5.182 port 57164 ssh2", "src_ip": "10.0.5.182", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-11T21:57:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.206 port 46148 ssh2", "src_ip": "10.0.2.206", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-11T21:58:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.180 dst=193.27.228.114 dport=443 bytes=808 interval=30s", "src_ip": "10.0.0.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-11T21:58:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.180 dst=193.27.228.114 dport=443 bytes=657 interval=30s", "src_ip": "10.0.0.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-11T21:59:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.180 dst=193.27.228.114 dport=443 bytes=763 interval=30s", "src_ip": "10.0.0.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-11T21:59:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.180 dst=193.27.228.114 dport=443 bytes=806 interval=30s", "src_ip": "10.0.0.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-11T22:00:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.180 dst=193.27.228.114 dport=443 bytes=837 interval=30s", "src_ip": "10.0.0.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-11T22:09:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=66.184.235.17 OUT= PROTO=TCP DPT=443", "src_ip": "66.184.235.17", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T22:14:27", "source": "nginx", "category": "benign", "severity": "info", "message": "174.147.147.188 - - \"GET / HTTP/1.1\" 200 972", "src_ip": "174.147.147.188", "status": 200, "path": "/"} {"timestamp": "2026-06-11T22:16:31", "source": "nginx", "category": "benign", "severity": "info", "message": "152.247.91.95 - - \"GET /static/app.js HTTP/1.1\" 200 4745", "src_ip": "152.247.91.95", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T22:18:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=144.132.247.160 OUT= PROTO=TCP DPT=80", "src_ip": "144.132.247.160", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T22:24:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 55523 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:24:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 40249 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:24:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 52272 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:24:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 57466 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:24:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 53774 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:24:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 42779 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:24:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 46939 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:24:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 45037 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:25:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 43553 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:25:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 171.153.221.40 port 47512 ssh2", "src_ip": "171.153.221.40", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-11T22:27:59", "source": "nginx", "category": "benign", "severity": "info", "message": "185.86.246.253 - - \"GET /dashboard HTTP/1.1\" 200 397", "src_ip": "185.86.246.253", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T22:28:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.111 port 55305 ssh2", "src_ip": "10.0.0.111", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-11T22:30:34", "source": "nginx", "category": "benign", "severity": "info", "message": "73.69.77.51 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4183", "src_ip": "73.69.77.51", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T22:32:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.105 port 49340 ssh2", "src_ip": "10.0.1.105", "user": "root", "action": "login_success"} {"timestamp": "2026-06-11T22:33:30", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.192 dst=45.137.21.9 bytes=6380584960 proto=TCP dport=443 duration=91s", "src_ip": "10.0.5.192", "dst_ip": "45.137.21.9", "bytes_mb": 6085, "off_hours": false} {"timestamp": "2026-06-11T22:33:58", "source": "nginx", "category": "benign", "severity": "info", "message": "44.212.26.63 - - \"GET /login HTTP/1.1\" 200 7548", "src_ip": "44.212.26.63", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T22:34:10", "source": "nginx", "category": "benign", "severity": "info", "message": "57.97.208.41 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6269", "src_ip": "57.97.208.41", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T22:38:38", "source": "nginx", "category": "web_attack", "severity": "high", "message": "130.211.37.27 - - \"GET /search?q= HTTP/1.1\" 200 113", "src_ip": "130.211.37.27", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T22:45:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=16.79.8.176 OUT= PROTO=TCP DPT=443", "src_ip": "16.79.8.176", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T22:47:33", "source": "nginx", "category": "web_attack", "severity": "high", "message": "106.73.39.154 - - \"GET /search?q= HTTP/1.1\" 403 106", "src_ip": "106.73.39.154", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T22:48:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.81 port 57448 ssh2", "src_ip": "10.0.1.81", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-11T22:51:51", "source": "nginx", "category": "benign", "severity": "info", "message": "115.235.178.77 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 763", "src_ip": "115.235.178.77", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T22:53:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=24.127.113.156 OUT= PROTO=TCP DPT=443", "src_ip": "24.127.113.156", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T22:54:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.138 port 56510 ssh2", "src_ip": "10.0.0.138", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-11T22:55:13", "source": "nginx", "category": "benign", "severity": "info", "message": "138.173.85.158 - - \"GET /api/products HTTP/1.1\" 200 3176", "src_ip": "138.173.85.158", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T22:59:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=32.166.47.241 OUT= PROTO=TCP DPT=80", "src_ip": "32.166.47.241", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T23:00:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=52.44.131.218 OUT= PROTO=TCP DPT=80", "src_ip": "52.44.131.218", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T23:02:59", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 245", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-11T23:04:44", "source": "nginx", "category": "benign", "severity": "info", "message": "156.88.139.252 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5775", "src_ip": "156.88.139.252", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-11T23:08:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 41818 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 59821 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 49829 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 54155 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 40677 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 59548 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 41344 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 56620 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 41394 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 59828 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 55825 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:08:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 43849 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-11T23:15:19", "source": "nginx", "category": "benign", "severity": "info", "message": "13.100.0.131 - - \"GET /dashboard HTTP/1.1\" 200 7396", "src_ip": "13.100.0.131", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-11T23:17:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.203.39.77 OUT= PROTO=TCP DPT=80", "src_ip": "47.203.39.77", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T23:19:48", "source": "nginx", "category": "benign", "severity": "info", "message": "42.131.165.187 - - \"GET /login HTTP/1.1\" 200 4788", "src_ip": "42.131.165.187", "status": 200, "path": "/login"} {"timestamp": "2026-06-11T23:23:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.77 port 47093 ssh2", "src_ip": "10.0.3.77", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-11T23:25:04", "source": "nginx", "category": "benign", "severity": "info", "message": "19.104.228.3 - - \"GET /api/products HTTP/1.1\" 200 1818", "src_ip": "19.104.228.3", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-11T23:27:08", "source": "nginx", "category": "benign", "severity": "info", "message": "147.157.107.58 - - \"GET /static/app.js HTTP/1.1\" 200 1027", "src_ip": "147.157.107.58", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-11T23:30:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=38.9.154.60 OUT= PROTO=TCP DPT=443", "src_ip": "38.9.154.60", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T23:31:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=186.158.103.30 OUT= PROTO=TCP DPT=80", "src_ip": "186.158.103.30", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-11T23:36:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 44609 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:36:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 57479 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:36:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 47648 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:36:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 47493 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:36:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 48280 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:36:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 55362 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:36:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 40026 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:36:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 44876 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:36:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 48543 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 49043 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 42742 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 55800 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 42081 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 40264 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 59013 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 43040 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 57235 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:26", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-11T23:37:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 59279 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 55288 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:37:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 50381 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-11T23:42:35", "source": "nginx", "category": "benign", "severity": "info", "message": "33.248.131.153 - - \"GET / HTTP/1.1\" 200 4990", "src_ip": "33.248.131.153", "status": 200, "path": "/"} {"timestamp": "2026-06-11T23:44:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.34.30.194 OUT= PROTO=TCP DPT=443", "src_ip": "167.34.30.194", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-11T23:45:25", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/su -", "user": "deploy", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-11T23:50:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=25.55.44.124 OUT= PROTO=TCP DPT=443", "src_ip": "25.55.44.124", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T00:03:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 41784 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 52216 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 54824 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 56431 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 57429 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 55003 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 42627 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 44020 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 54810 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 45399 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 57460 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 57061 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 52063 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 45859 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 42521 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 42150 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 43670 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 44931 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 53649 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 44848 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:03:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.178 port 43660 ssh2", "src_ip": "10.0.3.178", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-12T00:04:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 93.180.136.129 port 40743 ssh2", "src_ip": "93.180.136.129", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T00:17:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=98.104.135.130 OUT= PROTO=TCP DPT=443", "src_ip": "98.104.135.130", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T00:28:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=187.27.200.136 OUT= PROTO=TCP DPT=80", "src_ip": "187.27.200.136", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T00:35:44", "source": "nginx", "category": "benign", "severity": "info", "message": "94.172.194.72 - - \"GET /health HTTP/1.1\" 200 7992", "src_ip": "94.172.194.72", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T00:39:05", "source": "nginx", "category": "benign", "severity": "info", "message": "79.165.145.87 - - \"GET /static/app.js HTTP/1.1\" 200 4934", "src_ip": "79.165.145.87", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T00:39:37", "source": "nginx", "category": "benign", "severity": "info", "message": "84.255.14.133 - - \"GET /static/app.js HTTP/1.1\" 200 6044", "src_ip": "84.255.14.133", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T00:50:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=117.84.246.143 OUT= PROTO=TCP DPT=443", "src_ip": "117.84.246.143", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T00:51:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.193 port 45987 ssh2", "src_ip": "10.0.0.193", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T00:52:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 55885 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 48937 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 55957 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 46872 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 45008 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 55205 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 51597 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 48805 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 52754 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 58777 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 50412 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 48857 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 44599 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 40431 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 56126 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 56693 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 56327 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 59152 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:46", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T00:52:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 47299 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 48231 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:52:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 40617 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:53:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 57973 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:53:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 54162 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T00:53:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.28 port 48607 ssh2", "src_ip": "10.0.1.28", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T01:01:22", "source": "nginx", "category": "benign", "severity": "info", "message": "132.188.251.98 - - \"GET /api/products HTTP/1.1\" 200 7246", "src_ip": "132.188.251.98", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T01:02:36", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.20 dst=91.219.236.18 bytes=4570742784 proto=TCP dport=443 duration=567s", "src_ip": "10.0.5.20", "dst_ip": "91.219.236.18", "bytes_mb": 4359, "off_hours": true} {"timestamp": "2026-06-12T01:10:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T01:10:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T01:10:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T01:10:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T01:10:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T01:10:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T01:10:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T01:10:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T01:10:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T01:10:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T01:10:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T01:10:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T01:14:52", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 350", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T01:15:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.124 port 55797 ssh2", "src_ip": "10.0.5.124", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T01:15:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.86 port 57780 ssh2", "src_ip": "10.0.3.86", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T01:16:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=181.160.77.61 OUT= PROTO=TCP DPT=80", "src_ip": "181.160.77.61", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T01:24:48", "source": "nginx", "category": "benign", "severity": "info", "message": "132.49.121.205 - - \"GET /dashboard HTTP/1.1\" 200 3864", "src_ip": "132.49.121.205", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T01:26:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.65 port 57240 ssh2", "src_ip": "10.0.2.65", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T01:31:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T01:31:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T01:31:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T01:31:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T01:31:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T01:31:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T01:31:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T01:31:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T01:31:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T01:31:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T01:36:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=110.184.97.27 OUT= PROTO=TCP DPT=443", "src_ip": "110.184.97.27", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T01:39:35", "source": "nginx", "category": "benign", "severity": "info", "message": "37.47.194.25 - - \"GET /api/products HTTP/1.1\" 200 7142", "src_ip": "37.47.194.25", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T01:52:17", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=102.142.65.187 OUT= PROTO=TCP DPT=443", "src_ip": "102.142.65.187", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T01:53:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.214 port 57242 ssh2", "src_ip": "10.0.1.214", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T02:01:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T02:01:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T02:01:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T02:01:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T02:01:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T02:01:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T02:01:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T02:01:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T02:01:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T02:01:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T02:01:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T02:02:38", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/su -", "user": "somchai", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-12T02:08:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.58 port 42734 ssh2", "src_ip": "10.0.1.58", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T02:13:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 58895 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:13:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 47015 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:13:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 43303 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:13:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 53498 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:13:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 49935 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:13:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 58125 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:13:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 45457 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:13:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 59175 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:13:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 53995 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:14:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 51917 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:14:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 44714 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:14:13", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T02:14:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 48012 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:14:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 57700 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:19:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T02:19:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T02:19:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T02:19:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T02:19:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T02:19:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T02:19:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T02:19:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T02:20:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.4 port 55410 ssh2", "src_ip": "10.0.1.4", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T02:22:57", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/bin/su -", "user": "svc_backup", "host": "web-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-12T02:23:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 40672 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 52865 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 55023 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 47142 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 45150 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 51401 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 42388 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 50750 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 46963 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 50259 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 44260 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 46017 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 43465 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 57604 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 46021 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:45", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 156.147.157.149 port 51234 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T02:23:47", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 92", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T02:23:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 42003 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 46120 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:23:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 58765 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:24:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 156.147.157.149 port 44897 ssh2", "src_ip": "156.147.157.149", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T02:24:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T02:24:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T02:24:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T02:24:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T02:24:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T02:24:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T02:24:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T02:24:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T02:26:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.165.168.88 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "36.165.168.88", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T02:26:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.165.168.88 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "36.165.168.88", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T02:26:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.165.168.88 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "36.165.168.88", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T02:26:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.165.168.88 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "36.165.168.88", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T02:26:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.165.168.88 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "36.165.168.88", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T02:26:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.165.168.88 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "36.165.168.88", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T02:26:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.165.168.88 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "36.165.168.88", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T02:26:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=36.165.168.88 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "36.165.168.88", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T02:32:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=61.222.200.93 OUT= PROTO=TCP DPT=80", "src_ip": "61.222.200.93", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T02:33:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=145.181.5.4 OUT= PROTO=TCP DPT=443", "src_ip": "145.181.5.4", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T02:34:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 49188 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:34:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 59288 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:34:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 51167 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:34:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 46851 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:34:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 43892 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:34:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 48202 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:34:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 55597 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:34:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 42906 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 58863 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 57592 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47903 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47089 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 50837 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 49079 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 45473 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 40208 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 40003 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 51434 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 54822 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:27", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T02:35:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 59099 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 58710 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 45383 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 44229 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 45679 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 55687 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 55693 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 49406 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:35:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 49874 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:36:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 51394 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:36:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 51032 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:36:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 59189 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:36:06", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T02:36:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 53526 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T02:36:20", "source": "nginx", "category": "benign", "severity": "info", "message": "88.255.52.183 - - \"GET /static/app.js HTTP/1.1\" 200 6682", "src_ip": "88.255.52.183", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T02:38:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=20.189.37.5 OUT= PROTO=TCP DPT=443", "src_ip": "20.189.37.5", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T02:40:15", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/bin/su -", "user": "svc_backup", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-12T02:40:40", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.2 port 50870 ssh2", "src_ip": "10.0.3.2", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T02:41:44", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.187 dst=185.220.101.34 bytes=1087373312 proto=TCP dport=443 duration=347s", "src_ip": "10.0.2.187", "dst_ip": "185.220.101.34", "bytes_mb": 1037, "off_hours": true} {"timestamp": "2026-06-12T02:42:23", "source": "nginx", "category": "benign", "severity": "info", "message": "58.39.239.123 - - \"GET /api/products HTTP/1.1\" 200 5546", "src_ip": "58.39.239.123", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T02:47:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=579 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T02:51:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T02:51:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T02:51:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T02:51:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T02:51:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T02:51:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T02:51:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T02:51:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T02:51:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T02:52:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=363 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T02:57:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=495 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T02:57:09", "source": "nginx", "category": "benign", "severity": "info", "message": "55.205.29.131 - - \"GET /health HTTP/1.1\" 200 2549", "src_ip": "55.205.29.131", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T02:57:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.190 port 51815 ssh2", "src_ip": "10.0.0.190", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T03:00:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.74 port 50961 ssh2", "src_ip": "10.0.0.74", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T03:00:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=16.143.99.123 OUT= PROTO=TCP DPT=443", "src_ip": "16.143.99.123", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T03:02:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=652 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T03:07:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=477 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T03:11:22", "source": "nginx", "category": "benign", "severity": "info", "message": "45.8.120.166 - - \"GET /dashboard HTTP/1.1\" 200 3350", "src_ip": "45.8.120.166", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T03:11:49", "source": "nginx", "category": "benign", "severity": "info", "message": "61.19.197.250 - - \"GET /api/products HTTP/1.1\" 200 4828", "src_ip": "61.19.197.250", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T03:12:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=603 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T03:16:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.41 port 54908 ssh2", "src_ip": "10.0.3.41", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T03:17:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=644 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T03:18:55", "source": "nginx", "category": "benign", "severity": "info", "message": "18.86.230.111 - - \"GET /dashboard HTTP/1.1\" 200 2358", "src_ip": "18.86.230.111", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T03:20:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 50012 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:20:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 48150 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:20:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 40047 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 40618 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 52249 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 48281 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 57910 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 43263 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 52811 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 50787 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 59014 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 40140 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 49507 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 53343 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 44676 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 50855 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 40900 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 43142 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 43112 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:43", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for admin from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T03:21:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 53529 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 45569 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:21:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 40117 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:22:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 44246 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:22:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=525 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T03:23:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=48.8.133.142 OUT= PROTO=TCP DPT=443", "src_ip": "48.8.133.142", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T03:27:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=882 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T03:32:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.219 dst=193.27.228.114 dport=443 bytes=438 interval=300s", "src_ip": "10.0.3.219", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T03:43:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=76.195.51.34 OUT= PROTO=TCP DPT=80", "src_ip": "76.195.51.34", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T03:44:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 42427 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54200 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 50315 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 57081 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 44485 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 46238 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 46411 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 55876 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 56276 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 42906 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41167 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54231 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 56078 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 40261 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 55404 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 53702 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 52327 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 44318 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 47018 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:44:58", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for admin from 91.219.236.18 port 51234 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T03:45:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 46833 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:45:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 45836 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:45:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 48620 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:45:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 52461 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:45:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 59133 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T03:48:10", "source": "nginx", "category": "benign", "severity": "info", "message": "180.35.153.151 - - \"GET /static/app.js HTTP/1.1\" 200 679", "src_ip": "180.35.153.151", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T03:51:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=122.167.87.25 OUT= PROTO=TCP DPT=80", "src_ip": "122.167.87.25", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T03:52:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.230.234.167 OUT= PROTO=TCP DPT=80", "src_ip": "214.230.234.167", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T03:54:21", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/su -", "user": "guest", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-12T03:55:06", "source": "nginx", "category": "benign", "severity": "info", "message": "153.196.23.200 - - \"GET /static/app.js HTTP/1.1\" 200 5784", "src_ip": "153.196.23.200", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T03:58:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=196.14.113.13 OUT= PROTO=TCP DPT=443", "src_ip": "196.14.113.13", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T04:07:52", "source": "nginx", "category": "benign", "severity": "info", "message": "151.163.25.140 - - \"GET / HTTP/1.1\" 200 5327", "src_ip": "151.163.25.140", "status": 200, "path": "/"} {"timestamp": "2026-06-12T04:08:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.142 port 41747 ssh2", "src_ip": "10.0.3.142", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T04:16:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.100 port 44829 ssh2", "src_ip": "10.0.3.100", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T04:16:55", "source": "nginx", "category": "benign", "severity": "info", "message": "62.141.244.247 - - \"GET /dashboard HTTP/1.1\" 200 2408", "src_ip": "62.141.244.247", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T04:17:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=44.108.11.151 OUT= PROTO=TCP DPT=80", "src_ip": "44.108.11.151", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T04:19:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=67.125.115.113 OUT= PROTO=TCP DPT=80", "src_ip": "67.125.115.113", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T04:21:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=139.42.51.101 OUT= PROTO=TCP DPT=80", "src_ip": "139.42.51.101", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T04:25:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.18 port 49431 ssh2", "src_ip": "10.0.1.18", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T04:30:07", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 11", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T04:37:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.210 port 57318 ssh2", "src_ip": "10.0.3.210", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T04:37:57", "source": "nginx", "category": "benign", "severity": "info", "message": "21.21.112.195 - - \"GET /login HTTP/1.1\" 200 7982", "src_ip": "21.21.112.195", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T04:40:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=108.230.226.77 OUT= PROTO=TCP DPT=443", "src_ip": "108.230.226.77", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T04:42:15", "source": "nginx", "category": "benign", "severity": "info", "message": "13.50.193.251 - - \"GET /login HTTP/1.1\" 200 3301", "src_ip": "13.50.193.251", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T04:47:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.150 port 52222 ssh2", "src_ip": "10.0.4.150", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T04:53:03", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 499", "src_ip": "193.27.228.114", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-12T04:53:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T04:53:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T04:53:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T04:53:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T04:53:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T04:53:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T04:53:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T04:53:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T04:53:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T04:53:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T04:53:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T05:00:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=192.171.250.30 OUT= PROTO=TCP DPT=443", "src_ip": "192.171.250.30", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T05:05:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44121 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 56864 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:04", "source": "nginx", "category": "benign", "severity": "info", "message": "75.249.204.120 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4010", "src_ip": "75.249.204.120", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T05:05:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48516 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 52202 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41610 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59468 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 55909 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41828 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41538 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44452 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57378 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58756 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 52331 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48977 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:05:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48199 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T05:06:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.95 port 53507 ssh2", "src_ip": "10.0.2.95", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T05:11:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 54096 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 50286 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 55855 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 40481 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 42838 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 44615 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 58408 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 58808 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 59502 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 55536 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 50722 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 50186 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 53539 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 49602 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 51292 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 57101 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 49143 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 43786 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 58197 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 42886 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 46990 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:11:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 56864 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T05:13:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=844 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:13:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=834 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:14:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.51 port 53056 ssh2", "src_ip": "10.0.5.51", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T05:14:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=589 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:14:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=351 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:15:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=897 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:15:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=448 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:16:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=232 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:16:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=786 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:17:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.124 dst=45.137.21.9 dport=443 bytes=312 interval=30s", "src_ip": "10.0.4.124", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T05:19:31", "source": "nginx", "category": "benign", "severity": "info", "message": "31.119.51.98 - - \"GET /api/products HTTP/1.1\" 200 3914", "src_ip": "31.119.51.98", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T05:20:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.6 port 51578 ssh2", "src_ip": "10.0.2.6", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-12T05:23:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=166.112.166.172 OUT= PROTO=TCP DPT=443", "src_ip": "166.112.166.172", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T05:33:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.69 port 45529 ssh2", "src_ip": "10.0.1.69", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T05:40:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.61 port 53132 ssh2", "src_ip": "10.0.2.61", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T05:42:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=223.242.187.99 OUT= PROTO=TCP DPT=80", "src_ip": "223.242.187.99", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T05:46:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=131.27.3.140 OUT= PROTO=TCP DPT=443", "src_ip": "131.27.3.140", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T05:47:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=136.3.178.180 OUT= PROTO=TCP DPT=80", "src_ip": "136.3.178.180", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T05:48:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 43057 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 43609 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 58165 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 41575 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 44317 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 46411 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 45967 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 42079 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 42682 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 54063 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 47247 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 49322 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 47537 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 51703 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 40660 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 59945 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:48:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 59031 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:49:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 56645 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:49:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 44445 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:49:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 51168 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:49:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 54105 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:49:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 56544 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:49:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 59834 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T05:49:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=70.8.189.70 OUT= PROTO=TCP DPT=443", "src_ip": "70.8.189.70", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T05:55:07", "source": "nginx", "category": "benign", "severity": "info", "message": "180.76.124.39 - - \"GET /login HTTP/1.1\" 200 6144", "src_ip": "180.76.124.39", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T05:56:18", "source": "nginx", "category": "benign", "severity": "info", "message": "90.51.91.40 - - \"GET /api/products HTTP/1.1\" 200 6410", "src_ip": "90.51.91.40", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T06:06:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.86 port 40738 ssh2", "src_ip": "10.0.4.86", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T06:08:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 55943 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:08:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 49776 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:08:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40506 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:08:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 51019 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:08:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58098 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:08:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 52247 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:08:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 43751 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:08:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41739 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:08:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59535 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T06:13:28", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "somchai", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-12T06:14:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=109.97.98.135 OUT= PROTO=TCP DPT=80", "src_ip": "109.97.98.135", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T06:15:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T06:15:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T06:15:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T06:15:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T06:15:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T06:15:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T06:15:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T06:15:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T06:19:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T06:19:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T06:19:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T06:19:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T06:19:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T06:19:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T06:19:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T06:19:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T06:19:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T06:19:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T06:19:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T06:21:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.31 port 54579 ssh2", "src_ip": "10.0.5.31", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T06:21:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=116.190.234.250 OUT= PROTO=TCP DPT=80", "src_ip": "116.190.234.250", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T06:24:43", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 14", "src_ip": "209.141.56.12", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T06:25:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 59608 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 57689 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 56002 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 52109 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 49235 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 46394 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 43930 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 53975 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 49664 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 54576 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 54164 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 44134 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 48619 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T06:25:57", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T06:26:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T06:26:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T06:26:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T06:26:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T06:26:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T06:26:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T06:26:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T06:26:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T06:26:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T06:28:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=172.164.106.62 OUT= PROTO=TCP DPT=443", "src_ip": "172.164.106.62", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T06:32:21", "source": "nginx", "category": "web_attack", "severity": "high", "message": "37.193.17.34 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 127", "src_ip": "37.193.17.34", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T06:33:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.3.111 port 54028 ssh2", "src_ip": "10.0.3.111", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T06:35:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=200.19.89.107 OUT= PROTO=TCP DPT=80", "src_ip": "200.19.89.107", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T06:40:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.221 port 50833 ssh2", "src_ip": "10.0.4.221", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T06:41:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.208.73.197 OUT= PROTO=TCP DPT=443", "src_ip": "215.208.73.197", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T06:41:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=216.18.248.198 OUT= PROTO=TCP DPT=80", "src_ip": "216.18.248.198", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T06:42:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=165.13.101.184 OUT= PROTO=TCP DPT=443", "src_ip": "165.13.101.184", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T06:44:51", "source": "nginx", "category": "benign", "severity": "info", "message": "115.182.14.194 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1050", "src_ip": "115.182.14.194", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T06:47:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.152 dst=45.137.21.9 dport=443 bytes=326 interval=30s", "src_ip": "10.0.1.152", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T06:47:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.152 dst=45.137.21.9 dport=443 bytes=304 interval=30s", "src_ip": "10.0.1.152", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T06:48:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.152 dst=45.137.21.9 dport=443 bytes=353 interval=30s", "src_ip": "10.0.1.152", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T06:48:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.152 dst=45.137.21.9 dport=443 bytes=548 interval=30s", "src_ip": "10.0.1.152", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T06:49:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.152 dst=45.137.21.9 dport=443 bytes=848 interval=30s", "src_ip": "10.0.1.152", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-12T06:51:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=123.191.224.239 OUT= PROTO=TCP DPT=80", "src_ip": "123.191.224.239", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T06:58:30", "source": "nginx", "category": "benign", "severity": "info", "message": "22.162.242.181 - - \"GET /health HTTP/1.1\" 200 3323", "src_ip": "22.162.242.181", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T06:59:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.201 port 59159 ssh2", "src_ip": "10.0.1.201", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T07:12:53", "source": "nginx", "category": "benign", "severity": "info", "message": "66.156.217.228 - - \"GET /dashboard HTTP/1.1\" 200 4880", "src_ip": "66.156.217.228", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T07:15:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.19 port 46340 ssh2", "src_ip": "10.0.4.19", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-12T07:18:29", "source": "nginx", "category": "benign", "severity": "info", "message": "149.182.39.246 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1301", "src_ip": "149.182.39.246", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T07:19:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.76 port 57187 ssh2", "src_ip": "10.0.4.76", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T07:20:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.135 port 43734 ssh2", "src_ip": "10.0.3.135", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T07:21:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.172.37.112 OUT= PROTO=TCP DPT=443", "src_ip": "164.172.37.112", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T07:25:49", "source": "nginx", "category": "benign", "severity": "info", "message": "181.167.107.62 - - \"GET /dashboard HTTP/1.1\" 200 1418", "src_ip": "181.167.107.62", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T07:26:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=137.110.213.126 OUT= PROTO=TCP DPT=80", "src_ip": "137.110.213.126", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T07:27:12", "source": "nginx", "category": "benign", "severity": "info", "message": "41.126.20.159 - - \"GET / HTTP/1.1\" 200 3634", "src_ip": "41.126.20.159", "status": 200, "path": "/"} {"timestamp": "2026-06-12T07:32:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.234 dst=209.141.56.12 dport=443 bytes=796 interval=30s", "src_ip": "10.0.3.234", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T07:32:37", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.234 dst=209.141.56.12 dport=443 bytes=900 interval=30s", "src_ip": "10.0.3.234", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T07:33:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.234 dst=209.141.56.12 dport=443 bytes=862 interval=30s", "src_ip": "10.0.3.234", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T07:33:37", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.234 dst=209.141.56.12 dport=443 bytes=669 interval=30s", "src_ip": "10.0.3.234", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T07:34:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.234 dst=209.141.56.12 dport=443 bytes=287 interval=30s", "src_ip": "10.0.3.234", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T07:34:37", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.234 dst=209.141.56.12 dport=443 bytes=210 interval=30s", "src_ip": "10.0.3.234", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T07:35:07", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.234 dst=209.141.56.12 dport=443 bytes=680 interval=30s", "src_ip": "10.0.3.234", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T07:46:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=528 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T07:47:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.126 dst=193.27.228.114 dport=443 bytes=610 interval=60s", "src_ip": "10.0.3.126", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-12T07:48:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=16.145.9.165 OUT= PROTO=TCP DPT=80", "src_ip": "16.145.9.165", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T07:48:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.126 dst=193.27.228.114 dport=443 bytes=260 interval=60s", "src_ip": "10.0.3.126", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-12T07:49:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.126 dst=193.27.228.114 dport=443 bytes=368 interval=60s", "src_ip": "10.0.3.126", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-12T07:50:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.126 dst=193.27.228.114 dport=443 bytes=588 interval=60s", "src_ip": "10.0.3.126", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-12T07:51:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=312 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T07:51:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.126 dst=193.27.228.114 dport=443 bytes=202 interval=60s", "src_ip": "10.0.3.126", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-12T07:52:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.126 dst=193.27.228.114 dport=443 bytes=599 interval=60s", "src_ip": "10.0.3.126", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-12T07:56:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=671 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T07:56:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=141.244.69.80 OUT= PROTO=TCP DPT=443", "src_ip": "141.244.69.80", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T07:58:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 44861 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:58:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57341 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:58:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 50539 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:58:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 54728 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:59:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55161 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:59:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 40100 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:59:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 48716 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:59:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 46330 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:59:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 44688 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:59:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 41934 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T07:59:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 48080 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T08:01:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=268 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T08:06:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=555 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T08:07:00", "source": "nginx", "category": "benign", "severity": "info", "message": "24.137.15.170 - - \"GET /health HTTP/1.1\" 200 3152", "src_ip": "24.137.15.170", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T08:08:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.148 port 58011 ssh2", "src_ip": "10.0.3.148", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T08:10:02", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.101 dst=45.137.21.9 dport=443 bytes=626 interval=300s", "src_ip": "10.0.1.101", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-12T08:10:17", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=136.128.176.251 OUT= PROTO=TCP DPT=443", "src_ip": "136.128.176.251", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T08:11:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=366 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T08:11:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=158.207.160.251 OUT= PROTO=TCP DPT=443", "src_ip": "158.207.160.251", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T08:14:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T08:14:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T08:14:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T08:14:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T08:14:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T08:14:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T08:14:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T08:14:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T08:15:02", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.101 dst=45.137.21.9 dport=443 bytes=862 interval=300s", "src_ip": "10.0.1.101", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-12T08:16:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=415 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T08:18:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.183 port 52068 ssh2", "src_ip": "10.0.3.183", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T08:18:59", "source": "nginx", "category": "benign", "severity": "info", "message": "136.30.72.183 - - \"GET /api/products HTTP/1.1\" 200 962", "src_ip": "136.30.72.183", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T08:19:02", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/bash", "user": "nattapong", "host": "web-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-12T08:20:02", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.101 dst=45.137.21.9 dport=443 bytes=331 interval=300s", "src_ip": "10.0.1.101", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-12T08:21:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=784 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T08:24:32", "source": "nginx", "category": "benign", "severity": "info", "message": "110.32.157.128 - - \"GET /static/app.js HTTP/1.1\" 200 7034", "src_ip": "110.32.157.128", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T08:25:02", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.101 dst=45.137.21.9 dport=443 bytes=341 interval=300s", "src_ip": "10.0.1.101", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-12T08:25:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.31 port 58480 ssh2", "src_ip": "10.0.5.31", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T08:26:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.22 dst=91.219.236.18 dport=443 bytes=295 interval=300s", "src_ip": "10.0.5.22", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-12T08:26:47", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 403 12", "src_ip": "185.220.101.34", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T08:29:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.72 port 47420 ssh2", "src_ip": "10.0.0.72", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T08:30:02", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.101 dst=45.137.21.9 dport=443 bytes=805 interval=300s", "src_ip": "10.0.1.101", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-12T08:30:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=89.134.229.111 OUT= PROTO=TCP DPT=443", "src_ip": "89.134.229.111", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T08:33:52", "source": "nginx", "category": "benign", "severity": "info", "message": "199.169.192.53 - - \"GET /dashboard HTTP/1.1\" 200 1709", "src_ip": "199.169.192.53", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T08:38:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=51.159.7.142 OUT= PROTO=TCP DPT=443", "src_ip": "51.159.7.142", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T08:40:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.251 port 46116 ssh2", "src_ip": "10.0.3.251", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-12T08:44:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=144.93.218.240 OUT= PROTO=TCP DPT=80", "src_ip": "144.93.218.240", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T08:52:09", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 200 71", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T08:54:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=175.38.30.160 OUT= PROTO=TCP DPT=443", "src_ip": "175.38.30.160", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T08:57:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.128.89.55 OUT= PROTO=TCP DPT=443", "src_ip": "47.128.89.55", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T08:59:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 47214 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T08:59:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.179 port 53324 ssh2", "src_ip": "10.0.0.179", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T08:59:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 59280 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T08:59:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 46840 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 41298 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 53794 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 55543 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 58144 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 54343 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 51733 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 42364 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 44906 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:00:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 193.27.228.114 port 40529 ssh2", "src_ip": "193.27.228.114", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T09:03:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.198 port 50955 ssh2", "src_ip": "10.0.5.198", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T09:14:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=140.255.46.222 OUT= PROTO=TCP DPT=443", "src_ip": "140.255.46.222", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T09:14:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=124.253.86.154 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "124.253.86.154", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T09:14:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=124.253.86.154 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "124.253.86.154", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T09:14:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=124.253.86.154 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "124.253.86.154", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T09:14:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=124.253.86.154 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "124.253.86.154", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T09:14:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=124.253.86.154 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "124.253.86.154", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T09:14:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=124.253.86.154 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "124.253.86.154", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T09:14:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=124.253.86.154 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "124.253.86.154", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T09:14:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=124.253.86.154 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "124.253.86.154", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T09:14:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.110 port 51399 ssh2", "src_ip": "10.0.1.110", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T09:21:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.49 port 45972 ssh2", "src_ip": "10.0.3.49", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-12T09:22:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=183.99.172.174 OUT= PROTO=TCP DPT=80", "src_ip": "183.99.172.174", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T09:23:33", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.184 dst=91.219.236.18 bytes=3802136576 proto=TCP dport=443 duration=503s", "src_ip": "10.0.3.184", "dst_ip": "91.219.236.18", "bytes_mb": 3626, "off_hours": false} {"timestamp": "2026-06-12T09:25:10", "source": "nginx", "category": "benign", "severity": "info", "message": "172.242.29.37 - - \"GET /dashboard HTTP/1.1\" 200 6131", "src_ip": "172.242.29.37", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T09:25:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T09:25:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T09:25:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T09:25:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T09:25:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T09:25:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T09:25:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T09:25:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T09:25:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T09:25:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T09:25:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T09:25:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.190 port 49322 ssh2", "src_ip": "10.0.1.190", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-12T09:26:09", "source": "nginx", "category": "benign", "severity": "info", "message": "214.204.204.253 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4181", "src_ip": "214.204.204.253", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T09:26:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 51036 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 46588 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 49470 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 50498 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 42440 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 58444 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 41026 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 51871 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 44902 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 52058 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 44799 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 49371 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 41907 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 56075 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 42983 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:26:57", "source": "nginx", "category": "benign", "severity": "info", "message": "63.117.103.214 - - \"GET /login HTTP/1.1\" 200 7051", "src_ip": "63.117.103.214", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T09:26:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 55326 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T09:27:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T09:27:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T09:27:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T09:27:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T09:27:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T09:27:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T09:27:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T09:27:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T09:31:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=123.71.241.211 OUT= PROTO=TCP DPT=443", "src_ip": "123.71.241.211", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T09:32:59", "source": "nginx", "category": "benign", "severity": "info", "message": "195.178.208.31 - - \"GET / HTTP/1.1\" 200 3150", "src_ip": "195.178.208.31", "status": 200, "path": "/"} {"timestamp": "2026-06-12T09:36:38", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/bash", "user": "guest", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-12T09:36:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 434", "src_ip": "185.220.101.34", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T09:41:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=201.244.242.206 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "201.244.242.206", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T09:41:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=201.244.242.206 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "201.244.242.206", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T09:41:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=201.244.242.206 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "201.244.242.206", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T09:41:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=201.244.242.206 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "201.244.242.206", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T09:41:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=201.244.242.206 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "201.244.242.206", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T09:41:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=201.244.242.206 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "201.244.242.206", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T09:41:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=201.244.242.206 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "201.244.242.206", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T09:41:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=201.244.242.206 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "201.244.242.206", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T09:41:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T09:41:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T09:41:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T09:41:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T09:41:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T09:41:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T09:41:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T09:41:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T09:42:17", "source": "nginx", "category": "benign", "severity": "info", "message": "79.30.49.29 - - \"GET /login HTTP/1.1\" 200 3828", "src_ip": "79.30.49.29", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T09:43:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.24 port 52583 ssh2", "src_ip": "10.0.0.24", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T09:44:42", "source": "nginx", "category": "benign", "severity": "info", "message": "222.139.75.31 - - \"GET /api/products HTTP/1.1\" 200 7362", "src_ip": "222.139.75.31", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T09:45:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.124 port 59429 ssh2", "src_ip": "10.0.5.124", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T09:48:13", "source": "nginx", "category": "benign", "severity": "info", "message": "209.234.235.230 - - \"GET /static/app.js HTTP/1.1\" 200 7261", "src_ip": "209.234.235.230", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T09:53:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=181.67.228.45 OUT= PROTO=TCP DPT=80", "src_ip": "181.67.228.45", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T09:54:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.216 port 42958 ssh2", "src_ip": "10.0.4.216", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T09:55:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.149 port 53868 ssh2", "src_ip": "10.0.0.149", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T09:57:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.236 port 43715 ssh2", "src_ip": "10.0.3.236", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T10:04:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.81 port 59416 ssh2", "src_ip": "10.0.5.81", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T10:05:11", "source": "nginx", "category": "benign", "severity": "info", "message": "44.203.245.169 - - \"GET / HTTP/1.1\" 200 5578", "src_ip": "44.203.245.169", "status": 200, "path": "/"} {"timestamp": "2026-06-12T10:11:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=73.132.141.149 OUT= PROTO=TCP DPT=443", "src_ip": "73.132.141.149", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T10:14:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.128 port 42186 ssh2", "src_ip": "10.0.2.128", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-12T10:18:27", "source": "nginx", "category": "benign", "severity": "info", "message": "124.160.21.131 - - \"GET /static/app.js HTTP/1.1\" 200 7586", "src_ip": "124.160.21.131", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T10:23:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=133.110.20.83 OUT= PROTO=TCP DPT=443", "src_ip": "133.110.20.83", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T10:26:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.203 port 47477 ssh2", "src_ip": "10.0.3.203", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T10:27:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.64 port 55227 ssh2", "src_ip": "10.0.3.64", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-12T10:29:04", "source": "nginx", "category": "benign", "severity": "info", "message": "206.102.90.35 - - \"GET /login HTTP/1.1\" 200 2640", "src_ip": "206.102.90.35", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T10:34:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=93.174.107.118 OUT= PROTO=TCP DPT=443", "src_ip": "93.174.107.118", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T10:37:34", "source": "nginx", "category": "benign", "severity": "info", "message": "133.54.70.215 - - \"GET /health HTTP/1.1\" 200 2257", "src_ip": "133.54.70.215", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T10:41:56", "source": "nginx", "category": "benign", "severity": "info", "message": "211.74.185.122 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3212", "src_ip": "211.74.185.122", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T10:42:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.13 dst=91.219.236.18 dport=443 bytes=272 interval=60s", "src_ip": "10.0.5.13", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-12T10:43:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.13 dst=91.219.236.18 dport=443 bytes=685 interval=60s", "src_ip": "10.0.5.13", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-12T10:44:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.13 dst=91.219.236.18 dport=443 bytes=280 interval=60s", "src_ip": "10.0.5.13", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-12T10:45:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.13 dst=91.219.236.18 dport=443 bytes=632 interval=60s", "src_ip": "10.0.5.13", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-12T10:46:22", "source": "nginx", "category": "benign", "severity": "info", "message": "164.55.167.137 - - \"GET /api/products HTTP/1.1\" 200 2783", "src_ip": "164.55.167.137", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T10:46:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.13 dst=91.219.236.18 dport=443 bytes=899 interval=60s", "src_ip": "10.0.5.13", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-12T10:47:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.150 port 47287 ssh2", "src_ip": "10.0.3.150", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T10:48:40", "source": "nginx", "category": "benign", "severity": "info", "message": "185.97.67.80 - - \"GET / HTTP/1.1\" 200 3307", "src_ip": "185.97.67.80", "status": 200, "path": "/"} {"timestamp": "2026-06-12T10:49:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=97.164.56.36 OUT= PROTO=TCP DPT=80", "src_ip": "97.164.56.36", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T10:51:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=159.65.49.252 OUT= PROTO=TCP DPT=443", "src_ip": "159.65.49.252", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T10:51:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T10:51:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T10:51:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T10:51:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T10:51:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T10:51:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T10:51:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T10:51:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T10:51:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T10:58:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.5.33 port 52381 ssh2", "src_ip": "10.0.5.33", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-12T11:00:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 44259 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 42816 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 43906 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 51359 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 55004 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 41375 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 41638 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 58114 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 41621 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 49546 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 42422 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:00:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 41181 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:01:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 47390 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-12T11:04:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=189.39.35.177 OUT= PROTO=TCP DPT=443", "src_ip": "189.39.35.177", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T11:07:53", "source": "nginx", "category": "benign", "severity": "info", "message": "152.156.55.1 - - \"GET / HTTP/1.1\" 200 1755", "src_ip": "152.156.55.1", "status": 200, "path": "/"} {"timestamp": "2026-06-12T11:14:16", "source": "nginx", "category": "benign", "severity": "info", "message": "190.192.1.94 - - \"GET /login HTTP/1.1\" 200 311", "src_ip": "190.192.1.94", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T11:15:48", "source": "nginx", "category": "benign", "severity": "info", "message": "180.83.104.183 - - \"GET /dashboard HTTP/1.1\" 200 1084", "src_ip": "180.83.104.183", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T11:16:24", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 457", "src_ip": "91.219.236.18", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T11:20:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=157.209.3.99 OUT= PROTO=TCP DPT=80", "src_ip": "157.209.3.99", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T11:20:13", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.160 dst=185.220.101.34 bytes=6418333696 proto=TCP dport=443 duration=546s", "src_ip": "10.0.3.160", "dst_ip": "185.220.101.34", "bytes_mb": 6121, "off_hours": false} {"timestamp": "2026-06-12T11:22:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.141 dst=209.141.56.12 dport=443 bytes=283 interval=30s", "src_ip": "10.0.5.141", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T11:22:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.76 port 46000 ssh2", "src_ip": "10.0.3.76", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-12T11:22:29", "source": "nginx", "category": "benign", "severity": "info", "message": "201.206.232.62 - - \"GET /static/app.js HTTP/1.1\" 200 1111", "src_ip": "201.206.232.62", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T11:22:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.141 dst=209.141.56.12 dport=443 bytes=752 interval=30s", "src_ip": "10.0.5.141", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T11:23:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.141 dst=209.141.56.12 dport=443 bytes=224 interval=30s", "src_ip": "10.0.5.141", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T11:23:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.195 port 57254 ssh2", "src_ip": "10.0.0.195", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T11:23:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T11:23:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T11:23:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T11:23:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T11:23:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T11:23:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T11:23:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T11:23:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T11:23:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T11:23:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T11:23:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.141 dst=209.141.56.12 dport=443 bytes=897 interval=30s", "src_ip": "10.0.5.141", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T11:23:36", "source": "nginx", "category": "benign", "severity": "info", "message": "168.190.115.235 - - \"GET /health HTTP/1.1\" 200 892", "src_ip": "168.190.115.235", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T11:24:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.141 dst=209.141.56.12 dport=443 bytes=414 interval=30s", "src_ip": "10.0.5.141", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T11:24:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.141 dst=209.141.56.12 dport=443 bytes=802 interval=30s", "src_ip": "10.0.5.141", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-12T11:25:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.35 port 43365 ssh2", "src_ip": "10.0.2.35", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T11:26:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T11:26:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T11:26:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T11:26:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T11:26:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T11:26:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T11:26:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T11:26:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T11:26:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T11:26:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T11:26:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T11:26:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T11:27:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=159.202.225.80 OUT= PROTO=TCP DPT=443", "src_ip": "159.202.225.80", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T11:30:41", "source": "nginx", "category": "benign", "severity": "info", "message": "43.94.46.239 - - \"GET /health HTTP/1.1\" 200 756", "src_ip": "43.94.46.239", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T11:34:50", "source": "nginx", "category": "benign", "severity": "info", "message": "56.42.193.207 - - \"GET /api/products HTTP/1.1\" 200 2300", "src_ip": "56.42.193.207", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T11:36:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=99.10.178.184 OUT= PROTO=TCP DPT=80", "src_ip": "99.10.178.184", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T11:37:32", "source": "nginx", "category": "benign", "severity": "info", "message": "97.187.117.142 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4519", "src_ip": "97.187.117.142", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T11:41:40", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "web-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-12T11:41:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 44903 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:41:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 43702 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:41:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 45772 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:41:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 50502 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:41:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 46399 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:41:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 46630 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 48541 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 49985 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 52533 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 45446 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 49647 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 40049 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 54510 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 57680 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 56664 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 40384 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 55224 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:27", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T11:42:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 56992 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:42:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 59009 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-12T11:43:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.34 port 44446 ssh2", "src_ip": "10.0.1.34", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T11:47:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T11:47:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T11:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T11:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T11:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T11:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T11:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T11:47:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T11:47:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T11:47:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T11:47:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T11:47:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.235.9.80 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "222.235.9.80", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T11:47:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.138 port 43548 ssh2", "src_ip": "10.0.3.138", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T11:48:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.97 port 49806 ssh2", "src_ip": "10.0.3.97", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T11:49:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=63.253.182.230 OUT= PROTO=TCP DPT=80", "src_ip": "63.253.182.230", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T11:50:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=15.44.32.42 OUT= PROTO=TCP DPT=80", "src_ip": "15.44.32.42", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T11:52:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.233 port 45423 ssh2", "src_ip": "10.0.5.233", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T11:56:12", "source": "nginx", "category": "benign", "severity": "info", "message": "15.254.76.168 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 207", "src_ip": "15.254.76.168", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T11:57:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 58569 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:57:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 57813 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 50606 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 57404 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 54725 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 59617 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 55348 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 51930 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 45254 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 48629 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 40023 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 46079 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 52029 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 42075 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 56579 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 46221 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 47824 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 53428 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:43", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for root from 135.224.150.139 port 51234 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T11:58:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 57660 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 56303 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 45050 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:58:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 49277 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T11:59:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 135.224.150.139 port 50552 ssh2", "src_ip": "135.224.150.139", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-12T12:02:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 59676 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:02:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 50883 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:02:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49187 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:02:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 47450 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:02:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 58465 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:02:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 46265 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:02:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 40575 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:02:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 45032 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 50117 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 56825 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49361 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 54418 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 51880 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 55067 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 48759 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 54312 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:27", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T12:03:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 51970 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 57127 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:03:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 45209 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T12:05:15", "source": "nginx", "category": "benign", "severity": "info", "message": "169.80.38.67 - - \"GET /static/app.js HTTP/1.1\" 200 5145", "src_ip": "169.80.38.67", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T12:14:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=141.168.214.171 OUT= PROTO=TCP DPT=443", "src_ip": "141.168.214.171", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T12:17:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=101.91.162.189 OUT= PROTO=TCP DPT=80", "src_ip": "101.91.162.189", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T12:18:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.212 port 52785 ssh2", "src_ip": "10.0.0.212", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T12:21:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T12:21:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T12:21:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T12:21:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T12:21:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T12:21:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T12:21:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T12:21:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T12:23:54", "source": "nginx", "category": "benign", "severity": "info", "message": "58.254.237.169 - - \"GET /dashboard HTTP/1.1\" 200 6620", "src_ip": "58.254.237.169", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T12:25:28", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 332", "src_ip": "209.141.56.12", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T12:27:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=170.41.71.243 OUT= PROTO=TCP DPT=80", "src_ip": "170.41.71.243", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T12:29:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.212 dst=91.219.236.18 dport=443 bytes=703 interval=30s", "src_ip": "10.0.0.212", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-12T12:29:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.212 dst=91.219.236.18 dport=443 bytes=275 interval=30s", "src_ip": "10.0.0.212", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-12T12:30:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.212 dst=91.219.236.18 dport=443 bytes=790 interval=30s", "src_ip": "10.0.0.212", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-12T12:30:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.212 dst=91.219.236.18 dport=443 bytes=844 interval=30s", "src_ip": "10.0.0.212", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-12T12:31:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.212 dst=91.219.236.18 dport=443 bytes=254 interval=30s", "src_ip": "10.0.0.212", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-12T12:31:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.212 dst=91.219.236.18 dport=443 bytes=355 interval=30s", "src_ip": "10.0.0.212", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-12T12:32:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.212 dst=91.219.236.18 dport=443 bytes=352 interval=30s", "src_ip": "10.0.0.212", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-12T12:32:19", "source": "nginx", "category": "benign", "severity": "info", "message": "144.53.113.1 - - \"GET /static/app.js HTTP/1.1\" 200 7386", "src_ip": "144.53.113.1", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T12:32:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.212 dst=91.219.236.18 dport=443 bytes=776 interval=30s", "src_ip": "10.0.0.212", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-12T12:33:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.253 port 57053 ssh2", "src_ip": "10.0.2.253", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T12:33:38", "source": "nginx", "category": "benign", "severity": "info", "message": "190.78.105.178 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5363", "src_ip": "190.78.105.178", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T12:35:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.116 port 41492 ssh2", "src_ip": "10.0.0.116", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T12:36:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.62 port 45041 ssh2", "src_ip": "10.0.5.62", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T12:40:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=63.104.108.109 OUT= PROTO=TCP DPT=443", "src_ip": "63.104.108.109", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T12:41:36", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 143", "src_ip": "209.141.56.12", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T12:41:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.76 port 44945 ssh2", "src_ip": "10.0.0.76", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T12:46:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.97 port 46254 ssh2", "src_ip": "10.0.4.97", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T12:49:16", "source": "nginx", "category": "benign", "severity": "info", "message": "148.216.187.157 - - \"GET /api/products HTTP/1.1\" 200 5775", "src_ip": "148.216.187.157", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T12:49:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=108.2.168.24 OUT= PROTO=TCP DPT=443", "src_ip": "108.2.168.24", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T12:55:17", "source": "nginx", "category": "benign", "severity": "info", "message": "76.4.238.231 - - \"GET /api/products HTTP/1.1\" 200 5750", "src_ip": "76.4.238.231", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T12:58:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T12:58:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T12:58:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T12:58:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T12:58:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T12:58:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T12:58:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T12:58:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T12:58:32", "source": "nginx", "category": "benign", "severity": "info", "message": "116.145.170.33 - - \"GET /login HTTP/1.1\" 200 2692", "src_ip": "116.145.170.33", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T13:00:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=74.221.199.7 OUT= PROTO=TCP DPT=443", "src_ip": "74.221.199.7", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T13:04:38", "source": "nginx", "category": "benign", "severity": "info", "message": "153.48.205.86 - - \"GET /health HTTP/1.1\" 200 6999", "src_ip": "153.48.205.86", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T13:08:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T13:08:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T13:08:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T13:08:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T13:08:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T13:08:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T13:08:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T13:08:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T13:08:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T13:08:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T13:08:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T13:09:47", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=55.25.128.230 OUT= PROTO=TCP DPT=80", "src_ip": "55.25.128.230", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T13:10:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T13:10:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T13:10:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T13:10:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T13:10:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T13:10:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T13:10:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T13:10:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T13:12:35", "source": "nginx", "category": "benign", "severity": "info", "message": "108.83.204.117 - - \"GET / HTTP/1.1\" 200 7939", "src_ip": "108.83.204.117", "status": 200, "path": "/"} {"timestamp": "2026-06-12T13:13:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.22 port 54738 ssh2", "src_ip": "10.0.5.22", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T13:13:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 48288 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 44200 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 48152 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 41317 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46041 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 48191 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 59012 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 47147 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.183 port 45072 ssh2", "src_ip": "10.0.3.183", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T13:13:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 41525 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 43690 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 42365 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 52934 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 40092 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:13:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46887 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T13:21:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.24 port 48746 ssh2", "src_ip": "10.0.3.24", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T13:25:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 41081 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:25:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 48451 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:25:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 52487 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:25:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 50977 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:25:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 54178 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:25:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 44865 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:25:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 55236 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:25:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 51233 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:25:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=551 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:26:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=870 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:26:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=768 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:27:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=528 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:27:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=472 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:28:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=889 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:28:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=354 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:29:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=303 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:29:24", "source": "nginx", "category": "benign", "severity": "info", "message": "106.12.164.110 - - \"GET /health HTTP/1.1\" 200 3332", "src_ip": "106.12.164.110", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T13:29:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=895 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:30:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.172 dst=193.27.228.114 dport=443 bytes=727 interval=30s", "src_ip": "10.0.3.172", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T13:34:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 59869 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 59602 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 48311 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 41491 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 58335 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 59021 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 48529 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 52933 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 56506 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 52482 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 50397 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 52153 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 56358 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 51114 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:34:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 44322 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 44646 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 43828 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 41447 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 51815 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 49270 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 57380 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 48642 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 40944 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 59771 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 43692 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 52696 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 56770 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 46704 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 46736 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 58684 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 193.27.228.114 port 50256 ssh2", "src_ip": "193.27.228.114", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 47530 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 56747 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 50154 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 47091 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 55197 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 49784 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:35:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 47023 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:36:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 49940 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:36:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48268 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T13:40:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.27 port 53334 ssh2", "src_ip": "10.0.4.27", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T13:45:38", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.249 dst=45.137.21.9 bytes=1523580928 proto=TCP dport=443 duration=256s", "src_ip": "10.0.3.249", "dst_ip": "45.137.21.9", "bytes_mb": 1453, "off_hours": false} {"timestamp": "2026-06-12T13:47:17", "source": "nginx", "category": "benign", "severity": "info", "message": "172.220.134.249 - - \"GET /api/products HTTP/1.1\" 200 631", "src_ip": "172.220.134.249", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T13:49:44", "source": "nginx", "category": "benign", "severity": "info", "message": "52.218.104.187 - - \"GET /login HTTP/1.1\" 200 3160", "src_ip": "52.218.104.187", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T13:53:27", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 200 132", "src_ip": "193.27.228.114", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T13:57:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=41.226.200.41 OUT= PROTO=TCP DPT=80", "src_ip": "41.226.200.41", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T13:59:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T13:59:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T13:59:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T13:59:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T13:59:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T13:59:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T13:59:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T13:59:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T13:59:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T14:02:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.188 port 54909 ssh2", "src_ip": "10.0.4.188", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T14:03:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.4.243 port 51631 ssh2", "src_ip": "10.0.4.243", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T14:04:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=177.84.28.73 OUT= PROTO=TCP DPT=80", "src_ip": "177.84.28.73", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T14:08:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T14:08:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T14:08:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T14:08:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T14:08:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T14:08:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T14:08:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T14:08:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T14:08:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T14:08:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T14:08:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=88.142.127.206 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "88.142.127.206", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T14:09:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T14:09:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T14:09:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T14:09:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T14:09:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T14:09:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T14:09:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T14:09:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T14:09:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T14:09:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T14:09:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T14:09:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T14:11:45", "source": "nginx", "category": "benign", "severity": "info", "message": "82.141.5.133 - - \"GET /login HTTP/1.1\" 200 901", "src_ip": "82.141.5.133", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T14:12:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.5 port 55029 ssh2", "src_ip": "10.0.5.5", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T14:19:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.61 port 54362 ssh2", "src_ip": "10.0.5.61", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T14:20:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.198 port 50702 ssh2", "src_ip": "10.0.5.198", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T14:20:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.197 port 53228 ssh2", "src_ip": "10.0.3.197", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T14:22:38", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.25 dst=185.220.101.34 bytes=4262461440 proto=TCP dport=443 duration=366s", "src_ip": "10.0.5.25", "dst_ip": "185.220.101.34", "bytes_mb": 4065, "off_hours": false} {"timestamp": "2026-06-12T14:30:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T14:30:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T14:30:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T14:30:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T14:30:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T14:30:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T14:30:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T14:30:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T14:30:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.231 port 54042 ssh2", "src_ip": "10.0.0.231", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T14:33:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.210 port 57291 ssh2", "src_ip": "10.0.2.210", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T14:36:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=14.35.185.53 OUT= PROTO=TCP DPT=443", "src_ip": "14.35.185.53", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T14:38:05", "source": "nginx", "category": "benign", "severity": "info", "message": "51.86.112.219 - - \"GET /static/app.js HTTP/1.1\" 200 5483", "src_ip": "51.86.112.219", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T14:44:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=65.10.100.104 OUT= PROTO=TCP DPT=443", "src_ip": "65.10.100.104", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T14:53:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.167 port 58274 ssh2", "src_ip": "10.0.0.167", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T14:59:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.181 port 49353 ssh2", "src_ip": "10.0.1.181", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T15:01:46", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 310", "src_ip": "209.141.56.12", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T15:11:29", "source": "nginx", "category": "benign", "severity": "info", "message": "160.142.81.108 - - \"GET /api/products HTTP/1.1\" 200 460", "src_ip": "160.142.81.108", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T15:11:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.37 port 52416 ssh2", "src_ip": "10.0.5.37", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T15:11:50", "source": "nginx", "category": "benign", "severity": "info", "message": "27.217.240.137 - - \"GET /dashboard HTTP/1.1\" 200 5455", "src_ip": "27.217.240.137", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T15:11:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.63 port 53879 ssh2", "src_ip": "10.0.4.63", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T15:15:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=55.173.125.46 OUT= PROTO=TCP DPT=80", "src_ip": "55.173.125.46", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T15:18:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=108.190.55.173 OUT= PROTO=TCP DPT=80", "src_ip": "108.190.55.173", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T15:22:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=42.252.238.243 OUT= PROTO=TCP DPT=80", "src_ip": "42.252.238.243", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T15:24:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T15:24:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T15:24:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T15:24:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T15:24:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T15:24:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T15:24:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T15:24:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T15:24:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T15:24:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T15:30:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T15:30:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T15:30:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T15:30:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T15:30:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T15:30:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T15:30:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T15:30:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T15:30:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T15:30:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T15:30:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T15:33:54", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.88 dst=45.137.21.9 bytes=4143972352 proto=TCP dport=443 duration=327s", "src_ip": "10.0.0.88", "dst_ip": "45.137.21.9", "bytes_mb": 3952, "off_hours": false} {"timestamp": "2026-06-12T15:35:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.39 port 43634 ssh2", "src_ip": "10.0.0.39", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T15:36:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.199 port 57933 ssh2", "src_ip": "10.0.4.199", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T15:38:10", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 403 406", "src_ip": "45.137.21.9", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T15:47:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.196 port 40318 ssh2", "src_ip": "10.0.5.196", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T15:49:53", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.236 dst=193.27.228.114 bytes=2449473536 proto=TCP dport=443 duration=229s", "src_ip": "10.0.3.236", "dst_ip": "193.27.228.114", "bytes_mb": 2336, "off_hours": false} {"timestamp": "2026-06-12T15:52:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=172.139.193.235 OUT= PROTO=TCP DPT=443", "src_ip": "172.139.193.235", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T15:55:34", "source": "nginx", "category": "web_attack", "severity": "high", "message": "56.222.36.121 - - \"GET /search?q= HTTP/1.1\" 403 410", "src_ip": "56.222.36.121", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T15:56:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=134.98.126.72 OUT= PROTO=TCP DPT=443", "src_ip": "134.98.126.72", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T15:57:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T15:57:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T15:57:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T15:57:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T15:57:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T15:57:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T15:57:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T15:57:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T15:57:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T15:57:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T15:57:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T15:57:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T15:59:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.33 port 52403 ssh2", "src_ip": "10.0.4.33", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T16:00:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=23.86.165.13 OUT= PROTO=TCP DPT=80", "src_ip": "23.86.165.13", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T16:01:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.209 port 49080 ssh2", "src_ip": "10.0.4.209", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T16:02:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.127 port 46575 ssh2", "src_ip": "10.0.0.127", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T16:06:11", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 54", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T16:08:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T16:08:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T16:08:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T16:08:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T16:08:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T16:08:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T16:08:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T16:08:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T16:08:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T16:08:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T16:08:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T16:08:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T16:13:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T16:13:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T16:13:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T16:13:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T16:13:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T16:13:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T16:13:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T16:13:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T16:13:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T16:13:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T16:13:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T16:16:35", "source": "nginx", "category": "benign", "severity": "info", "message": "94.197.166.173 - - \"GET /health HTTP/1.1\" 200 3881", "src_ip": "94.197.166.173", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T16:18:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.11 port 46190 ssh2", "src_ip": "10.0.0.11", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-12T16:19:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=145.213.242.49 OUT= PROTO=TCP DPT=443", "src_ip": "145.213.242.49", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T16:21:54", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.127 dst=45.137.21.9 bytes=5249171456 proto=TCP dport=443 duration=567s", "src_ip": "10.0.3.127", "dst_ip": "45.137.21.9", "bytes_mb": 5006, "off_hours": false} {"timestamp": "2026-06-12T16:22:10", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 200 49", "src_ip": "185.220.101.34", "status": 200, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T16:23:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T16:23:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T16:23:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T16:23:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T16:23:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T16:23:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T16:23:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T16:23:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T16:23:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T16:23:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T16:23:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T16:23:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T16:25:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.184 port 52014 ssh2", "src_ip": "10.0.4.184", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T16:42:46", "source": "nginx", "category": "benign", "severity": "info", "message": "88.5.133.168 - - \"GET /api/products HTTP/1.1\" 200 5875", "src_ip": "88.5.133.168", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T16:44:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.201 dst=185.220.101.34 dport=443 bytes=777 interval=300s", "src_ip": "10.0.3.201", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T16:49:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.201 dst=185.220.101.34 dport=443 bytes=891 interval=300s", "src_ip": "10.0.3.201", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T16:50:42", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "somchai", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-12T16:54:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T16:54:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T16:54:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T16:54:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T16:54:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T16:54:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T16:54:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T16:54:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T16:54:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T16:54:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T16:54:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T16:54:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T16:54:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.201 dst=185.220.101.34 dport=443 bytes=475 interval=300s", "src_ip": "10.0.3.201", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T16:54:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=61.151.117.170 OUT= PROTO=TCP DPT=443", "src_ip": "61.151.117.170", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T16:56:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.166 port 53474 ssh2", "src_ip": "10.0.4.166", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T16:58:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.187 port 49126 ssh2", "src_ip": "10.0.3.187", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-12T16:59:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.201 dst=185.220.101.34 dport=443 bytes=711 interval=300s", "src_ip": "10.0.3.201", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T17:04:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.201 dst=185.220.101.34 dport=443 bytes=538 interval=300s", "src_ip": "10.0.3.201", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T17:04:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 52878 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 59485 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 54119 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 49186 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 42591 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 52527 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 51247 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 57546 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 52122 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:04:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 50587 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 43697 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 40443 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 47851 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 46074 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 40259 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 59527 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 50880 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 58865 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 50038 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 53011 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 42868 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 54636 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 49049 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-12T17:05:45", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "guest", "host": "web-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-12T17:09:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.201 dst=185.220.101.34 dport=443 bytes=664 interval=300s", "src_ip": "10.0.3.201", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T17:09:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=41.87.114.12 OUT= PROTO=TCP DPT=80", "src_ip": "41.87.114.12", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T17:10:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=26.77.49.22 OUT= PROTO=TCP DPT=443", "src_ip": "26.77.49.22", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T17:12:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=117.192.231.20 OUT= PROTO=TCP DPT=80", "src_ip": "117.192.231.20", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T17:13:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 42092 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 58895 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 56371 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 42525 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54915 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 56673 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41443 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 51800 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 48013 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 55458 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 45154 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 45864 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:13:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 43371 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:14:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 45468 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:14:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 43779 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:14:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 52549 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:14:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.201 dst=185.220.101.34 dport=443 bytes=611 interval=300s", "src_ip": "10.0.3.201", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T17:16:24", "source": "nginx", "category": "benign", "severity": "info", "message": "79.252.74.17 - - \"GET /login HTTP/1.1\" 200 3760", "src_ip": "79.252.74.17", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T17:17:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=104.14.164.27 OUT= PROTO=TCP DPT=80", "src_ip": "104.14.164.27", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T17:19:12", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.201 dst=185.220.101.34 dport=443 bytes=800 interval=300s", "src_ip": "10.0.3.201", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T17:25:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 201", "src_ip": "209.141.56.12", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T17:27:31", "source": "nginx", "category": "benign", "severity": "info", "message": "26.56.94.88 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5934", "src_ip": "26.56.94.88", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T17:30:31", "source": "nginx", "category": "benign", "severity": "info", "message": "27.202.249.103 - - \"GET /health HTTP/1.1\" 200 6178", "src_ip": "27.202.249.103", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T17:36:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=217.247.238.112 OUT= PROTO=TCP DPT=443", "src_ip": "217.247.238.112", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T17:37:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.177 port 57968 ssh2", "src_ip": "10.0.0.177", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T17:38:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 47539 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 48432 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 55487 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 43359 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 54292 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 49315 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 58416 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 57262 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 52573 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 51141 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 48336 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 49436 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 58927 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 41221 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 54242 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 58655 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 40682 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 48814 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 45344 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 44376 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 50805 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:38:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 40270 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:39:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 57139 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:39:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 52229 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:39:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 48912 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 47690 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 50245 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 57834 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 40472 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 50158 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 49716 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 41009 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 49159 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 48796 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:41:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 52053 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:42:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 59691 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:42:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 48871 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:42:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 54392 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:42:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 51502 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:42:19", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for admin from 187.117.31.106 port 51234 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-12T17:42:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 187.117.31.106 port 42977 ssh2", "src_ip": "187.117.31.106", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-12T17:42:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.110 port 58339 ssh2", "src_ip": "10.0.5.110", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T17:54:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 46699 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 52165 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 59808 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55470 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 57182 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 46901 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 50410 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44434 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55417 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 40183 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43075 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55358 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 45872 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 51483 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:54:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 51303 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55527 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 48997 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 46149 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43103 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55027 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 53964 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 45126 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 58322 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:55:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 40462 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T17:57:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.243 port 40273 ssh2", "src_ip": "10.0.5.243", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T17:58:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=179.184.55.5 OUT= PROTO=TCP DPT=443", "src_ip": "179.184.55.5", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T18:12:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.42 port 48871 ssh2", "src_ip": "10.0.1.42", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T18:20:34", "source": "nginx", "category": "benign", "severity": "info", "message": "80.136.50.66 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4985", "src_ip": "80.136.50.66", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T18:20:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.114.80.17 OUT= PROTO=TCP DPT=80", "src_ip": "147.114.80.17", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T18:24:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.43 port 55037 ssh2", "src_ip": "10.0.2.43", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-12T18:25:56", "source": "nginx", "category": "benign", "severity": "info", "message": "216.156.83.41 - - \"GET /static/app.js HTTP/1.1\" 200 4613", "src_ip": "216.156.83.41", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T18:27:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.61 port 49796 ssh2", "src_ip": "10.0.4.61", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T18:27:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=113.182.243.171 OUT= PROTO=TCP DPT=443", "src_ip": "113.182.243.171", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T18:35:09", "source": "nginx", "category": "benign", "severity": "info", "message": "134.241.124.117 - - \"GET /static/app.js HTTP/1.1\" 200 1384", "src_ip": "134.241.124.117", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T18:35:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=612 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:35:44", "source": "nginx", "category": "benign", "severity": "info", "message": "42.194.202.210 - - \"GET /api/products HTTP/1.1\" 200 6532", "src_ip": "42.194.202.210", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T18:35:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=720 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:36:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=526 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:36:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.40 port 51192 ssh2", "src_ip": "10.0.2.40", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T18:36:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=833 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:37:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=419 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:37:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=715 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:38:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=241 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:38:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=604 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:39:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.92 dst=193.27.228.114 dport=443 bytes=361 interval=30s", "src_ip": "10.0.2.92", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-12T18:41:18", "source": "nginx", "category": "web_attack", "severity": "high", "message": "171.149.34.179 - - \"GET /search?q= HTTP/1.1\" 403 210", "src_ip": "171.149.34.179", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T18:42:33", "source": "nginx", "category": "benign", "severity": "info", "message": "123.114.86.74 - - \"GET /api/products HTTP/1.1\" 200 5165", "src_ip": "123.114.86.74", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T18:42:56", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.110 dst=209.141.56.12 bytes=7520387072 proto=TCP dport=443 duration=553s", "src_ip": "10.0.4.110", "dst_ip": "209.141.56.12", "bytes_mb": 7172, "off_hours": false} {"timestamp": "2026-06-12T18:43:25", "source": "nginx", "category": "benign", "severity": "info", "message": "23.129.1.111 - - \"GET /dashboard HTTP/1.1\" 200 1499", "src_ip": "23.129.1.111", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T18:43:33", "source": "nginx", "category": "benign", "severity": "info", "message": "31.152.231.224 - - \"GET /dashboard HTTP/1.1\" 200 4498", "src_ip": "31.152.231.224", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T18:45:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T18:45:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T18:45:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T18:45:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T18:45:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T18:45:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T18:45:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T18:45:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T18:45:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T18:45:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T18:52:28", "source": "nginx", "category": "benign", "severity": "info", "message": "41.63.231.44 - - \"GET /static/app.js HTTP/1.1\" 200 2877", "src_ip": "41.63.231.44", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T18:53:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T18:53:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T18:53:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T18:53:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T18:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T18:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T18:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T18:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T18:53:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T18:53:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T18:54:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=192.234.141.23 OUT= PROTO=TCP DPT=80", "src_ip": "192.234.141.23", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T18:58:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.49 port 55096 ssh2", "src_ip": "10.0.2.49", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T19:01:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=133.203.22.179 OUT= PROTO=TCP DPT=443", "src_ip": "133.203.22.179", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T19:09:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 57060 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 53013 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 56761 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 43352 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 52262 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 44912 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 43542 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 59456 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 59661 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 42091 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 49262 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 49059 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 48557 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 50654 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 50472 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 49790 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:09:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 48500 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:10:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 47874 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:10:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 53257 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:10:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 44585 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:10:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 40834 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:10:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 56297 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-12T19:10:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.142 port 50703 ssh2", "src_ip": "10.0.2.142", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T19:18:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=166.252.221.28 OUT= PROTO=TCP DPT=80", "src_ip": "166.252.221.28", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T19:19:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=141.79.48.10 OUT= PROTO=TCP DPT=443", "src_ip": "141.79.48.10", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T19:22:41", "source": "nginx", "category": "benign", "severity": "info", "message": "137.65.116.162 - - \"GET /login HTTP/1.1\" 200 1403", "src_ip": "137.65.116.162", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T19:23:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=128.6.214.29 OUT= PROTO=TCP DPT=443", "src_ip": "128.6.214.29", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T19:23:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=799 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T19:24:29", "source": "nginx", "category": "benign", "severity": "info", "message": "59.21.175.214 - - \"GET /static/app.js HTTP/1.1\" 200 1207", "src_ip": "59.21.175.214", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T19:27:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.20 port 51804 ssh2", "src_ip": "10.0.0.20", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-12T19:28:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=888 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T19:33:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=136.129.245.130 OUT= PROTO=TCP DPT=80", "src_ip": "136.129.245.130", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T19:33:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=355 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T19:35:00", "source": "nginx", "category": "benign", "severity": "info", "message": "22.185.163.65 - - \"GET /static/app.js HTTP/1.1\" 200 795", "src_ip": "22.185.163.65", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T19:37:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=32.127.145.200 OUT= PROTO=TCP DPT=80", "src_ip": "32.127.145.200", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T19:38:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=410 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T19:43:05", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 139", "src_ip": "91.219.236.18", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T19:43:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=139.252.87.142 OUT= PROTO=TCP DPT=80", "src_ip": "139.252.87.142", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T19:43:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=654 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T19:48:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=345 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T19:50:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T19:50:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T19:50:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T19:50:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T19:50:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T19:50:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T19:50:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T19:50:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T19:50:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T19:50:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T19:50:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T19:51:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=151.90.21.247 OUT= PROTO=TCP DPT=443", "src_ip": "151.90.21.247", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T19:51:19", "source": "nginx", "category": "benign", "severity": "info", "message": "138.204.165.84 - - \"GET /health HTTP/1.1\" 200 6414", "src_ip": "138.204.165.84", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T19:52:56", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 500 190", "src_ip": "209.141.56.12", "status": 500, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T19:53:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=888 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T19:56:38", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.155 port 40341 ssh2", "src_ip": "10.0.2.155", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T19:58:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.110 port 51149 ssh2", "src_ip": "10.0.5.110", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T19:58:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=482 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T19:59:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=105.232.249.84 OUT= PROTO=TCP DPT=80", "src_ip": "105.232.249.84", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T19:59:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.167 dst=185.220.101.34 dport=443 bytes=618 interval=60s", "src_ip": "10.0.0.167", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-12T19:59:36", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.2 port 53733 ssh2", "src_ip": "10.0.5.2", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T20:00:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.167 dst=185.220.101.34 dport=443 bytes=790 interval=60s", "src_ip": "10.0.0.167", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-12T20:01:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=11.34.239.13 OUT= PROTO=TCP DPT=80", "src_ip": "11.34.239.13", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T20:01:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.167 dst=185.220.101.34 dport=443 bytes=434 interval=60s", "src_ip": "10.0.0.167", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-12T20:02:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.167 dst=185.220.101.34 dport=443 bytes=696 interval=60s", "src_ip": "10.0.0.167", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-12T20:02:28", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 164", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-12T20:03:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=66.78.74.234 OUT= PROTO=TCP DPT=443", "src_ip": "66.78.74.234", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T20:03:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=182.59.181.206 OUT= PROTO=TCP DPT=80", "src_ip": "182.59.181.206", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T20:03:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.167 dst=185.220.101.34 dport=443 bytes=551 interval=60s", "src_ip": "10.0.0.167", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-12T20:03:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=535 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T20:04:08", "source": "nginx", "category": "benign", "severity": "info", "message": "133.29.70.236 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7535", "src_ip": "133.29.70.236", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T20:04:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.167 dst=185.220.101.34 dport=443 bytes=518 interval=60s", "src_ip": "10.0.0.167", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-12T20:05:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.167 dst=185.220.101.34 dport=443 bytes=246 interval=60s", "src_ip": "10.0.0.167", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-12T20:06:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.167 dst=185.220.101.34 dport=443 bytes=338 interval=60s", "src_ip": "10.0.0.167", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-12T20:06:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55840 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:06:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 54648 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:06:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 43078 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:06:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 58993 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:06:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 52327 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:06:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 53998 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:06:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 59985 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:06:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55556 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:06:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 51464 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:08:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.33 dst=193.27.228.114 dport=443 bytes=211 interval=300s", "src_ip": "10.0.3.33", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-12T20:18:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T20:18:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T20:18:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T20:18:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T20:18:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T20:18:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T20:18:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T20:18:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T20:18:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T20:18:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T20:18:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T20:19:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.205 port 41909 ssh2", "src_ip": "10.0.3.205", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T20:20:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=102.142.87.42 OUT= PROTO=TCP DPT=443", "src_ip": "102.142.87.42", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T20:21:59", "source": "nginx", "category": "benign", "severity": "info", "message": "53.70.252.181 - - \"GET /api/products HTTP/1.1\" 200 4379", "src_ip": "53.70.252.181", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T20:23:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=172.173.216.247 OUT= PROTO=TCP DPT=443", "src_ip": "172.173.216.247", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T20:25:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T20:25:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T20:25:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T20:25:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T20:25:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T20:25:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T20:25:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T20:25:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T20:25:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T20:25:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T20:25:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T20:29:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 58863 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:29:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 59817 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:29:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 45508 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:29:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 55512 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:29:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 47596 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:29:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 42992 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:29:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 45400 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:29:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 44488 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 58354 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 40008 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 44800 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 42548 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 55456 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 49914 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 52363 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 54407 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 55547 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 50215 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 43843 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:30:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 50386 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T20:32:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 43429 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:32:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 50202 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:32:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 50111 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:32:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 47432 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:32:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 41684 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:32:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 46502 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 43355 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 41227 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 57555 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 47606 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 50574 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 43730 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 52895 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 53869 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 54627 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 59717 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 53970 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 54349 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 53500 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 58825 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 41751 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 40810 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 49914 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 48749 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:33:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 49565 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-12T20:46:25", "source": "nginx", "category": "benign", "severity": "info", "message": "163.203.203.176 - - \"GET /static/app.js HTTP/1.1\" 200 2211", "src_ip": "163.203.203.176", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T20:47:03", "source": "nginx", "category": "benign", "severity": "info", "message": "76.7.57.155 - - \"GET /login HTTP/1.1\" 200 7655", "src_ip": "76.7.57.155", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T20:52:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.105 port 56668 ssh2", "src_ip": "10.0.2.105", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-12T20:54:50", "source": "nginx", "category": "benign", "severity": "info", "message": "153.191.198.41 - - \"GET /health HTTP/1.1\" 200 1851", "src_ip": "153.191.198.41", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T20:56:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.59 dst=185.220.101.34 dport=443 bytes=327 interval=300s", "src_ip": "10.0.2.59", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T20:57:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.184 port 51944 ssh2", "src_ip": "10.0.5.184", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T21:00:59", "source": "nginx", "category": "benign", "severity": "info", "message": "202.159.60.153 - - \"GET /dashboard HTTP/1.1\" 200 6132", "src_ip": "202.159.60.153", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T21:01:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.59 dst=185.220.101.34 dport=443 bytes=770 interval=300s", "src_ip": "10.0.2.59", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T21:02:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55555 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 59312 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 54406 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 51626 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 56850 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 53355 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 50298 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 43516 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55266 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 53896 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 57030 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 56246 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 50751 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 58150 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55586 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:02:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 49446 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:03:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 43791 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:03:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 49293 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:03:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 59673 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:03:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 41330 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:03:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 49522 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:03:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 46186 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:03:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 50223 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:03:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 54547 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-12T21:05:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.107 port 53925 ssh2", "src_ip": "10.0.1.107", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-12T21:06:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.59 dst=185.220.101.34 dport=443 bytes=216 interval=300s", "src_ip": "10.0.2.59", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T21:08:38", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.18 port 46943 ssh2", "src_ip": "10.0.0.18", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-12T21:10:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 55143 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 59358 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 50746 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 56937 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 48740 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 52280 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 45969 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 44684 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 45304 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 58746 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 44758 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 41121 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 52616 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 41573 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 50568 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 55854 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:10:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 41117 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-12T21:11:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.59 dst=185.220.101.34 dport=443 bytes=845 interval=300s", "src_ip": "10.0.2.59", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T21:16:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.59 dst=185.220.101.34 dport=443 bytes=774 interval=300s", "src_ip": "10.0.2.59", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-12T21:22:19", "source": "nginx", "category": "benign", "severity": "info", "message": "112.207.80.222 - - \"GET /login HTTP/1.1\" 200 5091", "src_ip": "112.207.80.222", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T21:23:11", "source": "nginx", "category": "benign", "severity": "info", "message": "189.99.201.25 - - \"GET /login HTTP/1.1\" 200 2849", "src_ip": "189.99.201.25", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T21:26:26", "source": "nginx", "category": "benign", "severity": "info", "message": "154.246.36.86 - - \"GET /login HTTP/1.1\" 200 6056", "src_ip": "154.246.36.86", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T21:30:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.157 port 55447 ssh2", "src_ip": "10.0.3.157", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-12T21:33:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=41.212.1.226 OUT= PROTO=TCP DPT=80", "src_ip": "41.212.1.226", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T21:37:02", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/bin/bash", "user": "www-data", "host": "app-02", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-12T21:38:23", "source": "nginx", "category": "benign", "severity": "info", "message": "83.196.197.151 - - \"GET /static/app.js HTTP/1.1\" 200 6071", "src_ip": "83.196.197.151", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T21:40:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=151.104.210.119 OUT= PROTO=TCP DPT=80", "src_ip": "151.104.210.119", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T21:43:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=90.213.236.230 OUT= PROTO=TCP DPT=443", "src_ip": "90.213.236.230", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T21:46:22", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/bash", "user": "nattapong", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-12T21:48:57", "source": "nginx", "category": "benign", "severity": "info", "message": "182.124.215.13 - - \"GET /health HTTP/1.1\" 200 1134", "src_ip": "182.124.215.13", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T21:49:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=203.163.94.60 OUT= PROTO=TCP DPT=443", "src_ip": "203.163.94.60", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T21:54:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T21:54:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T21:54:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T21:54:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T21:54:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T21:54:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T21:54:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T21:54:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T21:54:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T22:01:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=77.99.43.134 OUT= PROTO=TCP DPT=80", "src_ip": "77.99.43.134", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T22:03:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=74.39.54.227 OUT= PROTO=TCP DPT=80", "src_ip": "74.39.54.227", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T22:04:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.213 port 51297 ssh2", "src_ip": "10.0.2.213", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T22:04:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.168 port 54268 ssh2", "src_ip": "10.0.3.168", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-12T22:06:00", "source": "nginx", "category": "benign", "severity": "info", "message": "176.235.119.136 - - \"GET /dashboard HTTP/1.1\" 200 7092", "src_ip": "176.235.119.136", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T22:06:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.228 dst=209.141.56.12 dport=443 bytes=690 interval=60s", "src_ip": "10.0.4.228", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-12T22:07:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.228 dst=209.141.56.12 dport=443 bytes=769 interval=60s", "src_ip": "10.0.4.228", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-12T22:08:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.228 dst=209.141.56.12 dport=443 bytes=638 interval=60s", "src_ip": "10.0.4.228", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-12T22:08:53", "source": "nginx", "category": "benign", "severity": "info", "message": "197.111.69.191 - - \"GET /login HTTP/1.1\" 200 878", "src_ip": "197.111.69.191", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T22:09:31", "source": "nginx", "category": "benign", "severity": "info", "message": "46.205.63.121 - - \"GET /api/products HTTP/1.1\" 200 5707", "src_ip": "46.205.63.121", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-12T22:09:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.228 dst=209.141.56.12 dport=443 bytes=726 interval=60s", "src_ip": "10.0.4.228", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-12T22:10:13", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 128", "src_ip": "91.219.236.18", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-12T22:10:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.228 dst=209.141.56.12 dport=443 bytes=890 interval=60s", "src_ip": "10.0.4.228", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-12T22:11:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.228 dst=209.141.56.12 dport=443 bytes=631 interval=60s", "src_ip": "10.0.4.228", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-12T22:12:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.228 dst=209.141.56.12 dport=443 bytes=329 interval=60s", "src_ip": "10.0.4.228", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-12T22:13:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T22:13:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T22:13:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T22:13:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T22:13:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T22:13:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T22:13:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T22:13:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T22:25:51", "source": "nginx", "category": "benign", "severity": "info", "message": "115.66.225.94 - - \"GET /static/app.js HTTP/1.1\" 200 7120", "src_ip": "115.66.225.94", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T22:29:11", "source": "nginx", "category": "benign", "severity": "info", "message": "32.64.39.218 - - \"GET /health HTTP/1.1\" 200 2476", "src_ip": "32.64.39.218", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T22:29:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.228 port 43683 ssh2", "src_ip": "10.0.5.228", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-12T22:33:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=52.131.120.104 OUT= PROTO=TCP DPT=80", "src_ip": "52.131.120.104", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T22:35:37", "source": "nginx", "category": "benign", "severity": "info", "message": "144.39.77.45 - - \"GET /health HTTP/1.1\" 200 6452", "src_ip": "144.39.77.45", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T22:35:56", "source": "nginx", "category": "benign", "severity": "info", "message": "146.250.202.141 - - \"GET /static/app.js HTTP/1.1\" 200 6149", "src_ip": "146.250.202.141", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-12T22:37:08", "source": "nginx", "category": "benign", "severity": "info", "message": "125.166.126.170 - - \"GET /dashboard HTTP/1.1\" 200 1148", "src_ip": "125.166.126.170", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-12T22:37:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T22:37:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T22:37:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T22:37:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T22:37:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T22:37:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T22:37:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T22:37:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T22:37:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T22:37:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T22:44:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.123 port 49748 ssh2", "src_ip": "10.0.5.123", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T22:44:22", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 378", "src_ip": "91.219.236.18", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-12T22:45:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T22:45:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T22:45:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T22:45:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T22:45:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T22:45:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T22:45:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T22:45:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T22:45:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T22:45:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T22:45:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T22:46:30", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=52.73.162.15 OUT= PROTO=TCP DPT=80", "src_ip": "52.73.162.15", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T23:00:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.114 port 49522 ssh2", "src_ip": "10.0.2.114", "user": "root", "action": "login_success"} {"timestamp": "2026-06-12T23:03:29", "source": "nginx", "category": "benign", "severity": "info", "message": "149.35.39.252 - - \"GET /login HTTP/1.1\" 200 7353", "src_ip": "149.35.39.252", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T23:06:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.105 port 49845 ssh2", "src_ip": "10.0.5.105", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T23:06:25", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.60 dst=209.141.56.12 bytes=3212836864 proto=TCP dport=443 duration=391s", "src_ip": "10.0.4.60", "dst_ip": "209.141.56.12", "bytes_mb": 3064, "off_hours": true} {"timestamp": "2026-06-12T23:07:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.38 port 41103 ssh2", "src_ip": "10.0.3.38", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-12T23:08:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=132.83.117.181 OUT= PROTO=TCP DPT=80", "src_ip": "132.83.117.181", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-12T23:12:02", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/su -", "user": "somchai", "host": "db-03", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-12T23:18:31", "source": "nginx", "category": "benign", "severity": "info", "message": "17.212.34.11 - - \"GET /login HTTP/1.1\" 200 5030", "src_ip": "17.212.34.11", "status": 200, "path": "/login"} {"timestamp": "2026-06-12T23:23:01", "source": "nginx", "category": "benign", "severity": "info", "message": "110.183.34.224 - - \"GET /health HTTP/1.1\" 200 1493", "src_ip": "110.183.34.224", "status": 200, "path": "/health"} {"timestamp": "2026-06-12T23:32:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T23:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T23:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T23:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T23:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T23:32:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T23:32:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T23:32:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T23:32:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-12T23:32:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T23:33:44", "source": "nginx", "category": "benign", "severity": "info", "message": "54.150.199.71 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7883", "src_ip": "54.150.199.71", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-12T23:34:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=99.67.91.129 OUT= PROTO=TCP DPT=443", "src_ip": "99.67.91.129", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T23:35:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T23:35:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-12T23:35:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T23:35:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T23:35:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-12T23:35:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T23:35:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-12T23:35:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T23:35:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T23:35:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T23:40:42", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/bash", "user": "somchai", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-12T23:43:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-12T23:43:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-12T23:43:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-12T23:43:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-12T23:43:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-12T23:43:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-12T23:43:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-12T23:43:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-12T23:44:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43860 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 56155 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 48427 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 47340 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 51737 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 53312 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 50429 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43656 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 57346 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:44:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 54281 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:45:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 53215 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-12T23:48:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=79.202.138.228 OUT= PROTO=TCP DPT=443", "src_ip": "79.202.138.228", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-12T23:51:06", "source": "nginx", "category": "benign", "severity": "info", "message": "168.228.100.53 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7387", "src_ip": "168.228.100.53", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T00:02:34", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 200 202", "src_ip": "185.220.101.34", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T00:11:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 49434 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 42280 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 57804 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 44381 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 42061 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 47157 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 46559 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 52358 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 44692 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 40232 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 49989 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:11:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 43034 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:12:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 40265 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T00:14:20", "source": "nginx", "category": "benign", "severity": "info", "message": "45.62.140.85 - - \"GET /static/app.js HTTP/1.1\" 200 3589", "src_ip": "45.62.140.85", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T00:15:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T00:15:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T00:15:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T00:15:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T00:15:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T00:15:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T00:15:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T00:15:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T00:15:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T00:18:44", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 200 414", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T00:20:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=169.185.98.181 OUT= PROTO=TCP DPT=80", "src_ip": "169.185.98.181", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T00:23:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.128 port 42313 ssh2", "src_ip": "10.0.2.128", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T00:26:47", "source": "nginx", "category": "benign", "severity": "info", "message": "65.1.201.56 - - \"GET /api/products HTTP/1.1\" 200 7811", "src_ip": "65.1.201.56", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T00:27:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 52293 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:27:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 57767 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:27:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 51514 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:27:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 52704 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:27:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 48401 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:27:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 53242 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:27:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 55314 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:28:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 49729 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:28:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 91.219.236.18 port 42200 ssh2", "src_ip": "91.219.236.18", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T00:33:23", "source": "nginx", "category": "benign", "severity": "info", "message": "81.229.146.141 - - \"GET /static/app.js HTTP/1.1\" 200 200", "src_ip": "81.229.146.141", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T00:35:01", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 231", "src_ip": "185.220.101.34", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T00:37:36", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.245 port 44361 ssh2", "src_ip": "10.0.5.245", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T00:37:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=724 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:38:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=506 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:39:08", "source": "nginx", "category": "benign", "severity": "info", "message": "40.131.128.178 - - \"GET /dashboard HTTP/1.1\" 200 3289", "src_ip": "40.131.128.178", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T00:39:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=760 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:40:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=521 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:41:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=766 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:42:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=847 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:43:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=422 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:44:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=43.117.69.170 OUT= PROTO=TCP DPT=80", "src_ip": "43.117.69.170", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T00:44:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=405 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:45:46", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.37 dst=91.219.236.18 dport=443 bytes=414 interval=60s", "src_ip": "10.0.1.37", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-13T00:50:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.157 port 49579 ssh2", "src_ip": "10.0.1.157", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-13T00:50:23", "source": "nginx", "category": "benign", "severity": "info", "message": "214.15.132.128 - - \"GET /api/products HTTP/1.1\" 200 4135", "src_ip": "214.15.132.128", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T00:50:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.3 port 43786 ssh2", "src_ip": "10.0.2.3", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T00:50:45", "source": "nginx", "category": "benign", "severity": "info", "message": "113.49.210.60 - - \"GET /health HTTP/1.1\" 200 5111", "src_ip": "113.49.210.60", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T00:54:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.121 dst=185.220.101.34 dport=443 bytes=431 interval=30s", "src_ip": "10.0.0.121", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T00:55:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.121 dst=185.220.101.34 dport=443 bytes=892 interval=30s", "src_ip": "10.0.0.121", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T00:55:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.121 dst=185.220.101.34 dport=443 bytes=890 interval=30s", "src_ip": "10.0.0.121", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T00:56:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.121 dst=185.220.101.34 dport=443 bytes=606 interval=30s", "src_ip": "10.0.0.121", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T00:56:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.121 dst=185.220.101.34 dport=443 bytes=770 interval=30s", "src_ip": "10.0.0.121", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T00:57:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.121 dst=185.220.101.34 dport=443 bytes=574 interval=30s", "src_ip": "10.0.0.121", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T00:57:51", "source": "nginx", "category": "benign", "severity": "info", "message": "212.48.84.83 - - \"GET /login HTTP/1.1\" 200 3445", "src_ip": "212.48.84.83", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T01:03:19", "source": "nginx", "category": "benign", "severity": "info", "message": "122.189.143.109 - - \"GET /health HTTP/1.1\" 200 3989", "src_ip": "122.189.143.109", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T01:06:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T01:06:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T01:06:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T01:06:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T01:06:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T01:06:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T01:06:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T01:06:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T01:06:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T01:06:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T01:09:23", "source": "nginx", "category": "benign", "severity": "info", "message": "145.167.15.170 - - \"GET /health HTTP/1.1\" 200 357", "src_ip": "145.167.15.170", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T01:13:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=57.57.72.184 OUT= PROTO=TCP DPT=443", "src_ip": "57.57.72.184", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T01:13:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=48.94.229.164 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "48.94.229.164", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T01:13:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=48.94.229.164 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "48.94.229.164", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T01:13:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=48.94.229.164 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "48.94.229.164", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T01:13:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=48.94.229.164 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "48.94.229.164", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T01:13:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=48.94.229.164 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "48.94.229.164", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T01:13:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=48.94.229.164 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "48.94.229.164", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T01:13:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=48.94.229.164 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "48.94.229.164", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T01:13:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=48.94.229.164 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "48.94.229.164", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T01:16:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.235 port 58253 ssh2", "src_ip": "10.0.1.235", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T01:17:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=60.164.42.243 OUT= PROTO=TCP DPT=80", "src_ip": "60.164.42.243", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T01:17:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.44 port 58054 ssh2", "src_ip": "10.0.0.44", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T01:20:00", "source": "nginx", "category": "benign", "severity": "info", "message": "203.138.106.202 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 863", "src_ip": "203.138.106.202", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T01:23:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.67 port 57171 ssh2", "src_ip": "10.0.3.67", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T01:23:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.125 port 54383 ssh2", "src_ip": "10.0.4.125", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T01:25:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.243 port 53733 ssh2", "src_ip": "10.0.2.243", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T01:29:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.71 dst=45.137.21.9 dport=443 bytes=767 interval=30s", "src_ip": "10.0.0.71", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-13T01:30:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.71 dst=45.137.21.9 dport=443 bytes=474 interval=30s", "src_ip": "10.0.0.71", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-13T01:30:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.71 dst=45.137.21.9 dport=443 bytes=663 interval=30s", "src_ip": "10.0.0.71", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-13T01:31:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.71 dst=45.137.21.9 dport=443 bytes=819 interval=30s", "src_ip": "10.0.0.71", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-13T01:31:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.71 dst=45.137.21.9 dport=443 bytes=318 interval=30s", "src_ip": "10.0.0.71", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-13T01:33:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=95.205.131.158 OUT= PROTO=TCP DPT=443", "src_ip": "95.205.131.158", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T01:34:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 43832 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:34:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 52232 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 58835 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 44632 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 55947 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 59543 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 52729 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 53862 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 46130 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 49464 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 57608 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 54778 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 45676 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 45467 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:35:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 41756 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T01:37:54", "source": "nginx", "category": "benign", "severity": "info", "message": "191.106.250.82 - - \"GET /dashboard HTTP/1.1\" 200 3057", "src_ip": "191.106.250.82", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T01:38:46", "source": "nginx", "category": "benign", "severity": "info", "message": "117.241.47.223 - - \"GET /api/products HTTP/1.1\" 200 6989", "src_ip": "117.241.47.223", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T01:42:01", "source": "nginx", "category": "benign", "severity": "info", "message": "112.94.165.165 - - \"GET /api/products HTTP/1.1\" 200 7067", "src_ip": "112.94.165.165", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T01:43:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.140 dst=91.219.236.18 dport=443 bytes=542 interval=30s", "src_ip": "10.0.1.140", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-13T01:43:39", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.140 dst=91.219.236.18 dport=443 bytes=254 interval=30s", "src_ip": "10.0.1.140", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-13T01:44:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.140 dst=91.219.236.18 dport=443 bytes=656 interval=30s", "src_ip": "10.0.1.140", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-13T01:44:39", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.140 dst=91.219.236.18 dport=443 bytes=654 interval=30s", "src_ip": "10.0.1.140", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-13T01:45:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.140 dst=91.219.236.18 dport=443 bytes=483 interval=30s", "src_ip": "10.0.1.140", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-13T01:45:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 50691 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 55729 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 51077 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 52366 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 40851 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 42670 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 44932 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 42843 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 47132 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 51310 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:39", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.140 dst=91.219.236.18 dport=443 bytes=251 interval=30s", "src_ip": "10.0.1.140", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-13T01:45:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 41542 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 47226 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 55923 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 56817 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 48013 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 50827 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:45:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 59755 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:46:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 43275 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:46:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 56152 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:46:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 59100 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:46:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 55800 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:46:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.140 dst=91.219.236.18 dport=443 bytes=602 interval=30s", "src_ip": "10.0.1.140", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-13T01:46:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 58946 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T01:47:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.57 port 44414 ssh2", "src_ip": "10.0.3.57", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T01:50:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.54 port 41018 ssh2", "src_ip": "10.0.0.54", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T01:58:45", "source": "nginx", "category": "benign", "severity": "info", "message": "170.169.205.97 - - \"GET /login HTTP/1.1\" 200 3097", "src_ip": "170.169.205.97", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T01:59:20", "source": "nginx", "category": "benign", "severity": "info", "message": "220.89.15.244 - - \"GET /dashboard HTTP/1.1\" 200 7200", "src_ip": "220.89.15.244", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T01:59:35", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 271", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T02:07:14", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/bin/bash", "user": "postgres", "host": "app-02", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-13T02:07:16", "source": "nginx", "category": "benign", "severity": "info", "message": "105.194.34.195 - - \"GET /dashboard HTTP/1.1\" 200 7108", "src_ip": "105.194.34.195", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T02:08:07", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 200 496", "src_ip": "209.141.56.12", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T02:12:02", "source": "nginx", "category": "web_attack", "severity": "high", "message": "128.189.202.14 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 430", "src_ip": "128.189.202.14", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T02:13:15", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.65 dst=185.220.101.34 bytes=3454009344 proto=TCP dport=443 duration=341s", "src_ip": "10.0.4.65", "dst_ip": "185.220.101.34", "bytes_mb": 3294, "off_hours": true} {"timestamp": "2026-06-13T02:14:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.63 dst=209.141.56.12 dport=443 bytes=878 interval=30s", "src_ip": "10.0.2.63", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T02:15:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.63 dst=209.141.56.12 dport=443 bytes=671 interval=30s", "src_ip": "10.0.2.63", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T02:15:16", "source": "nginx", "category": "benign", "severity": "info", "message": "211.39.184.65 - - \"GET /login HTTP/1.1\" 200 6105", "src_ip": "211.39.184.65", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T02:15:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.63 dst=209.141.56.12 dport=443 bytes=684 interval=30s", "src_ip": "10.0.2.63", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T02:16:05", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.63 dst=209.141.56.12 dport=443 bytes=573 interval=30s", "src_ip": "10.0.2.63", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T02:16:31", "source": "nginx", "category": "benign", "severity": "info", "message": "38.122.2.206 - - \"GET /static/app.js HTTP/1.1\" 200 4026", "src_ip": "38.122.2.206", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T02:16:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.63 dst=209.141.56.12 dport=443 bytes=737 interval=30s", "src_ip": "10.0.2.63", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T02:17:41", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/bin/su -", "user": "svc_backup", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-13T02:19:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T02:19:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T02:19:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T02:19:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T02:19:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T02:19:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T02:19:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T02:19:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T02:19:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T02:19:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=22.197.179.181 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "22.197.179.181", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T02:19:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.183 port 58211 ssh2", "src_ip": "10.0.2.183", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T02:19:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=12.36.170.223 OUT= PROTO=TCP DPT=80", "src_ip": "12.36.170.223", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T02:21:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.97 port 42260 ssh2", "src_ip": "10.0.5.97", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T02:21:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=153.12.68.70 OUT= PROTO=TCP DPT=443", "src_ip": "153.12.68.70", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T02:25:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 44170 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 53777 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 52423 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 54086 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 45702 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 53306 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 58648 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 49401 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 40013 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 54476 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 47002 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 59879 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 50559 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 56890 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 55505 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 45560 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:25:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=104.146.38.144 OUT= PROTO=TCP DPT=80", "src_ip": "104.146.38.144", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T02:25:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 90.209.167.104 port 42778 ssh2", "src_ip": "90.209.167.104", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T02:26:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.77 port 58629 ssh2", "src_ip": "10.0.3.77", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T02:28:21", "source": "nginx", "category": "benign", "severity": "info", "message": "26.89.218.143 - - \"GET /dashboard HTTP/1.1\" 200 584", "src_ip": "26.89.218.143", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T02:29:38", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.212 port 58764 ssh2", "src_ip": "10.0.3.212", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T02:29:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=189.101.71.34 OUT= PROTO=TCP DPT=443", "src_ip": "189.101.71.34", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T02:31:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.2.16 port 47887 ssh2", "src_ip": "10.0.2.16", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-13T02:31:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.5.166 port 52769 ssh2", "src_ip": "10.0.5.166", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T02:33:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=144.167.253.129 OUT= PROTO=TCP DPT=80", "src_ip": "144.167.253.129", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T02:46:17", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.254.186.190 OUT= PROTO=TCP DPT=443", "src_ip": "164.254.186.190", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T02:46:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T02:46:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T02:46:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T02:46:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T02:46:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T02:46:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T02:46:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T02:46:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T02:46:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=32.18.171.100 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "32.18.171.100", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T02:48:25", "source": "nginx", "category": "web_attack", "severity": "high", "message": "63.96.200.76 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 197", "src_ip": "63.96.200.76", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T02:51:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.56 port 50318 ssh2", "src_ip": "10.0.1.56", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-13T02:52:11", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/bash", "user": "nattapong", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-13T02:53:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.228 dst=185.220.101.34 dport=443 bytes=706 interval=60s", "src_ip": "10.0.3.228", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-13T02:54:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.228 dst=185.220.101.34 dport=443 bytes=634 interval=60s", "src_ip": "10.0.3.228", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-13T02:55:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.228 dst=185.220.101.34 dport=443 bytes=409 interval=60s", "src_ip": "10.0.3.228", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-13T02:56:11", "source": "nginx", "category": "benign", "severity": "info", "message": "73.207.152.117 - - \"GET / HTTP/1.1\" 200 5841", "src_ip": "73.207.152.117", "status": 200, "path": "/"} {"timestamp": "2026-06-13T02:56:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.228 dst=185.220.101.34 dport=443 bytes=423 interval=60s", "src_ip": "10.0.3.228", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-13T02:57:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.228 dst=185.220.101.34 dport=443 bytes=200 interval=60s", "src_ip": "10.0.3.228", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-13T02:57:52", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/bash", "user": "guest", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-13T02:58:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.228 dst=185.220.101.34 dport=443 bytes=503 interval=60s", "src_ip": "10.0.3.228", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-13T02:58:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.195.157.188 OUT= PROTO=TCP DPT=443", "src_ip": "147.195.157.188", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T02:59:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.72 port 41491 ssh2", "src_ip": "10.0.1.72", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T03:00:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.209 port 42031 ssh2", "src_ip": "10.0.2.209", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T03:00:42", "source": "nginx", "category": "benign", "severity": "info", "message": "167.86.159.100 - - \"GET /static/app.js HTTP/1.1\" 200 3852", "src_ip": "167.86.159.100", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T03:01:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.97 port 44170 ssh2", "src_ip": "10.0.4.97", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-13T03:03:03", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.6 dst=209.141.56.12 bytes=1494220800 proto=TCP dport=443 duration=349s", "src_ip": "10.0.5.6", "dst_ip": "209.141.56.12", "bytes_mb": 1425, "off_hours": true} {"timestamp": "2026-06-13T03:03:55", "source": "nginx", "category": "benign", "severity": "info", "message": "28.241.151.2 - - \"GET /login HTTP/1.1\" 200 6767", "src_ip": "28.241.151.2", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T03:05:32", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 200 227", "src_ip": "185.220.101.34", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T03:07:06", "source": "nginx", "category": "benign", "severity": "info", "message": "210.149.125.135 - - \"GET /api/products HTTP/1.1\" 200 2812", "src_ip": "210.149.125.135", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T03:08:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.47.86.152 OUT= PROTO=TCP DPT=80", "src_ip": "147.47.86.152", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T03:11:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=126.226.46.152 OUT= PROTO=TCP DPT=80", "src_ip": "126.226.46.152", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T03:11:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=145.21.141.208 OUT= PROTO=TCP DPT=80", "src_ip": "145.21.141.208", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T03:15:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=67.119.252.248 OUT= PROTO=TCP DPT=443", "src_ip": "67.119.252.248", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T03:15:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=142.124.25.96 OUT= PROTO=TCP DPT=443", "src_ip": "142.124.25.96", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T03:16:03", "source": "nginx", "category": "benign", "severity": "info", "message": "145.171.33.239 - - \"GET /static/app.js HTTP/1.1\" 200 6394", "src_ip": "145.171.33.239", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T03:18:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.222 port 55741 ssh2", "src_ip": "10.0.1.222", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T03:22:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.210 port 44466 ssh2", "src_ip": "10.0.4.210", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T03:22:03", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "deploy", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-13T03:22:49", "source": "nginx", "category": "web_attack", "severity": "high", "message": "105.74.156.86 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 157", "src_ip": "105.74.156.86", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T03:24:39", "source": "nginx", "category": "benign", "severity": "info", "message": "63.250.135.160 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5333", "src_ip": "63.250.135.160", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T03:28:19", "source": "nginx", "category": "benign", "severity": "info", "message": "77.186.215.156 - - \"GET /dashboard HTTP/1.1\" 200 1361", "src_ip": "77.186.215.156", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T03:40:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T03:40:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T03:40:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T03:40:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T03:40:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T03:40:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T03:40:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T03:40:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T03:40:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T03:40:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T03:40:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T03:40:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=156.208.228.22 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "156.208.228.22", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T03:40:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T03:40:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T03:40:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T03:40:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T03:40:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T03:40:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T03:40:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T03:40:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T03:40:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T03:40:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T03:40:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T03:40:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=35.226.175.164 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "35.226.175.164", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T03:43:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.212 port 54490 ssh2", "src_ip": "10.0.4.212", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T03:44:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.193 port 59125 ssh2", "src_ip": "10.0.4.193", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T03:49:50", "source": "nginx", "category": "benign", "severity": "info", "message": "66.93.250.1 - - \"GET / HTTP/1.1\" 200 4685", "src_ip": "66.93.250.1", "status": 200, "path": "/"} {"timestamp": "2026-06-13T03:52:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=19.83.25.143 OUT= PROTO=TCP DPT=80", "src_ip": "19.83.25.143", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T03:55:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=190.119.219.168 OUT= PROTO=TCP DPT=80", "src_ip": "190.119.219.168", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T04:01:54", "source": "nginx", "category": "benign", "severity": "info", "message": "212.237.69.162 - - \"GET /api/products HTTP/1.1\" 200 7692", "src_ip": "212.237.69.162", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T04:03:40", "source": "nginx", "category": "benign", "severity": "info", "message": "109.111.171.64 - - \"GET / HTTP/1.1\" 200 6838", "src_ip": "109.111.171.64", "status": 200, "path": "/"} {"timestamp": "2026-06-13T04:06:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.78 port 49529 ssh2", "src_ip": "10.0.0.78", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T04:11:39", "source": "nginx", "category": "benign", "severity": "info", "message": "125.217.47.131 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6459", "src_ip": "125.217.47.131", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T04:13:07", "source": "nginx", "category": "benign", "severity": "info", "message": "165.218.85.177 - - \"GET /dashboard HTTP/1.1\" 200 3079", "src_ip": "165.218.85.177", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T04:15:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=99.203.70.219 OUT= PROTO=TCP DPT=80", "src_ip": "99.203.70.219", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T04:20:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.1.122 port 43560 ssh2", "src_ip": "10.0.1.122", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T04:26:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=118.193.78.243 OUT= PROTO=TCP DPT=80", "src_ip": "118.193.78.243", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T04:27:22", "source": "nginx", "category": "benign", "severity": "info", "message": "13.230.225.137 - - \"GET / HTTP/1.1\" 200 5702", "src_ip": "13.230.225.137", "status": 200, "path": "/"} {"timestamp": "2026-06-13T04:28:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T04:28:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T04:28:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T04:28:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T04:28:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T04:28:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T04:28:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T04:28:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T04:28:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T04:28:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T04:31:44", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.161 dst=45.137.21.9 bytes=8334082048 proto=TCP dport=443 duration=383s", "src_ip": "10.0.2.161", "dst_ip": "45.137.21.9", "bytes_mb": 7948, "off_hours": true} {"timestamp": "2026-06-13T04:32:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.118 port 43523 ssh2", "src_ip": "10.0.2.118", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T04:33:19", "source": "nginx", "category": "benign", "severity": "info", "message": "208.136.39.197 - - \"GET /dashboard HTTP/1.1\" 200 1578", "src_ip": "208.136.39.197", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T04:40:28", "source": "nginx", "category": "benign", "severity": "info", "message": "117.62.250.186 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3993", "src_ip": "117.62.250.186", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T04:44:04", "source": "nginx", "category": "benign", "severity": "info", "message": "103.138.52.34 - - \"GET / HTTP/1.1\" 200 1735", "src_ip": "103.138.52.34", "status": 200, "path": "/"} {"timestamp": "2026-06-13T04:44:19", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 231", "src_ip": "91.219.236.18", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T04:45:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.58 port 53923 ssh2", "src_ip": "10.0.2.58", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T04:49:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.247 port 53046 ssh2", "src_ip": "10.0.2.247", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T04:56:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 44648 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 57382 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 41004 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 52327 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 54865 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 41723 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 45157 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 45158 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 50211 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:56:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 50629 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 59537 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 54519 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 59892 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 53571 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 41630 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 47063 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 42673 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 54087 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:16", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T04:57:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 53894 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:57:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 43729 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T04:58:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.161 port 44673 ssh2", "src_ip": "10.0.4.161", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T04:58:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.165 port 41060 ssh2", "src_ip": "10.0.1.165", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T05:05:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=18.52.119.26 OUT= PROTO=TCP DPT=80", "src_ip": "18.52.119.26", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T05:05:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T05:05:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T05:05:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T05:05:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T05:05:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T05:05:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T05:05:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T05:05:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T05:05:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T05:05:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T05:06:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 40922 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 58285 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 44948 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 45814 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 58819 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52772 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 46079 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 46707 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 53736 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:06:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 43535 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 42560 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 46305 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49782 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52500 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 41646 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 40458 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 57896 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 47011 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 44962 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52536 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 40393 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 41691 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 54701 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 54143 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:07:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 45565 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 50980 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 41657 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 59665 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 48601 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 47944 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 47540 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 57491 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 44492 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 53916 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 47229 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 54532 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:09:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 52907 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:10:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 40810 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:10:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 42698 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:10:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 54060 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:10:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 22.88.118.86 port 42188 ssh2", "src_ip": "22.88.118.86", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 51729 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 43973 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 45691 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 54163 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40571 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42439 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53421 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44307 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 50352 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 43942 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40303 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 55014 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 50302 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53451 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57578 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42397 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 51949 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:15:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41361 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:16:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 54174 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:16:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 45041 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:16:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=165.67.183.171 OUT= PROTO=TCP DPT=80", "src_ip": "165.67.183.171", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T05:16:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58427 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:16:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 52629 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:16:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 51747 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T05:21:11", "source": "nginx", "category": "benign", "severity": "info", "message": "35.188.129.129 - - \"GET / HTTP/1.1\" 200 5170", "src_ip": "35.188.129.129", "status": 200, "path": "/"} {"timestamp": "2026-06-13T05:25:01", "source": "nginx", "category": "benign", "severity": "info", "message": "47.42.48.144 - - \"GET /login HTTP/1.1\" 200 1901", "src_ip": "47.42.48.144", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T05:26:33", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 318", "src_ip": "185.220.101.34", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T05:27:43", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.184 dst=185.220.101.34 bytes=3357540352 proto=TCP dport=443 duration=206s", "src_ip": "10.0.0.184", "dst_ip": "185.220.101.34", "bytes_mb": 3202, "off_hours": true} {"timestamp": "2026-06-13T05:31:27", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "guest", "host": "web-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-13T05:31:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.26 dst=45.137.21.9 dport=443 bytes=372 interval=300s", "src_ip": "10.0.5.26", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T05:35:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=48.104.83.193 OUT= PROTO=TCP DPT=443", "src_ip": "48.104.83.193", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T05:36:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.26 dst=45.137.21.9 dport=443 bytes=688 interval=300s", "src_ip": "10.0.5.26", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T05:41:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.26 dst=45.137.21.9 dport=443 bytes=366 interval=300s", "src_ip": "10.0.5.26", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T05:41:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.9 port 48022 ssh2", "src_ip": "10.0.0.9", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T05:43:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T05:43:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T05:43:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T05:43:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T05:43:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T05:43:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T05:43:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T05:43:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T05:43:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T05:43:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T05:43:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T05:46:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.26 dst=45.137.21.9 dport=443 bytes=201 interval=300s", "src_ip": "10.0.5.26", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T05:51:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.26 dst=45.137.21.9 dport=443 bytes=255 interval=300s", "src_ip": "10.0.5.26", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T05:56:41", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.26 dst=45.137.21.9 dport=443 bytes=381 interval=300s", "src_ip": "10.0.5.26", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T05:57:00", "source": "nginx", "category": "benign", "severity": "info", "message": "220.101.40.250 - - \"GET /health HTTP/1.1\" 200 6462", "src_ip": "220.101.40.250", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T05:57:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=130.29.177.2 OUT= PROTO=TCP DPT=443", "src_ip": "130.29.177.2", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T05:58:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.250 port 44495 ssh2", "src_ip": "10.0.0.250", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T06:00:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.252 port 56461 ssh2", "src_ip": "10.0.0.252", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T06:00:44", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.5 dst=209.141.56.12 bytes=6912212992 proto=TCP dport=443 duration=317s", "src_ip": "10.0.0.5", "dst_ip": "209.141.56.12", "bytes_mb": 6592, "off_hours": false} {"timestamp": "2026-06-13T06:04:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=496 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:08:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T06:08:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T06:08:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T06:08:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T06:08:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T06:08:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T06:08:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T06:08:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T06:08:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T06:08:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T06:08:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T06:09:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=499 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:11:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=186.183.239.91 OUT= PROTO=TCP DPT=443", "src_ip": "186.183.239.91", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T06:12:38", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.163 port 46061 ssh2", "src_ip": "10.0.4.163", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T06:13:03", "source": "nginx", "category": "benign", "severity": "info", "message": "192.232.78.218 - - \"GET /static/app.js HTTP/1.1\" 200 1065", "src_ip": "192.232.78.218", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T06:13:28", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 489", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T06:14:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=467 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:15:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T06:15:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T06:15:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T06:15:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T06:15:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T06:15:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T06:15:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T06:15:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T06:16:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=182.169.60.73 OUT= PROTO=TCP DPT=443", "src_ip": "182.169.60.73", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T06:16:47", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.73 port 52297 ssh2", "src_ip": "10.0.1.73", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T06:18:04", "source": "nginx", "category": "benign", "severity": "info", "message": "32.211.230.68 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 549", "src_ip": "32.211.230.68", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T06:19:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=363 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:19:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=102.30.5.41 OUT= PROTO=TCP DPT=443", "src_ip": "102.30.5.41", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T06:23:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.210 port 54161 ssh2", "src_ip": "10.0.3.210", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T06:24:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=287 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:28:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.149 port 58514 ssh2", "src_ip": "10.0.5.149", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T06:29:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=758 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:31:34", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 500 405", "src_ip": "193.27.228.114", "status": 500, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T06:32:31", "source": "nginx", "category": "benign", "severity": "info", "message": "196.182.66.180 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 997", "src_ip": "196.182.66.180", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T06:34:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=351 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:39:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=814 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:40:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48597 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 58383 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 42547 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 53340 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 42005 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 53179 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 53155 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 58935 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 54509 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 46748 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 56677 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 47647 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 46280 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 40485 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 43932 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 59049 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 50579 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 42624 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 42963 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:40:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 58567 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:41:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 45234 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:41:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 45043 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T06:43:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=42.202.113.207 OUT= PROTO=TCP DPT=80", "src_ip": "42.202.113.207", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T06:44:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=884 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:44:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=68.230.135.77 OUT= PROTO=TCP DPT=80", "src_ip": "68.230.135.77", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T06:45:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 41836 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 45670 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 59061 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 40951 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 48875 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 45591 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 44163 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 48464 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 54883 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 44338 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 42231 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 44319 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 49699 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 41707 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 41916 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 40536 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 53552 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 57906 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:45:39", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-13T06:45:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 202.29.88.72 port 45342 ssh2", "src_ip": "202.29.88.72", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T06:49:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.31 dst=91.219.236.18 dport=443 bytes=790 interval=300s", "src_ip": "10.0.5.31", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-13T06:52:09", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 403 182", "src_ip": "45.137.21.9", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T06:58:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=27.160.92.32 OUT= PROTO=TCP DPT=443", "src_ip": "27.160.92.32", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T07:02:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.154.138.176 OUT= PROTO=TCP DPT=443", "src_ip": "215.154.138.176", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T07:03:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.1.87 port 42680 ssh2", "src_ip": "10.0.1.87", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T07:06:04", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 427", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T07:07:45", "source": "nginx", "category": "benign", "severity": "info", "message": "145.181.66.158 - - \"GET /static/app.js HTTP/1.1\" 200 4266", "src_ip": "145.181.66.158", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T07:08:12", "source": "nginx", "category": "benign", "severity": "info", "message": "157.199.165.147 - - \"GET / HTTP/1.1\" 200 6821", "src_ip": "157.199.165.147", "status": 200, "path": "/"} {"timestamp": "2026-06-13T07:08:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=45.137.21.9 dport=443 bytes=711 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-13T07:08:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=221.99.22.80 OUT= PROTO=TCP DPT=80", "src_ip": "221.99.22.80", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T07:08:31", "source": "nginx", "category": "benign", "severity": "info", "message": "70.137.94.116 - - \"GET /dashboard HTTP/1.1\" 200 4084", "src_ip": "70.137.94.116", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T07:09:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=45.137.21.9 dport=443 bytes=524 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-13T07:10:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=45.137.21.9 dport=443 bytes=316 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-13T07:11:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=45.137.21.9 dport=443 bytes=890 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-13T07:12:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=45.137.21.9 dport=443 bytes=616 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-13T07:13:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.231 dst=45.137.21.9 dport=443 bytes=469 interval=60s", "src_ip": "10.0.1.231", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-13T07:14:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.33.211.217 OUT= PROTO=TCP DPT=443", "src_ip": "167.33.211.217", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T07:22:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T07:22:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T07:22:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T07:22:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T07:22:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T07:22:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T07:22:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T07:22:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T07:22:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T07:22:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T07:29:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=553 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T07:31:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=67.94.34.202 OUT= PROTO=TCP DPT=80", "src_ip": "67.94.34.202", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T07:34:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=148.54.69.83 OUT= PROTO=TCP DPT=443", "src_ip": "148.54.69.83", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T07:34:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=585 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T07:36:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=108.207.195.112 OUT= PROTO=TCP DPT=80", "src_ip": "108.207.195.112", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T07:39:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=66.229.141.103 OUT= PROTO=TCP DPT=443", "src_ip": "66.229.141.103", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T07:39:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=324 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T07:43:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.191 port 49805 ssh2", "src_ip": "10.0.4.191", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T07:44:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=394 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T07:46:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 46158 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 44310 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 40858 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 40854 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 48744 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 56460 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 58580 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 52696 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 47566 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 45366 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 42604 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 47608 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 55617 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 55527 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:43", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for www-data from 116.155.226.191 port 51234 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T07:46:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 55360 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:46:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 116.155.226.191 port 52253 ssh2", "src_ip": "116.155.226.191", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T07:49:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T07:49:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T07:49:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T07:49:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T07:49:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T07:49:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T07:49:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T07:49:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T07:49:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T07:49:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T07:49:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T07:49:35", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/bash", "user": "guest", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-13T07:49:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=423 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T07:50:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=40.177.203.181 OUT= PROTO=TCP DPT=80", "src_ip": "40.177.203.181", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T07:54:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=658 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T07:57:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=99.204.66.195 OUT= PROTO=TCP DPT=443", "src_ip": "99.204.66.195", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T07:57:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T07:57:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T07:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T07:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T07:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T07:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T07:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T07:57:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T07:57:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T07:57:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T07:57:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T07:57:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T07:59:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=276 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T08:00:17", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=40.224.50.171 OUT= PROTO=TCP DPT=443", "src_ip": "40.224.50.171", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T08:01:02", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 141", "src_ip": "193.27.228.114", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T08:02:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T08:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T08:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T08:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T08:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T08:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T08:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T08:02:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T08:02:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T08:03:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 49725 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 44760 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 57301 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 41050 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 48893 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 52974 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 41131 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 57312 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 50843 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 50356 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 41635 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 48685 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 49320 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 42255 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 43616 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 49987 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:03:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 40804 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:04:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 42123 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:04:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 51961 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:04:07", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for admin from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T08:04:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 56528 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:04:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 47253 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:04:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 45.137.21.9 port 48120 ssh2", "src_ip": "45.137.21.9", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T08:04:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=883 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T08:07:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T08:07:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T08:07:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T08:07:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T08:07:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T08:07:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T08:07:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T08:07:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T08:07:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=204.179.57.220 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "204.179.57.220", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T08:09:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.128 dst=193.27.228.114 dport=443 bytes=758 interval=300s", "src_ip": "10.0.3.128", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-13T08:11:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.207 port 56185 ssh2", "src_ip": "10.0.0.207", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T08:15:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=65.51.89.197 OUT= PROTO=TCP DPT=80", "src_ip": "65.51.89.197", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T08:16:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T08:16:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T08:16:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T08:16:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T08:16:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T08:16:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T08:16:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T08:16:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T08:16:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T08:16:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T08:20:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.254 port 57080 ssh2", "src_ip": "10.0.1.254", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-13T08:21:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.204 dst=185.220.101.34 dport=443 bytes=817 interval=30s", "src_ip": "10.0.5.204", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T08:21:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.204 dst=185.220.101.34 dport=443 bytes=706 interval=30s", "src_ip": "10.0.5.204", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T08:22:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.204 dst=185.220.101.34 dport=443 bytes=216 interval=30s", "src_ip": "10.0.5.204", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T08:22:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.204 dst=185.220.101.34 dport=443 bytes=836 interval=30s", "src_ip": "10.0.5.204", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T08:23:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.204 dst=185.220.101.34 dport=443 bytes=804 interval=30s", "src_ip": "10.0.5.204", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T08:23:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.204 dst=185.220.101.34 dport=443 bytes=627 interval=30s", "src_ip": "10.0.5.204", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T08:24:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.204 dst=185.220.101.34 dport=443 bytes=373 interval=30s", "src_ip": "10.0.5.204", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T08:28:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.178 port 51209 ssh2", "src_ip": "10.0.2.178", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T08:33:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.200 port 45806 ssh2", "src_ip": "10.0.3.200", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T08:34:08", "source": "nginx", "category": "benign", "severity": "info", "message": "178.190.138.181 - - \"GET /dashboard HTTP/1.1\" 200 4526", "src_ip": "178.190.138.181", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T08:41:19", "source": "nginx", "category": "benign", "severity": "info", "message": "53.141.172.8 - - \"GET / HTTP/1.1\" 200 6470", "src_ip": "53.141.172.8", "status": 200, "path": "/"} {"timestamp": "2026-06-13T08:41:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=109.214.127.71 OUT= PROTO=TCP DPT=443", "src_ip": "109.214.127.71", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T08:46:50", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 200 222", "src_ip": "45.137.21.9", "status": 200, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T08:49:41", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 295", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T08:54:12", "source": "nginx", "category": "benign", "severity": "info", "message": "66.21.77.152 - - \"GET /api/products HTTP/1.1\" 200 2787", "src_ip": "66.21.77.152", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T08:55:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=24.154.251.203 OUT= PROTO=TCP DPT=443", "src_ip": "24.154.251.203", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T08:55:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T08:55:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T08:55:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T08:55:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T08:55:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T08:55:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T08:55:58", "source": "nginx", "category": "benign", "severity": "info", "message": "213.95.183.63 - - \"GET / HTTP/1.1\" 200 1962", "src_ip": "213.95.183.63", "status": 200, "path": "/"} {"timestamp": "2026-06-13T08:55:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T08:56:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T08:56:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T08:56:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T08:56:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T09:02:17", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=117.212.246.202 OUT= PROTO=TCP DPT=443", "src_ip": "117.212.246.202", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T09:02:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.92 port 50463 ssh2", "src_ip": "10.0.3.92", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-13T09:04:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.245 port 59735 ssh2", "src_ip": "10.0.4.245", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T09:05:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=112.108.196.182 OUT= PROTO=TCP DPT=443", "src_ip": "112.108.196.182", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T09:07:18", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.139 dst=193.27.228.114 bytes=8016363520 proto=TCP dport=443 duration=366s", "src_ip": "10.0.2.139", "dst_ip": "193.27.228.114", "bytes_mb": 7645, "off_hours": false} {"timestamp": "2026-06-13T09:11:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 45379 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 53624 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 55954 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 44598 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 56802 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 44855 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 42376 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 51820 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 52962 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 46627 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 54315 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 43310 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 49888 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 44471 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 58414 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 56231 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:11:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 41259 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 59298 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 52398 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 45823 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 45915 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 45966 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 55964 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 50396 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 56258 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 50851 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 51238 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 49650 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 52223 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 51692 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 58595 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 40058 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 58770 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:38", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for root from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T09:12:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 50427 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 47238 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 58531 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:12:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 45.137.21.9 port 42549 ssh2", "src_ip": "45.137.21.9", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T09:19:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=87.37.3.45 OUT= PROTO=TCP DPT=443", "src_ip": "87.37.3.45", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T09:22:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.172 port 49975 ssh2", "src_ip": "10.0.3.172", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T09:28:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 57746 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:28:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 40121 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:28:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 46597 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 57793 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 54574 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 58806 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 53670 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 43910 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 52589 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 43242 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 44338 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 50572 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 50441 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:29:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 54733 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T09:30:27", "source": "nginx", "category": "benign", "severity": "info", "message": "116.220.165.156 - - \"GET /login HTTP/1.1\" 200 4813", "src_ip": "116.220.165.156", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T09:33:46", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 309", "src_ip": "209.141.56.12", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T09:34:30", "source": "nginx", "category": "benign", "severity": "info", "message": "77.26.145.46 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2236", "src_ip": "77.26.145.46", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T09:44:07", "source": "nginx", "category": "benign", "severity": "info", "message": "167.132.95.141 - - \"GET /api/products HTTP/1.1\" 200 2142", "src_ip": "167.132.95.141", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T09:45:40", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 403 219", "src_ip": "91.219.236.18", "status": 403, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T09:47:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 58760 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 59255 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 40784 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 46101 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 53871 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 52181 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 51849 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 46773 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 41103 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 40166 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 59891 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 40698 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 51738 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 51215 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 40961 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 51574 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 41772 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 46417 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:47:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 41237 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:48:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 51554 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:48:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 40105 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:48:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 53179 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:48:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 59570 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:48:12", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T09:48:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 45411 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:48:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.60 port 43213 ssh2", "src_ip": "10.0.2.60", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T09:48:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 59436 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T09:56:29", "source": "nginx", "category": "benign", "severity": "info", "message": "196.134.107.164 - - \"GET /health HTTP/1.1\" 200 2706", "src_ip": "196.134.107.164", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T09:57:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=70.160.243.202 OUT= PROTO=TCP DPT=443", "src_ip": "70.160.243.202", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T10:05:01", "source": "nginx", "category": "benign", "severity": "info", "message": "211.47.141.79 - - \"GET /dashboard HTTP/1.1\" 200 7949", "src_ip": "211.47.141.79", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T10:16:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=114.28.2.43 OUT= PROTO=TCP DPT=80", "src_ip": "114.28.2.43", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T10:19:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=195.160.97.196 OUT= PROTO=TCP DPT=80", "src_ip": "195.160.97.196", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T10:22:56", "source": "nginx", "category": "benign", "severity": "info", "message": "135.2.118.154 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2144", "src_ip": "135.2.118.154", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T10:24:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.188 port 45685 ssh2", "src_ip": "10.0.1.188", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T10:27:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=51.44.201.174 OUT= PROTO=TCP DPT=443", "src_ip": "51.44.201.174", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T10:27:14", "source": "nginx", "category": "benign", "severity": "info", "message": "141.211.115.250 - - \"GET /login HTTP/1.1\" 200 2971", "src_ip": "141.211.115.250", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T10:34:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 49639 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 58166 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 59175 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 48365 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 43772 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 47776 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 50660 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 40997 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 53343 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 58746 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 40876 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 53532 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 49518 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 51544 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 50899 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:33", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 78.232.198.27 port 51234 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T10:35:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 51832 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 46892 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:35:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 78.232.198.27 port 56737 ssh2", "src_ip": "78.232.198.27", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T10:40:53", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "nattapong", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-13T10:44:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.205 port 50536 ssh2", "src_ip": "10.0.4.205", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T10:52:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=33.185.170.200 OUT= PROTO=TCP DPT=443", "src_ip": "33.185.170.200", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T10:54:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.23.198.121 OUT= PROTO=TCP DPT=80", "src_ip": "164.23.198.121", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T10:57:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=131.164.81.24 OUT= PROTO=TCP DPT=443", "src_ip": "131.164.81.24", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T11:06:21", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/bash", "user": "somchai", "host": "web-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-13T11:19:31", "source": "nginx", "category": "benign", "severity": "info", "message": "23.114.193.104 - - \"GET /health HTTP/1.1\" 200 2125", "src_ip": "23.114.193.104", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T11:21:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.190 port 41046 ssh2", "src_ip": "10.0.0.190", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T11:22:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=60.65.164.201 OUT= PROTO=TCP DPT=80", "src_ip": "60.65.164.201", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T11:23:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=506 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:24:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=628 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:25:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.52 port 55705 ssh2", "src_ip": "10.0.5.52", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-13T11:25:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=536 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:26:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=35.21.117.55 OUT= PROTO=TCP DPT=443", "src_ip": "35.21.117.55", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T11:26:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=366 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:27:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=307 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:28:01", "source": "nginx", "category": "web_attack", "severity": "high", "message": "197.113.64.169 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 130", "src_ip": "197.113.64.169", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T11:28:37", "source": "nginx", "category": "benign", "severity": "info", "message": "39.79.39.51 - - \"GET /dashboard HTTP/1.1\" 200 4183", "src_ip": "39.79.39.51", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T11:28:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=665 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:29:47", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.45 port 41745 ssh2", "src_ip": "10.0.5.45", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T11:29:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=243 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:30:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=707 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:31:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.248 dst=209.141.56.12 dport=443 bytes=424 interval=60s", "src_ip": "10.0.4.248", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T11:34:33", "source": "nginx", "category": "benign", "severity": "info", "message": "122.176.44.142 - - \"GET /login HTTP/1.1\" 200 3824", "src_ip": "122.176.44.142", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T11:34:35", "source": "nginx", "category": "benign", "severity": "info", "message": "49.215.233.241 - - \"GET /login HTTP/1.1\" 200 7525", "src_ip": "49.215.233.241", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T11:35:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 55545 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 51249 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 43141 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54102 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 51637 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 46047 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 47426 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 56373 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 57166 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 53153 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 45521 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 57338 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 42672 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 40152 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54802 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 40668 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 52607 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41995 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41938 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:35:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 52227 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T11:41:33", "source": "nginx", "category": "benign", "severity": "info", "message": "47.6.242.110 - - \"GET /api/products HTTP/1.1\" 200 370", "src_ip": "47.6.242.110", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T11:47:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T11:47:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T11:47:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T11:47:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T11:47:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T11:47:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T11:47:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T11:47:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T11:47:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T11:47:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T11:56:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=75.236.232.220 OUT= PROTO=TCP DPT=80", "src_ip": "75.236.232.220", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T11:57:55", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "guest", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-13T12:05:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.4.54 port 42248 ssh2", "src_ip": "10.0.4.54", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-13T12:05:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=14.13.236.56 OUT= PROTO=TCP DPT=443", "src_ip": "14.13.236.56", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T12:06:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=214.121.37.199 OUT= PROTO=TCP DPT=443", "src_ip": "214.121.37.199", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T12:10:09", "source": "nginx", "category": "benign", "severity": "info", "message": "154.108.5.164 - - \"GET /login HTTP/1.1\" 200 5852", "src_ip": "154.108.5.164", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T12:12:48", "source": "nginx", "category": "benign", "severity": "info", "message": "190.178.28.198 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7653", "src_ip": "190.178.28.198", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T12:13:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=166.177.117.237 OUT= PROTO=TCP DPT=80", "src_ip": "166.177.117.237", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T12:14:44", "source": "nginx", "category": "benign", "severity": "info", "message": "178.88.50.99 - - \"GET /static/app.js HTTP/1.1\" 200 5550", "src_ip": "178.88.50.99", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T12:19:04", "source": "nginx", "category": "benign", "severity": "info", "message": "74.55.242.62 - - \"GET /api/products HTTP/1.1\" 200 7019", "src_ip": "74.55.242.62", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T12:29:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 42269 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 40770 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55934 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 48922 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 41636 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 58449 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 44596 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55726 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 54945 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 58391 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:29:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 52964 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:30:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.168 port 55679 ssh2", "src_ip": "10.0.0.168", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T12:31:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=184.210.142.68 OUT= PROTO=TCP DPT=443", "src_ip": "184.210.142.68", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T12:32:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=125.53.135.104 OUT= PROTO=TCP DPT=80", "src_ip": "125.53.135.104", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T12:35:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.186 port 44441 ssh2", "src_ip": "10.0.3.186", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T12:35:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=187.171.9.173 OUT= PROTO=TCP DPT=443", "src_ip": "187.171.9.173", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T12:36:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 55371 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 40172 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 40622 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 57983 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 47066 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 49440 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 49868 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 41564 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 53756 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 59951 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 53869 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:36:44", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for oppa from 91.219.236.18 port 51234 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T12:36:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 54978 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-13T12:41:06", "source": "nginx", "category": "benign", "severity": "info", "message": "31.186.203.41 - - \"GET /login HTTP/1.1\" 200 4824", "src_ip": "31.186.203.41", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T12:43:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=25.186.26.29 OUT= PROTO=TCP DPT=443", "src_ip": "25.186.26.29", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T12:45:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.111 port 52226 ssh2", "src_ip": "10.0.3.111", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-13T12:47:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=23.138.176.205 OUT= PROTO=TCP DPT=80", "src_ip": "23.138.176.205", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T12:53:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=121.129.182.42 OUT= PROTO=TCP DPT=443", "src_ip": "121.129.182.42", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T12:55:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.204 dst=209.141.56.12 dport=443 bytes=564 interval=60s", "src_ip": "10.0.1.204", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T12:56:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.204 dst=209.141.56.12 dport=443 bytes=837 interval=60s", "src_ip": "10.0.1.204", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T12:57:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.204 dst=209.141.56.12 dport=443 bytes=544 interval=60s", "src_ip": "10.0.1.204", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T12:58:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.204 dst=209.141.56.12 dport=443 bytes=572 interval=60s", "src_ip": "10.0.1.204", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T12:59:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.204 dst=209.141.56.12 dport=443 bytes=645 interval=60s", "src_ip": "10.0.1.204", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T13:00:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.183 port 41132 ssh2", "src_ip": "10.0.1.183", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T13:00:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.146 port 44866 ssh2", "src_ip": "10.0.4.146", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-13T13:00:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.50 port 43157 ssh2", "src_ip": "10.0.3.50", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T13:00:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.204 dst=209.141.56.12 dport=443 bytes=391 interval=60s", "src_ip": "10.0.1.204", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T13:01:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.204 dst=209.141.56.12 dport=443 bytes=325 interval=60s", "src_ip": "10.0.1.204", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-13T13:08:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T13:08:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T13:08:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T13:08:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T13:08:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T13:08:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T13:08:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T13:08:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T13:08:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T13:08:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T13:08:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=53.165.89.194 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "53.165.89.194", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T13:09:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.23 port 45230 ssh2", "src_ip": "10.0.3.23", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T13:12:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=184.241.1.143 OUT= PROTO=TCP DPT=443", "src_ip": "184.241.1.143", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T13:13:09", "source": "nginx", "category": "benign", "severity": "info", "message": "179.199.229.242 - - \"GET / HTTP/1.1\" 200 5678", "src_ip": "179.199.229.242", "status": 200, "path": "/"} {"timestamp": "2026-06-13T13:13:23", "source": "nginx", "category": "benign", "severity": "info", "message": "184.242.178.194 - - \"GET /dashboard HTTP/1.1\" 200 3403", "src_ip": "184.242.178.194", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T13:16:04", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.249 dst=185.220.101.34 bytes=6739197952 proto=TCP dport=443 duration=562s", "src_ip": "10.0.3.249", "dst_ip": "185.220.101.34", "bytes_mb": 6427, "off_hours": false} {"timestamp": "2026-06-13T13:17:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=21.14.41.12 OUT= PROTO=TCP DPT=443", "src_ip": "21.14.41.12", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T13:22:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.149.183.47 OUT= PROTO=TCP DPT=80", "src_ip": "164.149.183.47", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T13:22:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.179 port 54330 ssh2", "src_ip": "10.0.2.179", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T13:24:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.5.15 port 40670 ssh2", "src_ip": "10.0.5.15", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-13T13:28:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=144.48.221.170 OUT= PROTO=TCP DPT=80", "src_ip": "144.48.221.170", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T13:29:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.63 port 56081 ssh2", "src_ip": "10.0.1.63", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T13:36:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=124.25.66.8 OUT= PROTO=TCP DPT=443", "src_ip": "124.25.66.8", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T13:41:08", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/su -", "user": "deploy", "host": "web-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-13T13:48:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.3 port 42399 ssh2", "src_ip": "10.0.0.3", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-13T13:58:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=123.97.1.95 OUT= PROTO=TCP DPT=443", "src_ip": "123.97.1.95", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T13:58:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 40868 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 45246 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 53329 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 42835 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 57938 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 44326 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 50523 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 42269 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 42430 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:58:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 41961 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-13T13:59:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=160.252.117.183 OUT= PROTO=TCP DPT=443", "src_ip": "160.252.117.183", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T14:01:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.114 port 40647 ssh2", "src_ip": "10.0.4.114", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T14:03:46", "source": "nginx", "category": "benign", "severity": "info", "message": "194.148.221.71 - - \"GET / HTTP/1.1\" 200 7436", "src_ip": "194.148.221.71", "status": 200, "path": "/"} {"timestamp": "2026-06-13T14:05:17", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.182 dst=193.27.228.114 bytes=1254096896 proto=TCP dport=443 duration=479s", "src_ip": "10.0.0.182", "dst_ip": "193.27.228.114", "bytes_mb": 1196, "off_hours": false} {"timestamp": "2026-06-13T14:06:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.101 port 42315 ssh2", "src_ip": "10.0.2.101", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T14:07:35", "source": "nginx", "category": "benign", "severity": "info", "message": "194.143.252.17 - - \"GET /static/app.js HTTP/1.1\" 200 6261", "src_ip": "194.143.252.17", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T14:07:58", "source": "nginx", "category": "benign", "severity": "info", "message": "24.220.93.112 - - \"GET /static/app.js HTTP/1.1\" 200 1091", "src_ip": "24.220.93.112", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T14:08:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.34.168.232 OUT= PROTO=TCP DPT=443", "src_ip": "215.34.168.232", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T14:10:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49615 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:10:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 43492 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:10:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49837 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 44486 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 56327 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 45014 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 48463 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 51139 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49343 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 42437 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 57201 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 51879 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 43118 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49824 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 58887 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 40744 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 59078 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 47586 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 51920 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49060 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 46054 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:27", "source": "nginx", "category": "benign", "severity": "info", "message": "126.178.205.54 - - \"GET /api/products HTTP/1.1\" 200 3182", "src_ip": "126.178.205.54", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T14:11:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 50937 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 44054 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 43049 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:11:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 59645 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T14:14:27", "source": "nginx", "category": "benign", "severity": "info", "message": "52.247.26.117 - - \"GET /static/app.js HTTP/1.1\" 200 6585", "src_ip": "52.247.26.117", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T14:18:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 43996 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44545 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42659 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 43004 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 54187 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41638 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 43001 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47637 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 50499 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:50", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 185.220.101.34 port 51234 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T14:18:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42602 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:18:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57345 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-13T14:20:36", "source": "nginx", "category": "benign", "severity": "info", "message": "35.219.176.254 - - \"GET /api/products HTTP/1.1\" 200 3574", "src_ip": "35.219.176.254", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T14:23:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.195 port 46010 ssh2", "src_ip": "10.0.5.195", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T14:27:33", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "svc_backup", "host": "app-02", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-13T14:32:04", "source": "nginx", "category": "benign", "severity": "info", "message": "90.255.190.119 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6683", "src_ip": "90.255.190.119", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T14:34:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T14:34:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T14:34:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T14:34:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T14:34:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T14:34:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T14:34:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T14:34:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T14:34:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T14:35:22", "source": "nginx", "category": "benign", "severity": "info", "message": "162.16.18.171 - - \"GET /static/app.js HTTP/1.1\" 200 5001", "src_ip": "162.16.18.171", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T14:40:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=143.32.128.162 OUT= PROTO=TCP DPT=443", "src_ip": "143.32.128.162", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T14:44:13", "source": "nginx", "category": "benign", "severity": "info", "message": "170.236.253.43 - - \"GET /static/app.js HTTP/1.1\" 200 7302", "src_ip": "170.236.253.43", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T14:45:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 40542 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 57128 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 59841 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 45813 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 53755 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 57413 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 55802 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 59654 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 54139 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 43850 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 44270 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 91.219.236.18 port 57671 ssh2", "src_ip": "91.219.236.18", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T14:45:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.1.231 port 55429 ssh2", "src_ip": "10.0.1.231", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T14:46:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T14:46:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T14:46:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T14:46:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T14:46:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T14:46:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T14:46:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T14:46:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T14:46:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T14:46:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T14:46:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T14:46:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T14:47:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=176.167.248.152 OUT= PROTO=TCP DPT=443", "src_ip": "176.167.248.152", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T14:47:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.249 port 40392 ssh2", "src_ip": "10.0.0.249", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T14:50:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=201.224.127.51 OUT= PROTO=TCP DPT=80", "src_ip": "201.224.127.51", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T14:52:45", "source": "nginx", "category": "benign", "severity": "info", "message": "58.255.217.54 - - \"GET /dashboard HTTP/1.1\" 200 5940", "src_ip": "58.255.217.54", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T14:55:18", "source": "nginx", "category": "benign", "severity": "info", "message": "111.144.130.235 - - \"GET /static/app.js HTTP/1.1\" 200 6136", "src_ip": "111.144.130.235", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T14:55:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T14:55:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T14:55:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T14:55:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T14:55:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T14:55:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T14:55:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T14:55:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T14:55:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T14:55:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T14:55:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T14:55:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T14:57:21", "source": "nginx", "category": "benign", "severity": "info", "message": "178.118.152.197 - - \"GET /dashboard HTTP/1.1\" 200 7002", "src_ip": "178.118.152.197", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T14:57:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.150 port 57577 ssh2", "src_ip": "10.0.5.150", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T14:58:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.234 port 55204 ssh2", "src_ip": "10.0.1.234", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T15:02:48", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "deploy", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-13T15:09:25", "source": "nginx", "category": "benign", "severity": "info", "message": "74.141.228.201 - - \"GET / HTTP/1.1\" 200 2858", "src_ip": "74.141.228.201", "status": 200, "path": "/"} {"timestamp": "2026-06-13T15:10:35", "source": "nginx", "category": "benign", "severity": "info", "message": "110.58.95.117 - - \"GET /dashboard HTTP/1.1\" 200 4283", "src_ip": "110.58.95.117", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T15:16:57", "source": "nginx", "category": "benign", "severity": "info", "message": "211.190.156.179 - - \"GET /health HTTP/1.1\" 200 370", "src_ip": "211.190.156.179", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T15:20:29", "source": "nginx", "category": "web_attack", "severity": "high", "message": "115.60.72.231 - - \"GET /search?q= HTTP/1.1\" 403 15", "src_ip": "115.60.72.231", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T15:25:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T15:25:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T15:25:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T15:25:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T15:25:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T15:25:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T15:25:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T15:25:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T15:25:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=25.253.232.89 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "25.253.232.89", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T15:32:09", "source": "nginx", "category": "benign", "severity": "info", "message": "210.171.100.129 - - \"GET /health HTTP/1.1\" 200 3384", "src_ip": "210.171.100.129", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T15:33:00", "source": "nginx", "category": "benign", "severity": "info", "message": "139.231.29.229 - - \"GET /static/app.js HTTP/1.1\" 200 2685", "src_ip": "139.231.29.229", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T15:39:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.81 port 59781 ssh2", "src_ip": "10.0.0.81", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T15:42:06", "source": "nginx", "category": "benign", "severity": "info", "message": "77.139.213.226 - - \"GET / HTTP/1.1\" 200 3026", "src_ip": "77.139.213.226", "status": 200, "path": "/"} {"timestamp": "2026-06-13T15:43:21", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 191", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T15:52:17", "source": "nginx", "category": "benign", "severity": "info", "message": "107.213.212.33 - - \"GET /health HTTP/1.1\" 200 779", "src_ip": "107.213.212.33", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T15:55:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=143.132.85.96 OUT= PROTO=TCP DPT=80", "src_ip": "143.132.85.96", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T15:56:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.76 port 48064 ssh2", "src_ip": "10.0.3.76", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T16:00:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=191.188.245.63 OUT= PROTO=TCP DPT=443", "src_ip": "191.188.245.63", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T16:11:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.174 port 48815 ssh2", "src_ip": "10.0.2.174", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T16:13:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.181 port 59527 ssh2", "src_ip": "10.0.1.181", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T16:15:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.238 port 48602 ssh2", "src_ip": "10.0.2.238", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-13T16:15:36", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.220 dst=185.220.101.34 bytes=4824498176 proto=TCP dport=443 duration=307s", "src_ip": "10.0.1.220", "dst_ip": "185.220.101.34", "bytes_mb": 4601, "off_hours": false} {"timestamp": "2026-06-13T16:17:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=184.15.20.195 OUT= PROTO=TCP DPT=80", "src_ip": "184.15.20.195", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T16:19:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.180 dst=193.27.228.114 dport=443 bytes=598 interval=30s", "src_ip": "10.0.5.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-13T16:19:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.180 dst=193.27.228.114 dport=443 bytes=427 interval=30s", "src_ip": "10.0.5.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-13T16:20:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=169.206.34.12 OUT= PROTO=TCP DPT=80", "src_ip": "169.206.34.12", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T16:20:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.180 dst=193.27.228.114 dport=443 bytes=399 interval=30s", "src_ip": "10.0.5.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-13T16:20:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.180 dst=193.27.228.114 dport=443 bytes=631 interval=30s", "src_ip": "10.0.5.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-13T16:21:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.180 dst=193.27.228.114 dport=443 bytes=323 interval=30s", "src_ip": "10.0.5.180", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-13T16:28:26", "source": "nginx", "category": "benign", "severity": "info", "message": "109.174.38.176 - - \"GET /login HTTP/1.1\" 200 7029", "src_ip": "109.174.38.176", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T16:33:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=145.199.32.45 OUT= PROTO=TCP DPT=80", "src_ip": "145.199.32.45", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T16:34:50", "source": "nginx", "category": "benign", "severity": "info", "message": "130.238.55.22 - - \"GET /login HTTP/1.1\" 200 6194", "src_ip": "130.238.55.22", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T16:36:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.74 port 45169 ssh2", "src_ip": "10.0.2.74", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T16:37:47", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/bash", "user": "nattapong", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-13T16:42:29", "source": "nginx", "category": "benign", "severity": "info", "message": "197.75.120.27 - - \"GET /login HTTP/1.1\" 200 2296", "src_ip": "197.75.120.27", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T16:50:16", "source": "nginx", "category": "benign", "severity": "info", "message": "178.200.66.153 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7884", "src_ip": "178.200.66.153", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T16:55:24", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 200 311", "src_ip": "185.220.101.34", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T17:01:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.219 port 52958 ssh2", "src_ip": "10.0.2.219", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T17:04:08", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.234 dst=91.219.236.18 bytes=7570718720 proto=TCP dport=443 duration=465s", "src_ip": "10.0.3.234", "dst_ip": "91.219.236.18", "bytes_mb": 7220, "off_hours": false} {"timestamp": "2026-06-13T17:11:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=118.126.163.230 OUT= PROTO=TCP DPT=80", "src_ip": "118.126.163.230", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T17:18:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=175.30.46.30 OUT= PROTO=TCP DPT=443", "src_ip": "175.30.46.30", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T17:20:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.218 port 49089 ssh2", "src_ip": "10.0.1.218", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-13T17:20:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.121 port 56785 ssh2", "src_ip": "10.0.0.121", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-13T17:21:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.134 port 49221 ssh2", "src_ip": "10.0.1.134", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T17:23:01", "source": "nginx", "category": "benign", "severity": "info", "message": "44.67.233.13 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1848", "src_ip": "44.67.233.13", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T17:31:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.141 port 56001 ssh2", "src_ip": "10.0.5.141", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-13T17:32:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 43488 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T17:32:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 52480 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T17:32:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 41738 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T17:32:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 48748 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T17:32:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 49391 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T17:32:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 42032 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T17:32:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 41854 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T17:32:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 91.219.236.18 port 48210 ssh2", "src_ip": "91.219.236.18", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T17:35:20", "source": "nginx", "category": "benign", "severity": "info", "message": "220.91.212.27 - - \"GET /dashboard HTTP/1.1\" 200 5088", "src_ip": "220.91.212.27", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T17:38:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=122.140.29.20 OUT= PROTO=TCP DPT=443", "src_ip": "122.140.29.20", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T17:42:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.182 port 44895 ssh2", "src_ip": "10.0.1.182", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T17:44:03", "source": "nginx", "category": "benign", "severity": "info", "message": "135.246.3.129 - - \"GET /login HTTP/1.1\" 200 3803", "src_ip": "135.246.3.129", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T17:48:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T17:48:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T17:48:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T17:48:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T17:48:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T17:48:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T17:48:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T17:48:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T17:48:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T17:48:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T17:48:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T17:48:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T17:50:28", "source": "nginx", "category": "benign", "severity": "info", "message": "81.127.148.231 - - \"GET /login HTTP/1.1\" 200 3308", "src_ip": "81.127.148.231", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T17:57:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T17:57:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T17:57:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T17:57:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T17:57:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T17:57:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T17:57:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T17:57:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T17:57:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T18:00:10", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 200 306", "src_ip": "185.220.101.34", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T18:04:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 53816 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49274 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 48677 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52331 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 57917 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 48704 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 56767 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 54067 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 44970 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-13T18:04:21", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for admin from 185.220.101.34 port 51234 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T18:09:52", "source": "nginx", "category": "benign", "severity": "info", "message": "38.68.205.196 - - \"GET /health HTTP/1.1\" 200 3326", "src_ip": "38.68.205.196", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T18:10:38", "source": "nginx", "category": "benign", "severity": "info", "message": "217.68.112.132 - - \"GET /static/app.js HTTP/1.1\" 200 4231", "src_ip": "217.68.112.132", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T18:10:46", "source": "nginx", "category": "benign", "severity": "info", "message": "65.77.203.129 - - \"GET /dashboard HTTP/1.1\" 200 4360", "src_ip": "65.77.203.129", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T18:13:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=35.252.121.248 OUT= PROTO=TCP DPT=80", "src_ip": "35.252.121.248", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T18:21:57", "source": "nginx", "category": "web_attack", "severity": "high", "message": "160.255.187.116 - - \"GET /search?q= HTTP/1.1\" 403 119", "src_ip": "160.255.187.116", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T18:23:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.149.191.180 OUT= PROTO=TCP DPT=80", "src_ip": "215.149.191.180", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T18:27:46", "source": "nginx", "category": "benign", "severity": "info", "message": "83.198.219.148 - - \"GET /api/products HTTP/1.1\" 200 2605", "src_ip": "83.198.219.148", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T18:33:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=50.36.70.97 OUT= PROTO=TCP DPT=443", "src_ip": "50.36.70.97", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T18:37:59", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "somchai", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-13T18:39:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47037 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 57019 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47707 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 57950 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 56240 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 52988 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47881 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 48457 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 58376 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 56024 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 52874 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 46308 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 48366 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:39:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 51930 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:40:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 40556 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:40:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 53798 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:40:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 56949 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:40:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47713 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:40:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 55715 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:40:12", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T18:40:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 50197 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:40:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 48708 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-13T18:42:29", "source": "nginx", "category": "benign", "severity": "info", "message": "41.48.113.214 - - \"GET /static/app.js HTTP/1.1\" 200 3573", "src_ip": "41.48.113.214", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T18:44:31", "source": "nginx", "category": "benign", "severity": "info", "message": "61.27.32.83 - - \"GET /login HTTP/1.1\" 200 519", "src_ip": "61.27.32.83", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T18:48:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 58771 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:48:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 55463 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:48:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 51813 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:48:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 51672 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 43018 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 45818 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 53247 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 53649 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 50895 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 48735 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 55988 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 45167 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 48070 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 42173 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 49835 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:49:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 193.27.228.114 port 56741 ssh2", "src_ip": "193.27.228.114", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-13T18:55:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=116.60.107.14 OUT= PROTO=TCP DPT=443", "src_ip": "116.60.107.14", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T19:00:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=20.202.127.45 OUT= PROTO=TCP DPT=80", "src_ip": "20.202.127.45", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T19:01:28", "source": "nginx", "category": "benign", "severity": "info", "message": "129.219.88.173 - - \"GET /dashboard HTTP/1.1\" 200 7492", "src_ip": "129.219.88.173", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T19:04:07", "source": "nginx", "category": "benign", "severity": "info", "message": "204.112.232.179 - - \"GET / HTTP/1.1\" 200 7767", "src_ip": "204.112.232.179", "status": 200, "path": "/"} {"timestamp": "2026-06-13T19:09:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.28 port 51589 ssh2", "src_ip": "10.0.5.28", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-13T19:13:17", "source": "nginx", "category": "benign", "severity": "info", "message": "52.239.95.193 - - \"GET / HTTP/1.1\" 200 3796", "src_ip": "52.239.95.193", "status": 200, "path": "/"} {"timestamp": "2026-06-13T19:13:21", "source": "nginx", "category": "benign", "severity": "info", "message": "36.106.128.82 - - \"GET /login HTTP/1.1\" 200 968", "src_ip": "36.106.128.82", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T19:15:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=218.245.189.128 OUT= PROTO=TCP DPT=443", "src_ip": "218.245.189.128", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T19:18:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.120 port 48683 ssh2", "src_ip": "10.0.2.120", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T19:19:35", "source": "nginx", "category": "benign", "severity": "info", "message": "212.6.139.115 - - \"GET /login HTTP/1.1\" 200 6084", "src_ip": "212.6.139.115", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T19:22:04", "source": "nginx", "category": "benign", "severity": "info", "message": "172.95.194.4 - - \"GET /api/products HTTP/1.1\" 200 844", "src_ip": "172.95.194.4", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T19:24:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.50 port 44002 ssh2", "src_ip": "10.0.2.50", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T19:26:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.175 dst=185.220.101.34 dport=443 bytes=715 interval=30s", "src_ip": "10.0.2.175", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T19:27:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.175 dst=185.220.101.34 dport=443 bytes=232 interval=30s", "src_ip": "10.0.2.175", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T19:27:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.175 dst=185.220.101.34 dport=443 bytes=265 interval=30s", "src_ip": "10.0.2.175", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T19:28:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.175 dst=185.220.101.34 dport=443 bytes=545 interval=30s", "src_ip": "10.0.2.175", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T19:28:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.175 dst=185.220.101.34 dport=443 bytes=640 interval=30s", "src_ip": "10.0.2.175", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T19:29:16", "source": "nginx", "category": "benign", "severity": "info", "message": "185.155.205.15 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5500", "src_ip": "185.155.205.15", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T19:29:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.175 dst=185.220.101.34 dport=443 bytes=316 interval=30s", "src_ip": "10.0.2.175", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-13T19:30:44", "source": "nginx", "category": "benign", "severity": "info", "message": "159.161.177.18 - - \"GET /static/app.js HTTP/1.1\" 200 5471", "src_ip": "159.161.177.18", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T19:32:16", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 341", "src_ip": "45.137.21.9", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T19:32:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.133 port 57912 ssh2", "src_ip": "10.0.4.133", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-13T19:32:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T19:32:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T19:32:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T19:32:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T19:32:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T19:32:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T19:32:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T19:32:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T19:32:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T19:32:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T19:32:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T19:32:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T19:35:15", "source": "nginx", "category": "benign", "severity": "info", "message": "32.224.97.36 - - \"GET / HTTP/1.1\" 200 1781", "src_ip": "32.224.97.36", "status": 200, "path": "/"} {"timestamp": "2026-06-13T19:35:34", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 280", "src_ip": "193.27.228.114", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T19:38:48", "source": "nginx", "category": "benign", "severity": "info", "message": "78.218.27.212 - - \"GET /static/app.js HTTP/1.1\" 200 1922", "src_ip": "78.218.27.212", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T19:40:51", "source": "nginx", "category": "benign", "severity": "info", "message": "107.85.241.113 - - \"GET /dashboard HTTP/1.1\" 200 4339", "src_ip": "107.85.241.113", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T19:46:03", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 403 488", "src_ip": "45.137.21.9", "status": 403, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T19:46:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.52 port 49309 ssh2", "src_ip": "10.0.1.52", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T19:47:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=69.169.101.197 OUT= PROTO=TCP DPT=80", "src_ip": "69.169.101.197", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T19:55:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.151 port 41021 ssh2", "src_ip": "10.0.4.151", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-13T19:56:03", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.206 dst=209.141.56.12 bytes=4562354176 proto=TCP dport=443 duration=461s", "src_ip": "10.0.2.206", "dst_ip": "209.141.56.12", "bytes_mb": 4351, "off_hours": false} {"timestamp": "2026-06-13T20:02:06", "source": "nginx", "category": "benign", "severity": "info", "message": "66.243.4.30 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3034", "src_ip": "66.243.4.30", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T20:06:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.156 port 46017 ssh2", "src_ip": "10.0.5.156", "user": "root", "action": "login_success"} {"timestamp": "2026-06-13T20:13:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=220.190.132.43 OUT= PROTO=TCP DPT=80", "src_ip": "220.190.132.43", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T20:14:15", "source": "nginx", "category": "benign", "severity": "info", "message": "132.109.27.55 - - \"GET /health HTTP/1.1\" 200 387", "src_ip": "132.109.27.55", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T20:16:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T20:16:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T20:16:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T20:16:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T20:16:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T20:16:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T20:16:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T20:16:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T20:16:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T20:18:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=134.223.132.161 OUT= PROTO=TCP DPT=443", "src_ip": "134.223.132.161", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T20:19:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=204.255.226.195 OUT= PROTO=TCP DPT=80", "src_ip": "204.255.226.195", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T20:23:25", "source": "nginx", "category": "benign", "severity": "info", "message": "189.57.85.39 - - \"GET / HTTP/1.1\" 200 3100", "src_ip": "189.57.85.39", "status": 200, "path": "/"} {"timestamp": "2026-06-13T20:25:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.156 dst=185.220.101.34 dport=443 bytes=537 interval=300s", "src_ip": "10.0.1.156", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-13T20:30:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.156 dst=185.220.101.34 dport=443 bytes=224 interval=300s", "src_ip": "10.0.1.156", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-13T20:32:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=84.37.197.130 OUT= PROTO=TCP DPT=443", "src_ip": "84.37.197.130", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T20:33:34", "source": "nginx", "category": "benign", "severity": "info", "message": "57.109.174.243 - - \"GET /health HTTP/1.1\" 200 4183", "src_ip": "57.109.174.243", "status": 200, "path": "/health"} {"timestamp": "2026-06-13T20:34:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=63.134.67.135 OUT= PROTO=TCP DPT=80", "src_ip": "63.134.67.135", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T20:35:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.156 dst=185.220.101.34 dport=443 bytes=836 interval=300s", "src_ip": "10.0.1.156", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-13T20:38:04", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.223 dst=45.137.21.9 bytes=2554331136 proto=TCP dport=443 duration=513s", "src_ip": "10.0.4.223", "dst_ip": "45.137.21.9", "bytes_mb": 2436, "off_hours": false} {"timestamp": "2026-06-13T20:40:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.156 dst=185.220.101.34 dport=443 bytes=377 interval=300s", "src_ip": "10.0.1.156", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-13T20:40:15", "source": "nginx", "category": "benign", "severity": "info", "message": "72.29.123.225 - - \"GET /static/app.js HTTP/1.1\" 200 7957", "src_ip": "72.29.123.225", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T20:43:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T20:43:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T20:43:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T20:43:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T20:43:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T20:43:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T20:43:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T20:43:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T20:43:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=87.200.40.71 OUT= PROTO=TCP DPT=443", "src_ip": "87.200.40.71", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T20:43:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=171.136.247.35 OUT= PROTO=TCP DPT=443", "src_ip": "171.136.247.35", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T20:45:09", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.156 dst=185.220.101.34 dport=443 bytes=598 interval=300s", "src_ip": "10.0.1.156", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-13T20:45:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=126.58.49.195 OUT= PROTO=TCP DPT=80", "src_ip": "126.58.49.195", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T20:54:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.130 port 44087 ssh2", "src_ip": "10.0.2.130", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-13T21:01:27", "source": "nginx", "category": "benign", "severity": "info", "message": "64.222.128.86 - - \"GET /static/app.js HTTP/1.1\" 200 6795", "src_ip": "64.222.128.86", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T21:09:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=202.72.45.83 OUT= PROTO=TCP DPT=80", "src_ip": "202.72.45.83", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T21:11:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=85.82.105.54 OUT= PROTO=TCP DPT=80", "src_ip": "85.82.105.54", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T21:12:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.55 port 48748 ssh2", "src_ip": "10.0.2.55", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T21:13:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=44.46.151.84 OUT= PROTO=TCP DPT=443", "src_ip": "44.46.151.84", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T21:13:08", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 3", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T21:16:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 48845 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:16:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 58197 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:16:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 44779 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:16:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 52480 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 53812 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 40319 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 44900 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 44406 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 49831 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 58420 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 56941 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 43243 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 50345 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:25", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for www-data from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T21:17:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 41563 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:17:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 45352 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T21:20:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=178.39.128.97 OUT= PROTO=TCP DPT=80", "src_ip": "178.39.128.97", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T21:27:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 40430 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 53662 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 48423 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 40637 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 54416 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 54845 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 53978 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 45796 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55107 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 54220 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44662 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 56214 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 40461 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55262 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 40118 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 48211 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 53650 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55681 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 57574 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:27:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55012 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:28:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 59857 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:28:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 56841 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:28:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 59879 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T21:30:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=146.255.207.8 OUT= PROTO=TCP DPT=443", "src_ip": "146.255.207.8", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T21:32:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.8 dst=209.141.56.12 dport=443 bytes=403 interval=30s", "src_ip": "10.0.2.8", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T21:32:35", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.119 dst=193.27.228.114 bytes=2930769920 proto=TCP dport=443 duration=262s", "src_ip": "10.0.1.119", "dst_ip": "193.27.228.114", "bytes_mb": 2795, "off_hours": false} {"timestamp": "2026-06-13T21:33:02", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.8 dst=209.141.56.12 dport=443 bytes=897 interval=30s", "src_ip": "10.0.2.8", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T21:33:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.8 dst=209.141.56.12 dport=443 bytes=204 interval=30s", "src_ip": "10.0.2.8", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T21:34:02", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.8 dst=209.141.56.12 dport=443 bytes=269 interval=30s", "src_ip": "10.0.2.8", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T21:34:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.8 dst=209.141.56.12 dport=443 bytes=651 interval=30s", "src_ip": "10.0.2.8", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T21:35:02", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.8 dst=209.141.56.12 dport=443 bytes=435 interval=30s", "src_ip": "10.0.2.8", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T21:35:32", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.8 dst=209.141.56.12 dport=443 bytes=895 interval=30s", "src_ip": "10.0.2.8", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-13T21:39:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T21:39:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T21:39:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T21:39:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T21:39:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T21:39:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T21:39:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T21:39:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T21:39:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T21:40:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 41486 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 54257 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 58939 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 44139 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 44142 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 58825 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 41631 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 53084 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 51212 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 56283 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 55052 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 46922 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:40:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 49124 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:41:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 41914 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:41:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 49014 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:41:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 45820 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:41:22", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 185.220.101.34 port 51234 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T21:41:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 45339 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:41:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 50751 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:41:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 49174 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-13T21:46:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=186.182.44.11 OUT= PROTO=TCP DPT=80", "src_ip": "186.182.44.11", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T21:48:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T21:48:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T21:48:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T21:48:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T21:48:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T21:48:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T21:48:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T21:48:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T21:48:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T21:48:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T21:48:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T21:53:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=211.142.236.63 OUT= PROTO=TCP DPT=443", "src_ip": "211.142.236.63", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T21:56:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=79.42.217.21 OUT= PROTO=TCP DPT=443", "src_ip": "79.42.217.21", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T21:58:52", "source": "nginx", "category": "benign", "severity": "info", "message": "184.253.130.13 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3316", "src_ip": "184.253.130.13", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T21:59:16", "source": "nginx", "category": "benign", "severity": "info", "message": "40.211.195.97 - - \"GET /api/products HTTP/1.1\" 200 3260", "src_ip": "40.211.195.97", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T22:01:35", "source": "nginx", "category": "benign", "severity": "info", "message": "67.254.42.22 - - \"GET /api/products HTTP/1.1\" 200 7128", "src_ip": "67.254.42.22", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T22:01:46", "source": "nginx", "category": "benign", "severity": "info", "message": "38.130.222.91 - - \"GET /login HTTP/1.1\" 200 7431", "src_ip": "38.130.222.91", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T22:09:34", "source": "nginx", "category": "benign", "severity": "info", "message": "189.151.180.246 - - \"GET /dashboard HTTP/1.1\" 200 2990", "src_ip": "189.151.180.246", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T22:10:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=223.84.203.55 OUT= PROTO=TCP DPT=80", "src_ip": "223.84.203.55", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T22:10:30", "source": "nginx", "category": "benign", "severity": "info", "message": "188.231.21.234 - - \"GET /login HTTP/1.1\" 200 501", "src_ip": "188.231.21.234", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T22:12:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=58.222.218.24 OUT= PROTO=TCP DPT=80", "src_ip": "58.222.218.24", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T22:12:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=32.229.34.15 OUT= PROTO=TCP DPT=443", "src_ip": "32.229.34.15", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T22:12:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=137.100.125.39 OUT= PROTO=TCP DPT=80", "src_ip": "137.100.125.39", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T22:13:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=180.155.83.211 OUT= PROTO=TCP DPT=80", "src_ip": "180.155.83.211", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T22:14:47", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.148 port 45413 ssh2", "src_ip": "10.0.1.148", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-13T22:21:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 492", "src_ip": "185.220.101.34", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-13T22:23:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 49970 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 48641 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 52437 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 59118 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 45581 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 50463 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=196.80.77.152 OUT= PROTO=TCP DPT=443", "src_ip": "196.80.77.152", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T22:23:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 59140 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 43928 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 54640 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:43", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for guest from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T22:23:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 44009 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:23:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 45.137.21.9 port 57288 ssh2", "src_ip": "45.137.21.9", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T22:25:48", "source": "nginx", "category": "benign", "severity": "info", "message": "152.176.217.191 - - \"GET /static/app.js HTTP/1.1\" 200 2909", "src_ip": "152.176.217.191", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T22:30:38", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 403 91", "src_ip": "185.220.101.34", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-13T22:37:53", "source": "nginx", "category": "benign", "severity": "info", "message": "93.107.157.204 - - \"GET /static/app.js HTTP/1.1\" 200 7472", "src_ip": "93.107.157.204", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-13T22:38:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T22:38:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T22:38:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T22:38:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T22:38:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T22:38:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T22:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T22:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T22:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T22:38:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T22:38:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T22:43:18", "source": "nginx", "category": "benign", "severity": "info", "message": "147.67.2.22 - - \"GET /dashboard HTTP/1.1\" 200 5597", "src_ip": "147.67.2.22", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T22:50:02", "source": "nginx", "category": "benign", "severity": "info", "message": "48.217.216.150 - - \"GET /login HTTP/1.1\" 200 2010", "src_ip": "48.217.216.150", "status": 200, "path": "/login"} {"timestamp": "2026-06-13T22:55:15", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/bin/bash", "user": "svc_backup", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-13T22:58:27", "source": "nginx", "category": "benign", "severity": "info", "message": "162.178.190.73 - - \"GET /dashboard HTTP/1.1\" 200 7109", "src_ip": "162.178.190.73", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-13T22:59:16", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-13T22:59:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=130.4.91.95 OUT= PROTO=TCP DPT=443", "src_ip": "130.4.91.95", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T22:59:47", "source": "nginx", "category": "web_attack", "severity": "high", "message": "22.66.44.166 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 279", "src_ip": "22.66.44.166", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T23:00:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T23:00:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T23:00:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T23:00:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T23:00:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T23:00:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T23:00:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T23:00:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T23:00:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=201.214.79.227 OUT= PROTO=TCP DPT=443", "src_ip": "201.214.79.227", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T23:01:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T23:01:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T23:01:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T23:01:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T23:01:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T23:01:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T23:01:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T23:01:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T23:01:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=90.100.142.22 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "90.100.142.22", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T23:05:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=152.74.164.189 OUT= PROTO=TCP DPT=443", "src_ip": "152.74.164.189", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T23:12:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=275 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:12:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T23:12:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T23:12:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T23:12:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T23:12:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T23:12:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-13T23:12:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T23:12:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T23:12:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T23:12:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T23:12:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T23:12:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-13T23:15:05", "source": "nginx", "category": "benign", "severity": "info", "message": "139.197.1.14 - - \"GET /api/products HTTP/1.1\" 200 2963", "src_ip": "139.197.1.14", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T23:16:10", "source": "nginx", "category": "benign", "severity": "info", "message": "208.24.75.91 - - \"GET /api/products HTTP/1.1\" 200 3934", "src_ip": "208.24.75.91", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T23:17:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.4 port 50439 ssh2", "src_ip": "10.0.0.4", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-13T23:17:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=688 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:19:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=138.50.174.93 OUT= PROTO=TCP DPT=443", "src_ip": "138.50.174.93", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T23:21:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=142.182.94.61 OUT= PROTO=TCP DPT=443", "src_ip": "142.182.94.61", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T23:22:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=808 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:25:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=137.72.121.177 OUT= PROTO=TCP DPT=80", "src_ip": "137.72.121.177", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-13T23:27:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=361 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:31:17", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=202.17.30.39 OUT= PROTO=TCP DPT=443", "src_ip": "202.17.30.39", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-13T23:32:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.232 port 41725 ssh2", "src_ip": "10.0.5.232", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-13T23:32:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=230 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:32:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.91 port 50095 ssh2", "src_ip": "10.0.2.91", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-13T23:32:37", "source": "nginx", "category": "benign", "severity": "info", "message": "165.240.63.46 - - \"GET /api/products HTTP/1.1\" 200 1384", "src_ip": "165.240.63.46", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-13T23:33:15", "source": "nginx", "category": "benign", "severity": "info", "message": "152.9.176.125 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5097", "src_ip": "152.9.176.125", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-13T23:37:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=350 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:40:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43487 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 54865 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 46171 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 50045 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 53307 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 40019 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44730 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 40770 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 41019 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43532 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 46085 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 48304 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 46856 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 59580 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43967 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43164 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43897 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 51715 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 51244 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 42337 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:41:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 53205 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-13T23:42:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=574 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:46:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 54639 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 58486 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 51854 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 42023 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 58766 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 50751 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 46730 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 56563 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 44910 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:46:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 193.27.228.114 port 54478 ssh2", "src_ip": "193.27.228.114", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-13T23:47:03", "source": "nginx", "category": "web_attack", "severity": "high", "message": "33.160.10.194 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 163", "src_ip": "33.160.10.194", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-13T23:47:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=344 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:52:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.29 dst=45.137.21.9 dport=443 bytes=280 interval=300s", "src_ip": "10.0.5.29", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-13T23:54:42", "source": "nginx", "category": "benign", "severity": "info", "message": "151.43.68.193 - - \"GET / HTTP/1.1\" 200 2617", "src_ip": "151.43.68.193", "status": 200, "path": "/"} {"timestamp": "2026-06-13T23:57:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 56041 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 59277 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 53395 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 44078 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:23", "source": "nginx", "category": "benign", "severity": "info", "message": "86.151.163.39 - - \"GET / HTTP/1.1\" 200 6784", "src_ip": "86.151.163.39", "status": 200, "path": "/"} {"timestamp": "2026-06-13T23:57:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 46364 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 58533 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 48364 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 55654 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 51842 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 51422 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 56011 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 48086 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 52064 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 41890 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 52626 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 59838 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 44828 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:57:58", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for deploy from 114.212.202.249 port 51234 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-13T23:58:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 40925 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:58:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 114.212.202.249 port 44845 ssh2", "src_ip": "114.212.202.249", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-13T23:58:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-13T23:58:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-13T23:58:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-13T23:58:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-13T23:58:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-13T23:58:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-13T23:58:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-13T23:58:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-13T23:58:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-13T23:58:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-13T23:59:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=220.162.171.44 OUT= PROTO=TCP DPT=443", "src_ip": "220.162.171.44", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T00:04:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.70 port 48667 ssh2", "src_ip": "10.0.2.70", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T00:05:20", "source": "nginx", "category": "benign", "severity": "info", "message": "86.15.82.95 - - \"GET / HTTP/1.1\" 200 2582", "src_ip": "86.15.82.95", "status": 200, "path": "/"} {"timestamp": "2026-06-14T00:05:54", "source": "nginx", "category": "web_attack", "severity": "high", "message": "32.80.248.38 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 477", "src_ip": "32.80.248.38", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T00:11:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=201.130.184.247 OUT= PROTO=TCP DPT=443", "src_ip": "201.130.184.247", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T00:27:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 56632 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 58932 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 56247 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 59225 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 43828 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 47447 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 52793 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 48074 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 58751 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:27:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 91.219.236.18 port 55701 ssh2", "src_ip": "91.219.236.18", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T00:28:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.2.190 port 52796 ssh2", "src_ip": "10.0.2.190", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T00:30:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T00:30:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T00:30:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T00:30:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T00:30:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T00:30:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T00:30:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T00:30:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T00:40:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.213 port 46901 ssh2", "src_ip": "10.0.1.213", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T00:40:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 56919 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:40:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 43232 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:40:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 46306 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:40:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 59344 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:40:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 42832 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:40:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 53200 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:40:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 40081 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 43023 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 57723 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 44375 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 55524 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 54755 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 44806 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 42959 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 51855 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 58452 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 53576 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 44901 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45005 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 44732 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 57981 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 40766 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:41:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 56468 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T00:48:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.144 port 48658 ssh2", "src_ip": "10.0.2.144", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T00:54:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T00:54:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T00:54:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T00:54:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T00:54:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T00:54:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T00:54:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T00:54:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T00:54:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=186.178.36.157 OUT= PROTO=TCP DPT=443", "src_ip": "186.178.36.157", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T00:54:56", "source": "nginx", "category": "benign", "severity": "info", "message": "116.222.39.1 - - \"GET /login HTTP/1.1\" 200 2767", "src_ip": "116.222.39.1", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T00:56:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.220 dst=193.27.228.114 dport=443 bytes=323 interval=300s", "src_ip": "10.0.1.220", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-14T00:56:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 42442 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 56906 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 41090 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 52687 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 46595 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 53153 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 55276 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 53035 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 44037 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 56885 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:56:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 50014 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:57:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 58914 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:57:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 42100 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T00:57:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 57160 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T01:00:03", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 66", "src_ip": "45.137.21.9", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T01:01:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.220 dst=193.27.228.114 dport=443 bytes=385 interval=300s", "src_ip": "10.0.1.220", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-14T01:04:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.246 dst=209.141.56.12 dport=443 bytes=466 interval=60s", "src_ip": "10.0.5.246", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:05:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.246 dst=209.141.56.12 dport=443 bytes=241 interval=60s", "src_ip": "10.0.5.246", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:06:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.246 dst=209.141.56.12 dport=443 bytes=724 interval=60s", "src_ip": "10.0.5.246", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:06:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.220 dst=193.27.228.114 dport=443 bytes=860 interval=300s", "src_ip": "10.0.1.220", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-14T01:07:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.246 dst=209.141.56.12 dport=443 bytes=655 interval=60s", "src_ip": "10.0.5.246", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:08:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.246 dst=209.141.56.12 dport=443 bytes=305 interval=60s", "src_ip": "10.0.5.246", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:09:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.246 dst=209.141.56.12 dport=443 bytes=205 interval=60s", "src_ip": "10.0.5.246", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:10:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=207.96.126.184 OUT= PROTO=TCP DPT=80", "src_ip": "207.96.126.184", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T01:10:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=25.182.169.207 OUT= PROTO=TCP DPT=80", "src_ip": "25.182.169.207", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T01:11:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.220 dst=193.27.228.114 dport=443 bytes=751 interval=300s", "src_ip": "10.0.1.220", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-14T01:13:10", "source": "nginx", "category": "benign", "severity": "info", "message": "58.32.56.184 - - \"GET /api/products HTTP/1.1\" 200 2598", "src_ip": "58.32.56.184", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T01:15:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.3 port 56574 ssh2", "src_ip": "10.0.1.3", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T01:15:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=406 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:16:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.220 dst=193.27.228.114 dport=443 bytes=330 interval=300s", "src_ip": "10.0.1.220", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-14T01:16:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=850 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:17:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=349 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:17:40", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.218 dst=209.141.56.12 bytes=5295308800 proto=TCP dport=443 duration=444s", "src_ip": "10.0.0.218", "dst_ip": "209.141.56.12", "bytes_mb": 5050, "off_hours": true} {"timestamp": "2026-06-14T01:18:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=411 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:19:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=598 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:20:02", "source": "nginx", "category": "benign", "severity": "info", "message": "18.253.166.47 - - \"GET /dashboard HTTP/1.1\" 200 1937", "src_ip": "18.253.166.47", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T01:20:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=561 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:21:11", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.220 dst=193.27.228.114 dport=443 bytes=323 interval=300s", "src_ip": "10.0.1.220", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-14T01:21:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=392 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:21:41", "source": "nginx", "category": "benign", "severity": "info", "message": "77.89.203.129 - - \"GET /login HTTP/1.1\" 200 3311", "src_ip": "77.89.203.129", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T01:21:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.229 port 40902 ssh2", "src_ip": "10.0.5.229", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T01:22:14", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 176", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T01:22:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=881 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:23:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=878 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:24:24", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.72 dst=209.141.56.12 dport=443 bytes=448 interval=60s", "src_ip": "10.0.5.72", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:25:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 42207 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 41146 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 55367 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 43477 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 40016 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 45787 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 52197 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 58195 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 45.137.21.9 port 51865 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T01:25:53", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for deploy from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "deploy", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T01:25:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.15 port 49999 ssh2", "src_ip": "10.0.4.15", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T01:26:40", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.136 port 48822 ssh2", "src_ip": "10.0.4.136", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T01:27:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.132 port 59558 ssh2", "src_ip": "10.0.0.132", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T01:29:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.44 port 40133 ssh2", "src_ip": "10.0.5.44", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T01:32:17", "source": "nginx", "category": "benign", "severity": "info", "message": "192.22.65.139 - - \"GET /static/app.js HTTP/1.1\" 200 4256", "src_ip": "192.22.65.139", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T01:35:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.59 port 50135 ssh2", "src_ip": "10.0.2.59", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-14T01:35:46", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 164", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T01:40:22", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 45", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T01:40:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.54 port 56106 ssh2", "src_ip": "10.0.2.54", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T01:41:06", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 403 163", "src_ip": "209.141.56.12", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T01:41:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=100.213.5.216 OUT= PROTO=TCP DPT=443", "src_ip": "100.213.5.216", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T01:45:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.167 port 53900 ssh2", "src_ip": "10.0.2.167", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T01:49:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=21.241.38.168 OUT= PROTO=TCP DPT=443", "src_ip": "21.241.38.168", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T01:55:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.242 port 57703 ssh2", "src_ip": "10.0.1.242", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T01:57:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.180 dst=209.141.56.12 dport=443 bytes=352 interval=60s", "src_ip": "10.0.2.180", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:58:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.180 dst=209.141.56.12 dport=443 bytes=507 interval=60s", "src_ip": "10.0.2.180", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T01:59:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 59311 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 59848 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 57591 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 50163 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 50758 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 41456 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 42596 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T01:59:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T01:59:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T01:59:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T01:59:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T01:59:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T01:59:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T01:59:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T01:59:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 45122 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 54713 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T01:59:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T01:59:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T01:59:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 45491 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 57452 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 45221 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 47216 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 45490 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 57707 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 209.141.56.12 port 55082 ssh2", "src_ip": "209.141.56.12", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T01:59:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.180 dst=209.141.56.12 dport=443 bytes=585 interval=60s", "src_ip": "10.0.2.180", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T02:00:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.180 dst=209.141.56.12 dport=443 bytes=388 interval=60s", "src_ip": "10.0.2.180", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T02:01:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.180 dst=209.141.56.12 dport=443 bytes=750 interval=60s", "src_ip": "10.0.2.180", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T02:02:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.180 dst=209.141.56.12 dport=443 bytes=684 interval=60s", "src_ip": "10.0.2.180", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T02:02:57", "source": "nginx", "category": "benign", "severity": "info", "message": "58.228.22.68 - - \"GET /dashboard HTTP/1.1\" 200 4009", "src_ip": "58.228.22.68", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T02:03:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T02:03:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T02:03:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T02:03:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T02:03:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T02:03:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T02:03:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T02:03:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T02:03:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T02:03:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T02:03:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T02:03:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.180 dst=209.141.56.12 dport=443 bytes=446 interval=60s", "src_ip": "10.0.2.180", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T02:04:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.180 dst=209.141.56.12 dport=443 bytes=430 interval=60s", "src_ip": "10.0.2.180", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T02:05:08", "source": "nginx", "category": "benign", "severity": "info", "message": "152.24.130.112 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5886", "src_ip": "152.24.130.112", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T02:11:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T02:11:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T02:11:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T02:11:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T02:11:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T02:11:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T02:11:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T02:11:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T02:11:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T02:16:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T02:16:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T02:16:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T02:16:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T02:16:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T02:16:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T02:16:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T02:16:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T02:16:41", "source": "nginx", "category": "benign", "severity": "info", "message": "90.96.15.245 - - \"GET /static/app.js HTTP/1.1\" 200 5705", "src_ip": "90.96.15.245", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T02:19:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.61 port 48703 ssh2", "src_ip": "10.0.3.61", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T02:20:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=101.233.132.102 OUT= PROTO=TCP DPT=443", "src_ip": "101.233.132.102", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T02:23:23", "source": "nginx", "category": "benign", "severity": "info", "message": "76.166.54.40 - - \"GET /login HTTP/1.1\" 200 7505", "src_ip": "76.166.54.40", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T02:25:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=120.88.181.55 OUT= PROTO=TCP DPT=80", "src_ip": "120.88.181.55", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T02:30:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=220 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:31:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=320 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:32:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=227 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:33:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=820 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:34:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=425 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:35:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=646 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:36:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=203 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:37:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=801 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:38:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.145 dst=45.137.21.9 dport=443 bytes=864 interval=60s", "src_ip": "10.0.0.145", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-14T02:45:40", "source": "nginx", "category": "benign", "severity": "info", "message": "111.112.21.12 - - \"GET /api/products HTTP/1.1\" 200 299", "src_ip": "111.112.21.12", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T02:46:23", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/bash", "user": "nattapong", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-14T02:48:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=57.217.77.73 OUT= PROTO=TCP DPT=443", "src_ip": "57.217.77.73", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T02:50:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=59.153.199.230 OUT= PROTO=TCP DPT=80", "src_ip": "59.153.199.230", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T02:54:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.6 port 44251 ssh2", "src_ip": "10.0.2.6", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T02:55:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=49.223.254.184 OUT= PROTO=TCP DPT=80", "src_ip": "49.223.254.184", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T03:00:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=114.178.109.185 OUT= PROTO=TCP DPT=443", "src_ip": "114.178.109.185", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T03:02:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.15 port 40381 ssh2", "src_ip": "10.0.4.15", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T03:05:00", "source": "nginx", "category": "benign", "severity": "info", "message": "206.180.205.4 - - \"GET / HTTP/1.1\" 200 5706", "src_ip": "206.180.205.4", "status": 200, "path": "/"} {"timestamp": "2026-06-14T03:10:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.111 port 54775 ssh2", "src_ip": "10.0.1.111", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T03:14:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.253 port 58325 ssh2", "src_ip": "10.0.3.253", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T03:15:18", "source": "nginx", "category": "benign", "severity": "info", "message": "182.167.52.234 - - \"GET /dashboard HTTP/1.1\" 200 2757", "src_ip": "182.167.52.234", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T03:17:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=44.51.53.145 OUT= PROTO=TCP DPT=443", "src_ip": "44.51.53.145", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T03:28:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.67 port 40960 ssh2", "src_ip": "10.0.5.67", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T03:31:41", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 101", "src_ip": "185.220.101.34", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-14T03:32:24", "source": "nginx", "category": "benign", "severity": "info", "message": "75.76.170.21 - - \"GET /static/app.js HTTP/1.1\" 200 5636", "src_ip": "75.76.170.21", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T03:33:49", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/bin/su -", "user": "svc_backup", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-14T03:34:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.21 port 42927 ssh2", "src_ip": "10.0.3.21", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T03:35:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.163 port 42719 ssh2", "src_ip": "10.0.5.163", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T03:37:57", "source": "nginx", "category": "benign", "severity": "info", "message": "75.8.182.202 - - \"GET / HTTP/1.1\" 200 3024", "src_ip": "75.8.182.202", "status": 200, "path": "/"} {"timestamp": "2026-06-14T03:41:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=77.186.134.111 OUT= PROTO=TCP DPT=443", "src_ip": "77.186.134.111", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T03:43:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.59 port 44971 ssh2", "src_ip": "10.0.2.59", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T03:45:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=217.90.192.12 OUT= PROTO=TCP DPT=443", "src_ip": "217.90.192.12", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T03:46:28", "source": "nginx", "category": "benign", "severity": "info", "message": "206.66.108.217 - - \"GET / HTTP/1.1\" 200 2324", "src_ip": "206.66.108.217", "status": 200, "path": "/"} {"timestamp": "2026-06-14T03:47:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 54481 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 57884 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 56732 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 45231 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 49615 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 55305 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 53526 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 56720 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 47710 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 40492 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 41969 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 46805 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 56403 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 44770 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:47:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 48908 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:48:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 55839 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T03:48:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.129 port 46378 ssh2", "src_ip": "10.0.4.129", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T03:49:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=41.114.18.145 OUT= PROTO=TCP DPT=80", "src_ip": "41.114.18.145", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T03:49:19", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "svc_backup", "host": "bastion-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-14T04:00:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=178.24.129.150 OUT= PROTO=TCP DPT=80", "src_ip": "178.24.129.150", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T04:02:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.236 port 56312 ssh2", "src_ip": "10.0.4.236", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T04:05:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 55071 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 57743 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 53180 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 51565 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 53297 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 53688 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 57364 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 54821 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 52728 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 51913 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 50682 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:05:48", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for nattapong from 185.220.101.34 port 51234 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T04:05:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 185.220.101.34 port 53070 ssh2", "src_ip": "185.220.101.34", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T04:06:17", "source": "nginx", "category": "benign", "severity": "info", "message": "83.78.61.77 - - \"GET /dashboard HTTP/1.1\" 200 6762", "src_ip": "83.78.61.77", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T04:08:00", "source": "nginx", "category": "benign", "severity": "info", "message": "118.32.62.170 - - \"GET /static/app.js HTTP/1.1\" 200 1691", "src_ip": "118.32.62.170", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T04:11:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 49287 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 42697 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 53916 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 54481 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 55959 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 59980 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 51032 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 45294 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 42520 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 47468 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 58498 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 43081 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 48960 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 41919 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 42352 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 49393 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 58430 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:42", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for oppa from 197.62.176.191 port 51234 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T04:11:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 55712 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:11:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 197.62.176.191 port 59359 ssh2", "src_ip": "197.62.176.191", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T04:12:29", "source": "nginx", "category": "benign", "severity": "info", "message": "182.207.84.216 - - \"GET /dashboard HTTP/1.1\" 200 7732", "src_ip": "182.207.84.216", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T04:14:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 59782 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:14:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 50168 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:14:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 44675 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:14:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 46651 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:14:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 46609 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:14:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 57231 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 55039 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 42096 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 42985 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.113 port 58625 ssh2", "src_ip": "10.0.2.113", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T04:15:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 59819 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 54158 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 58652 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 55079 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 52895 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 58878 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 54952 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 49746 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 45738 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 48163 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 52604 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:37", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 44.105.158.111 port 51234 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T04:15:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 46011 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 58632 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:15:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.252 port 51686 ssh2", "src_ip": "10.0.4.252", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T04:15:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 44.105.158.111 port 41430 ssh2", "src_ip": "44.105.158.111", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T04:19:50", "source": "nginx", "category": "benign", "severity": "info", "message": "37.206.108.43 - - \"GET /login HTTP/1.1\" 200 5287", "src_ip": "37.206.108.43", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T04:21:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 56062 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 54575 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 49669 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 49050 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 51158 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 52550 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 58700 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 55475 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 54466 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 52818 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:21:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 51052 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:22:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 42443 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:22:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 41662 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:22:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 41624 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:22:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 41659 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:22:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 42522 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:22:18", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T04:22:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 193.27.228.114 port 51713 ssh2", "src_ip": "193.27.228.114", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T04:30:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.195 port 49522 ssh2", "src_ip": "10.0.2.195", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T04:31:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=67.22.115.227 OUT= PROTO=TCP DPT=80", "src_ip": "67.22.115.227", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T04:32:13", "source": "nginx", "category": "benign", "severity": "info", "message": "148.112.249.57 - - \"GET /api/products HTTP/1.1\" 200 3770", "src_ip": "148.112.249.57", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T04:35:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 44090 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T04:35:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 49161 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T04:35:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 45764 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T04:35:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 48792 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T04:35:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 51227 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T04:35:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 45981 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T04:35:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 59450 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T04:35:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 45.137.21.9 port 52883 ssh2", "src_ip": "45.137.21.9", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-14T04:36:46", "source": "nginx", "category": "benign", "severity": "info", "message": "166.139.105.48 - - \"GET / HTTP/1.1\" 200 1510", "src_ip": "166.139.105.48", "status": 200, "path": "/"} {"timestamp": "2026-06-14T04:37:19", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 403 449", "src_ip": "185.220.101.34", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T04:40:54", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.181 dst=185.220.101.34 bytes=3356491776 proto=TCP dport=443 duration=460s", "src_ip": "10.0.1.181", "dst_ip": "185.220.101.34", "bytes_mb": 3201, "off_hours": true} {"timestamp": "2026-06-14T04:44:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=162.100.222.198 OUT= PROTO=TCP DPT=80", "src_ip": "162.100.222.198", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T04:49:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=60.127.179.19 OUT= PROTO=TCP DPT=80", "src_ip": "60.127.179.19", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T04:52:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=23.44.155.171 OUT= PROTO=TCP DPT=443", "src_ip": "23.44.155.171", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T04:56:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.102 port 41690 ssh2", "src_ip": "10.0.5.102", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T04:56:39", "source": "nginx", "category": "benign", "severity": "info", "message": "137.193.180.197 - - \"GET /api/products HTTP/1.1\" 200 2825", "src_ip": "137.193.180.197", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T05:03:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T05:03:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T05:03:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T05:03:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T05:03:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T05:03:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T05:03:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T05:03:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T05:05:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.163 port 54609 ssh2", "src_ip": "10.0.4.163", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T05:08:45", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "nattapong", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-14T05:12:41", "source": "nginx", "category": "benign", "severity": "info", "message": "87.58.218.3 - - \"GET /login HTTP/1.1\" 200 1794", "src_ip": "87.58.218.3", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T05:14:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=104.127.59.236 OUT= PROTO=TCP DPT=443", "src_ip": "104.127.59.236", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T05:17:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=197.105.48.114 OUT= PROTO=TCP DPT=80", "src_ip": "197.105.48.114", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T05:17:41", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "svc_backup", "host": "app-02", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-14T05:22:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=46.44.195.134 OUT= PROTO=TCP DPT=80", "src_ip": "46.44.195.134", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T05:23:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.185 port 51073 ssh2", "src_ip": "10.0.1.185", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T05:24:03", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "guest", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-14T05:24:27", "source": "nginx", "category": "benign", "severity": "info", "message": "88.46.120.77 - - \"GET /login HTTP/1.1\" 200 7240", "src_ip": "88.46.120.77", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T05:30:57", "source": "nginx", "category": "benign", "severity": "info", "message": "73.109.79.48 - - \"GET /health HTTP/1.1\" 200 6412", "src_ip": "73.109.79.48", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T05:31:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=51.9.177.176 OUT= PROTO=TCP DPT=443", "src_ip": "51.9.177.176", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T05:33:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=209.106.19.35 OUT= PROTO=TCP DPT=80", "src_ip": "209.106.19.35", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T05:34:21", "source": "nginx", "category": "benign", "severity": "info", "message": "12.206.28.248 - - \"GET /dashboard HTTP/1.1\" 200 3096", "src_ip": "12.206.28.248", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T05:35:47", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 500 358", "src_ip": "209.141.56.12", "status": 500, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T05:37:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=209.89.234.250 OUT= PROTO=TCP DPT=80", "src_ip": "209.89.234.250", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T05:40:13", "source": "nginx", "category": "benign", "severity": "info", "message": "158.254.90.126 - - \"GET /dashboard HTTP/1.1\" 200 3978", "src_ip": "158.254.90.126", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T05:41:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.248 port 55458 ssh2", "src_ip": "10.0.3.248", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T05:44:02", "source": "nginx", "category": "benign", "severity": "info", "message": "201.19.126.56 - - \"GET /health HTTP/1.1\" 200 7221", "src_ip": "201.19.126.56", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T05:46:34", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.132 dst=91.219.236.18 bytes=3891265536 proto=TCP dport=443 duration=488s", "src_ip": "10.0.0.132", "dst_ip": "91.219.236.18", "bytes_mb": 3711, "off_hours": true} {"timestamp": "2026-06-14T05:52:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.149 port 47901 ssh2", "src_ip": "10.0.0.149", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-14T05:52:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.33 port 54902 ssh2", "src_ip": "10.0.4.33", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T05:56:02", "source": "nginx", "category": "benign", "severity": "info", "message": "160.255.216.113 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7827", "src_ip": "160.255.216.113", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T05:56:32", "source": "nginx", "category": "benign", "severity": "info", "message": "188.52.86.17 - - \"GET /api/products HTTP/1.1\" 200 1830", "src_ip": "188.52.86.17", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T05:58:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.169 port 55634 ssh2", "src_ip": "10.0.1.169", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T05:59:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T05:59:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T05:59:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T05:59:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T05:59:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T05:59:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T05:59:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T05:59:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T05:59:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T05:59:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T05:59:18", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T05:59:47", "source": "nginx", "category": "benign", "severity": "info", "message": "33.64.69.4 - - \"GET /login HTTP/1.1\" 200 1116", "src_ip": "33.64.69.4", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T06:02:52", "source": "nginx", "category": "benign", "severity": "info", "message": "54.95.0.119 - - \"GET /api/products HTTP/1.1\" 200 4957", "src_ip": "54.95.0.119", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T06:07:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.58 port 44607 ssh2", "src_ip": "10.0.5.58", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T06:08:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.171 port 47306 ssh2", "src_ip": "10.0.1.171", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T06:09:02", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 110", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T06:13:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.82 port 42377 ssh2", "src_ip": "10.0.3.82", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T06:13:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=250 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:18:43", "source": "nginx", "category": "benign", "severity": "info", "message": "193.253.65.51 - - \"GET /health HTTP/1.1\" 200 848", "src_ip": "193.253.65.51", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T06:18:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=820 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:23:33", "source": "nginx", "category": "benign", "severity": "info", "message": "16.1.234.79 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5768", "src_ip": "16.1.234.79", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T06:23:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=708 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:26:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=52.235.205.45 OUT= PROTO=TCP DPT=80", "src_ip": "52.235.205.45", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T06:27:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.201 port 41557 ssh2", "src_ip": "10.0.5.201", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T06:28:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=493 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:33:49", "source": "nginx", "category": "benign", "severity": "info", "message": "62.205.168.17 - - \"GET /api/products HTTP/1.1\" 200 3005", "src_ip": "62.205.168.17", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T06:33:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=435 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:34:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=223.77.214.3 OUT= PROTO=TCP DPT=80", "src_ip": "223.77.214.3", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T06:34:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=133.175.13.151 OUT= PROTO=TCP DPT=80", "src_ip": "133.175.13.151", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T06:36:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.154 port 40534 ssh2", "src_ip": "10.0.2.154", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T06:36:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.200.237.245 OUT= PROTO=TCP DPT=80", "src_ip": "47.200.237.245", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T06:38:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=821 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:42:57", "source": "nginx", "category": "benign", "severity": "info", "message": "136.135.46.165 - - \"GET /static/app.js HTTP/1.1\" 200 3374", "src_ip": "136.135.46.165", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T06:43:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=560 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:44:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.120 port 59713 ssh2", "src_ip": "10.0.0.120", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T06:47:00", "source": "nginx", "category": "benign", "severity": "info", "message": "77.31.80.226 - - \"GET /api/products HTTP/1.1\" 200 5244", "src_ip": "77.31.80.226", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T06:48:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=424 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:51:10", "source": "nginx", "category": "benign", "severity": "info", "message": "21.80.144.78 - - \"GET / HTTP/1.1\" 200 2084", "src_ip": "21.80.144.78", "status": 200, "path": "/"} {"timestamp": "2026-06-14T06:51:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=46.174.87.103 OUT= PROTO=TCP DPT=80", "src_ip": "46.174.87.103", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T06:53:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=851 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T06:54:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.53 port 53163 ssh2", "src_ip": "10.0.1.53", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T06:58:55", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.146 dst=185.220.101.34 dport=443 bytes=394 interval=300s", "src_ip": "10.0.0.146", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-14T07:03:29", "source": "nginx", "category": "benign", "severity": "info", "message": "109.52.72.180 - - \"GET / HTTP/1.1\" 200 7493", "src_ip": "109.52.72.180", "status": 200, "path": "/"} {"timestamp": "2026-06-14T07:07:16", "source": "nginx", "category": "benign", "severity": "info", "message": "56.122.204.23 - - \"GET / HTTP/1.1\" 200 7182", "src_ip": "56.122.204.23", "status": 200, "path": "/"} {"timestamp": "2026-06-14T07:14:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=109.87.181.148 OUT= PROTO=TCP DPT=80", "src_ip": "109.87.181.148", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T07:16:10", "source": "nginx", "category": "benign", "severity": "info", "message": "149.42.72.208 - - \"GET /static/app.js HTTP/1.1\" 200 1296", "src_ip": "149.42.72.208", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T07:22:27", "source": "nginx", "category": "benign", "severity": "info", "message": "208.152.226.110 - - \"GET /health HTTP/1.1\" 200 240", "src_ip": "208.152.226.110", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T07:23:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=66.39.166.203 OUT= PROTO=TCP DPT=443", "src_ip": "66.39.166.203", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T07:24:01", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 154", "src_ip": "209.141.56.12", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T07:25:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=177.196.75.182 OUT= PROTO=TCP DPT=80", "src_ip": "177.196.75.182", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T07:27:19", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.78 dst=91.219.236.18 bytes=8055160832 proto=TCP dport=443 duration=447s", "src_ip": "10.0.4.78", "dst_ip": "91.219.236.18", "bytes_mb": 7682, "off_hours": false} {"timestamp": "2026-06-14T07:31:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.179 port 56991 ssh2", "src_ip": "10.0.1.179", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T07:35:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=31.202.158.191 OUT= PROTO=TCP DPT=443", "src_ip": "31.202.158.191", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T07:35:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=20.232.45.81 OUT= PROTO=TCP DPT=443", "src_ip": "20.232.45.81", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T07:35:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=24.245.171.174 OUT= PROTO=TCP DPT=443", "src_ip": "24.245.171.174", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T07:43:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 40233 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:43:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=213.18.106.57 OUT= PROTO=TCP DPT=80", "src_ip": "213.18.106.57", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T07:43:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 50940 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:43:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 50543 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:43:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 42960 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:43:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 50954 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:43:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 49564 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:43:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 59162 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:43:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 48071 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:43:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 52306 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-14T07:48:45", "source": "nginx", "category": "benign", "severity": "info", "message": "122.14.251.116 - - \"GET /login HTTP/1.1\" 200 5407", "src_ip": "122.14.251.116", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T07:50:18", "source": "nginx", "category": "benign", "severity": "info", "message": "210.88.255.220 - - \"GET / HTTP/1.1\" 200 2934", "src_ip": "210.88.255.220", "status": 200, "path": "/"} {"timestamp": "2026-06-14T07:50:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=73.70.61.7 OUT= PROTO=TCP DPT=80", "src_ip": "73.70.61.7", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T07:52:47", "source": "nginx", "category": "benign", "severity": "info", "message": "13.53.56.136 - - \"GET /api/products HTTP/1.1\" 200 2347", "src_ip": "13.53.56.136", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T07:55:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=67.228.182.24 OUT= PROTO=TCP DPT=443", "src_ip": "67.228.182.24", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T07:58:19", "source": "nginx", "category": "benign", "severity": "info", "message": "130.177.149.38 - - \"GET /health HTTP/1.1\" 200 5710", "src_ip": "130.177.149.38", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T07:58:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=46.13.62.223 OUT= PROTO=TCP DPT=443", "src_ip": "46.13.62.223", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T08:03:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.237 port 47864 ssh2", "src_ip": "10.0.5.237", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T08:04:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.147 port 52499 ssh2", "src_ip": "10.0.4.147", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T08:04:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.155 port 53586 ssh2", "src_ip": "10.0.1.155", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T08:06:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 53389 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 49720 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 54138 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 45894 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 58062 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 42490 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 46709 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 48493 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 57639 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 43181 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 56854 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:06:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 122.125.237.172 port 43505 ssh2", "src_ip": "122.125.237.172", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T08:07:44", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 298", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T08:09:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=44.233.105.47 OUT= PROTO=TCP DPT=80", "src_ip": "44.233.105.47", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T08:16:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.144 port 56914 ssh2", "src_ip": "10.0.1.144", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T08:17:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 49794 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:17:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 43508 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:17:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 58788 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 45018 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 42801 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 53394 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 57390 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 45031 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 56289 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 50517 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 51941 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 41395 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 47127 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:18:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 48057 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T08:23:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.132 port 56373 ssh2", "src_ip": "10.0.1.132", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-14T08:24:20", "source": "nginx", "category": "benign", "severity": "info", "message": "154.103.39.152 - - \"GET /login HTTP/1.1\" 200 1043", "src_ip": "154.103.39.152", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T08:25:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=92.195.144.115 OUT= PROTO=TCP DPT=80", "src_ip": "92.195.144.115", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T08:30:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.8 port 45380 ssh2", "src_ip": "10.0.2.8", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T08:36:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.209 port 50892 ssh2", "src_ip": "10.0.5.209", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T08:40:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=222.0.236.106 OUT= PROTO=TCP DPT=80", "src_ip": "222.0.236.106", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T08:40:35", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/bash", "user": "deploy", "host": "web-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-14T08:42:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.236 port 55742 ssh2", "src_ip": "10.0.0.236", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T08:42:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.187 port 56354 ssh2", "src_ip": "10.0.3.187", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T08:45:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 54911 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 46716 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 49875 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 57396 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 47471 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 54183 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.2.34 port 58831 ssh2", "src_ip": "10.0.2.34", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T08:45:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48811 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 56958 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 46431 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 55153 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 43856 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 49330 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48595 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 46052 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 40237 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 58156 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 44236 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48051 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:45:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 41892 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:46:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 40324 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:46:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 48023 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:46:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 52778 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:46:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=116.147.137.64 OUT= PROTO=TCP DPT=80", "src_ip": "116.147.137.64", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T08:46:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 42710 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T08:46:54", "source": "nginx", "category": "web_attack", "severity": "high", "message": "111.201.51.57 - - \"GET /search?q= HTTP/1.1\" 403 105", "src_ip": "111.201.51.57", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T08:56:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=201.249.155.159 OUT= PROTO=TCP DPT=443", "src_ip": "201.249.155.159", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T08:59:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.119 port 40505 ssh2", "src_ip": "10.0.4.119", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T09:01:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 52398 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 54953 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 42712 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 55478 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 56962 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 57096 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 40066 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 43800 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 49853 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 44256 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 42121 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 59088 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 58892 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 55359 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 58902 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 43907 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 49096 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 48447 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:01:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 52511 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:02:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 42677 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:02:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 193.27.228.114 port 47900 ssh2", "src_ip": "193.27.228.114", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T09:03:10", "source": "nginx", "category": "benign", "severity": "info", "message": "142.167.44.103 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 981", "src_ip": "142.167.44.103", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T09:06:05", "source": "nginx", "category": "benign", "severity": "info", "message": "65.232.134.140 - - \"GET /dashboard HTTP/1.1\" 200 1165", "src_ip": "65.232.134.140", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T09:11:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T09:11:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T09:11:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T09:11:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T09:11:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T09:11:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T09:11:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T09:11:54", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T09:11:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T09:11:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T09:11:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T09:11:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T09:14:10", "source": "nginx", "category": "benign", "severity": "info", "message": "165.107.243.220 - - \"GET /health HTTP/1.1\" 200 240", "src_ip": "165.107.243.220", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T09:14:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=169.189.119.81 OUT= PROTO=TCP DPT=443", "src_ip": "169.189.119.81", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T09:14:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T09:14:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T09:14:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T09:14:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T09:14:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T09:14:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T09:14:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T09:14:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T09:14:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T09:14:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T09:14:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T09:14:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T09:16:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.142.49.167 OUT= PROTO=TCP DPT=80", "src_ip": "167.142.49.167", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T09:18:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T09:18:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T09:18:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T09:18:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T09:18:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T09:18:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T09:18:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T09:18:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T09:18:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T09:18:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=103.16.58.18 OUT= PROTO=TCP DPT=80", "src_ip": "103.16.58.18", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T09:19:33", "source": "nginx", "category": "benign", "severity": "info", "message": "153.123.243.166 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4220", "src_ip": "153.123.243.166", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T09:19:34", "source": "nginx", "category": "benign", "severity": "info", "message": "169.10.170.217 - - \"GET /login HTTP/1.1\" 200 4075", "src_ip": "169.10.170.217", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T09:22:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 47129 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 51926 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 57127 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 45129 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 58936 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 46942 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49455 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 40772 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49877 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 53929 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 43686 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 50367 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 41535 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 43307 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 57635 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49595 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 42161 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 42335 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 55606 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 42444 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:22:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49528 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:23:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 51951 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:23:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T09:23:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T09:23:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T09:23:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T09:23:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T09:23:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 58024 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-14T09:23:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T09:23:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T09:23:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T09:23:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T09:23:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.232 port 59475 ssh2", "src_ip": "10.0.4.232", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-14T09:33:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 40620 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 42603 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 42771 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 54394 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 49632 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 59696 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 58943 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 42754 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 52690 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 41691 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 53843 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 44830 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 46828 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 51477 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 56505 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 41598 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 53597 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 56047 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:33:45", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for guest from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T09:33:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 52322 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 42408 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 54787 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 50983 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 43022 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53705 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57028 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 41195 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 44220 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 49632 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 46322 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 57047 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 40696 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51839 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 47787 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 52657 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53344 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 52959 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 54266 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:34:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 41404 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:35:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 40588 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:35:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 41519 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:35:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53036 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:35:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 43145 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:35:14", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T09:35:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 42896 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T09:39:17", "source": "nginx", "category": "benign", "severity": "info", "message": "156.6.9.102 - - \"GET /static/app.js HTTP/1.1\" 200 3710", "src_ip": "156.6.9.102", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T09:40:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=160.70.133.204 OUT= PROTO=TCP DPT=443", "src_ip": "160.70.133.204", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T09:41:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T09:41:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T09:41:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T09:41:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T09:41:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T09:41:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T09:41:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T09:41:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T09:41:17", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T09:45:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.3 port 56374 ssh2", "src_ip": "10.0.3.3", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T09:50:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=64.99.69.127 OUT= PROTO=TCP DPT=443", "src_ip": "64.99.69.127", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T09:56:04", "source": "nginx", "category": "benign", "severity": "info", "message": "187.240.149.9 - - \"GET /login HTTP/1.1\" 200 2560", "src_ip": "187.240.149.9", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T09:57:24", "source": "nginx", "category": "benign", "severity": "info", "message": "223.108.167.187 - - \"GET /login HTTP/1.1\" 200 4153", "src_ip": "223.108.167.187", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T10:00:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=139.35.22.11 OUT= PROTO=TCP DPT=443", "src_ip": "139.35.22.11", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T10:05:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 48630 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 48000 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 50929 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 44264 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 48060 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 40441 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 53849 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 48527 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 45907 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 41963 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 54084 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 40947 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 59166 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 42549 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 42578 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:47", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 112.182.76.62 port 51234 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T10:05:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 48045 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:05:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 112.182.76.62 port 51851 ssh2", "src_ip": "112.182.76.62", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T10:06:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=114.210.9.38 OUT= PROTO=TCP DPT=443", "src_ip": "114.210.9.38", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T10:06:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=136.212.227.126 OUT= PROTO=TCP DPT=80", "src_ip": "136.212.227.126", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T10:08:20", "source": "nginx", "category": "benign", "severity": "info", "message": "117.182.48.142 - - \"GET /static/app.js HTTP/1.1\" 200 4578", "src_ip": "117.182.48.142", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T10:09:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=65.116.83.109 OUT= PROTO=TCP DPT=443", "src_ip": "65.116.83.109", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T10:13:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=16.4.242.234 OUT= PROTO=TCP DPT=80", "src_ip": "16.4.242.234", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T10:18:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.139 port 46756 ssh2", "src_ip": "10.0.1.139", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T10:20:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.8.86.186 OUT= PROTO=TCP DPT=443", "src_ip": "147.8.86.186", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T10:24:37", "source": "nginx", "category": "benign", "severity": "info", "message": "31.3.125.226 - - \"GET /static/app.js HTTP/1.1\" 200 2478", "src_ip": "31.3.125.226", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T10:26:30", "source": "nginx", "category": "benign", "severity": "info", "message": "18.13.215.23 - - \"GET /health HTTP/1.1\" 200 1351", "src_ip": "18.13.215.23", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T10:31:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.131 port 42327 ssh2", "src_ip": "10.0.4.131", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T10:37:02", "source": "nginx", "category": "benign", "severity": "info", "message": "51.56.66.138 - - \"GET /dashboard HTTP/1.1\" 200 4117", "src_ip": "51.56.66.138", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T10:44:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.194 port 57849 ssh2", "src_ip": "10.0.5.194", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T10:54:19", "source": "nginx", "category": "benign", "severity": "info", "message": "149.30.139.253 - - \"GET /health HTTP/1.1\" 200 6423", "src_ip": "149.30.139.253", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T10:59:53", "source": "nginx", "category": "benign", "severity": "info", "message": "218.184.80.49 - - \"GET / HTTP/1.1\" 200 6954", "src_ip": "218.184.80.49", "status": 200, "path": "/"} {"timestamp": "2026-06-14T11:00:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.0.161 port 55133 ssh2", "src_ip": "10.0.0.161", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T11:03:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T11:03:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T11:03:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T11:03:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T11:03:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T11:03:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T11:03:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T11:03:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T11:04:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T11:04:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T11:04:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T11:04:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T11:04:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T11:04:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T11:04:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T11:04:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T11:07:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.1.20 port 55433 ssh2", "src_ip": "10.0.1.20", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T11:09:01", "source": "nginx", "category": "benign", "severity": "info", "message": "92.214.35.156 - - \"GET /login HTTP/1.1\" 200 1235", "src_ip": "92.214.35.156", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T11:13:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.139 port 44820 ssh2", "src_ip": "10.0.5.139", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T11:13:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.60 port 50539 ssh2", "src_ip": "10.0.4.60", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T11:17:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=189.250.201.138 OUT= PROTO=TCP DPT=80", "src_ip": "189.250.201.138", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T11:19:06", "source": "nginx", "category": "benign", "severity": "info", "message": "57.129.143.97 - - \"GET /static/app.js HTTP/1.1\" 200 2033", "src_ip": "57.129.143.97", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T11:19:40", "source": "nginx", "category": "benign", "severity": "info", "message": "194.241.51.175 - - \"GET /health HTTP/1.1\" 200 1326", "src_ip": "194.241.51.175", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T11:20:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T11:20:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T11:20:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T11:20:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T11:20:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T11:20:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T11:20:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T11:20:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T11:20:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T11:20:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T11:20:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T11:20:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T11:23:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=103.115.134.105 OUT= PROTO=TCP DPT=80", "src_ip": "103.115.134.105", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T11:24:35", "source": "nginx", "category": "benign", "severity": "info", "message": "104.178.97.83 - - \"GET /api/products HTTP/1.1\" 200 5065", "src_ip": "104.178.97.83", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T11:26:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 57564 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:26:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 58032 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:26:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 57162 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:26:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 42059 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:26:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 59823 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:26:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 46374 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:26:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 46568 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 56415 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 45512 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 55690 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 56056 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48972 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 56258 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 49612 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 46578 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 56147 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 59481 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48645 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48496 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 53903 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 42565 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 50970 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 54563 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 52689 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:27:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48686 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-14T11:28:46", "source": "nginx", "category": "benign", "severity": "info", "message": "97.11.214.196 - - \"GET /login HTTP/1.1\" 200 2252", "src_ip": "97.11.214.196", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T11:31:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T11:31:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T11:31:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T11:31:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T11:31:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T11:31:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T11:31:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T11:31:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T11:31:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T11:31:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T11:31:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T11:31:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T11:37:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=44.140.136.119 OUT= PROTO=TCP DPT=443", "src_ip": "44.140.136.119", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T11:40:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.199 port 54762 ssh2", "src_ip": "10.0.0.199", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T11:42:35", "source": "nginx", "category": "benign", "severity": "info", "message": "141.27.182.195 - - \"GET / HTTP/1.1\" 200 2670", "src_ip": "141.27.182.195", "status": 200, "path": "/"} {"timestamp": "2026-06-14T11:44:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=72.2.212.9 OUT= PROTO=TCP DPT=80", "src_ip": "72.2.212.9", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T11:47:30", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=219.147.12.59 OUT= PROTO=TCP DPT=443", "src_ip": "219.147.12.59", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T11:49:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.216 port 59568 ssh2", "src_ip": "10.0.1.216", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T11:55:47", "source": "nginx", "category": "benign", "severity": "info", "message": "136.81.104.184 - - \"GET /static/app.js HTTP/1.1\" 200 3994", "src_ip": "136.81.104.184", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T12:01:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 44615 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 49194 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 45013 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 59089 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 55263 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 49899 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 50437 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 45084 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 42938 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 49373 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 57582 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 45307 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 55967 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 46170 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 41537 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 53832 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 51086 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:01:56", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for guest from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T12:02:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 59972 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-14T12:06:18", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 499", "src_ip": "45.137.21.9", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T12:06:33", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 200 392", "src_ip": "193.27.228.114", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T12:06:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.238 port 54649 ssh2", "src_ip": "10.0.1.238", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T12:12:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=62.154.156.22 OUT= PROTO=TCP DPT=443", "src_ip": "62.154.156.22", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T12:16:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.251 port 51816 ssh2", "src_ip": "10.0.4.251", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-14T12:22:57", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.131 dst=193.27.228.114 bytes=1615855616 proto=TCP dport=443 duration=556s", "src_ip": "10.0.1.131", "dst_ip": "193.27.228.114", "bytes_mb": 1541, "off_hours": false} {"timestamp": "2026-06-14T12:25:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.78 port 41167 ssh2", "src_ip": "10.0.2.78", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T12:36:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.193 port 47074 ssh2", "src_ip": "10.0.1.193", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T12:40:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.34 port 44761 ssh2", "src_ip": "10.0.4.34", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T12:41:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.224 port 44253 ssh2", "src_ip": "10.0.3.224", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T12:46:30", "source": "nginx", "category": "benign", "severity": "info", "message": "59.14.114.36 - - \"GET /static/app.js HTTP/1.1\" 200 5278", "src_ip": "59.14.114.36", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T12:48:55", "source": "nginx", "category": "benign", "severity": "info", "message": "147.40.178.54 - - \"GET /static/app.js HTTP/1.1\" 200 7864", "src_ip": "147.40.178.54", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T12:56:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.238 port 57616 ssh2", "src_ip": "10.0.1.238", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T12:59:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.126.153.90 OUT= PROTO=TCP DPT=443", "src_ip": "147.126.153.90", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T13:09:53", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 244", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T13:12:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=16.207.207.67 OUT= PROTO=TCP DPT=80", "src_ip": "16.207.207.67", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T13:13:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=44.188.220.55 OUT= PROTO=TCP DPT=80", "src_ip": "44.188.220.55", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T13:16:59", "source": "nginx", "category": "benign", "severity": "info", "message": "36.181.184.243 - - \"GET /api/products HTTP/1.1\" 200 7052", "src_ip": "36.181.184.243", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T13:19:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.155 dst=209.141.56.12 dport=443 bytes=556 interval=60s", "src_ip": "10.0.1.155", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T13:20:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.55 port 48225 ssh2", "src_ip": "10.0.5.55", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T13:20:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.155 dst=209.141.56.12 dport=443 bytes=414 interval=60s", "src_ip": "10.0.1.155", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T13:21:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.155 dst=209.141.56.12 dport=443 bytes=395 interval=60s", "src_ip": "10.0.1.155", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T13:22:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.155 dst=209.141.56.12 dport=443 bytes=895 interval=60s", "src_ip": "10.0.1.155", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T13:23:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.155 dst=209.141.56.12 dport=443 bytes=790 interval=60s", "src_ip": "10.0.1.155", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T13:24:49", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.155 dst=209.141.56.12 dport=443 bytes=214 interval=60s", "src_ip": "10.0.1.155", "dst_ip": "209.141.56.12", "beacon_interval": 60} {"timestamp": "2026-06-14T13:27:20", "source": "nginx", "category": "web_attack", "severity": "high", "message": "99.185.41.175 - - \"GET /search?q= HTTP/1.1\" 403 5", "src_ip": "99.185.41.175", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T13:31:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=36.138.70.108 OUT= PROTO=TCP DPT=80", "src_ip": "36.138.70.108", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T13:35:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.142 port 44052 ssh2", "src_ip": "10.0.4.142", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T13:47:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=22.182.125.2 OUT= PROTO=TCP DPT=443", "src_ip": "22.182.125.2", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T13:50:49", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "svc_backup", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-14T13:54:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T13:54:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T13:54:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T13:54:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T13:54:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T13:54:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T13:54:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T13:54:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T13:54:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T13:54:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T13:54:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T13:56:02", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 382", "src_ip": "45.137.21.9", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T13:59:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=142.215.136.6 OUT= PROTO=TCP DPT=443", "src_ip": "142.215.136.6", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T14:07:47", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.164 dst=185.220.101.34 bytes=2036334592 proto=TCP dport=443 duration=145s", "src_ip": "10.0.2.164", "dst_ip": "185.220.101.34", "bytes_mb": 1942, "off_hours": false} {"timestamp": "2026-06-14T14:11:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.20 port 42873 ssh2", "src_ip": "10.0.1.20", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T14:13:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 54083 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:13:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 47552 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:13:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 59780 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:13:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 44971 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:13:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 58143 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:13:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 45630 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:13:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 48740 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:13:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 42987 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:13:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 51585 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:14:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 48067 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:14:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 46656 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:14:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 50378 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:14:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 44081 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:14:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 40571 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:14:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 47240 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:14:19", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 185.220.101.34 port 51234 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T14:14:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 185.220.101.34 port 48838 ssh2", "src_ip": "185.220.101.34", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-14T14:16:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=55.85.177.60 OUT= PROTO=TCP DPT=80", "src_ip": "55.85.177.60", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T14:18:49", "source": "nginx", "category": "benign", "severity": "info", "message": "132.163.77.171 - - \"GET /health HTTP/1.1\" 200 4367", "src_ip": "132.163.77.171", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T14:30:18", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 235", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T14:31:29", "source": "nginx", "category": "web_attack", "severity": "high", "message": "151.228.203.8 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 200 302", "src_ip": "151.228.203.8", "status": 200, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T14:31:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.164.113.210 OUT= PROTO=TCP DPT=80", "src_ip": "167.164.113.210", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T14:40:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=12.255.121.183 OUT= PROTO=TCP DPT=443", "src_ip": "12.255.121.183", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T14:42:08", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.216 dst=193.27.228.114 bytes=7350517760 proto=TCP dport=443 duration=515s", "src_ip": "10.0.4.216", "dst_ip": "193.27.228.114", "bytes_mb": 7010, "off_hours": false} {"timestamp": "2026-06-14T14:46:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T14:46:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T14:46:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T14:46:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T14:46:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T14:46:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T14:46:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T14:46:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T14:46:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T14:50:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.104.36.162 OUT= PROTO=TCP DPT=443", "src_ip": "47.104.36.162", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T14:52:47", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.46 port 44985 ssh2", "src_ip": "10.0.0.46", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T14:54:35", "source": "nginx", "category": "benign", "severity": "info", "message": "148.126.177.143 - - \"GET /api/products HTTP/1.1\" 200 6035", "src_ip": "148.126.177.143", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T14:56:26", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 181", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T14:58:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 50122 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 51519 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 57666 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 55317 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 50483 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 41828 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 42128 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 44398 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 46541 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 50642 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 58936 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 42493 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 52560 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 45868 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 48754 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 42313 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T14:58:37", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for admin from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T14:58:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 45748 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T15:03:23", "source": "nginx", "category": "benign", "severity": "info", "message": "130.221.209.95 - - \"GET /health HTTP/1.1\" 200 4275", "src_ip": "130.221.209.95", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T15:16:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.158 port 51382 ssh2", "src_ip": "10.0.4.158", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T15:20:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.142 port 53158 ssh2", "src_ip": "10.0.1.142", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T15:25:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.218 port 53453 ssh2", "src_ip": "10.0.3.218", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T15:31:40", "source": "nginx", "category": "benign", "severity": "info", "message": "63.71.112.179 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 932", "src_ip": "63.71.112.179", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T15:31:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 48259 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 59708 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 41417 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 55858 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 49859 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 51237 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 52380 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 44130 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 58305 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 50603 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:31:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 52262 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:32:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 50335 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:32:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 45924 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:32:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 59955 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:32:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 59574 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:32:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 55652 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:32:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 45841 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T15:32:21", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 185.220.101.34 port 51234 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T15:41:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T15:41:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T15:41:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T15:41:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T15:41:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T15:41:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T15:41:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T15:41:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T15:41:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T15:41:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T15:41:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T15:43:41", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 334", "src_ip": "209.141.56.12", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-14T15:43:46", "source": "nginx", "category": "benign", "severity": "info", "message": "221.139.229.15 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7479", "src_ip": "221.139.229.15", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T15:45:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=161.244.21.174 OUT= PROTO=TCP DPT=443", "src_ip": "161.244.21.174", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T15:47:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.14 port 48524 ssh2", "src_ip": "10.0.1.14", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T15:48:36", "source": "nginx", "category": "benign", "severity": "info", "message": "185.60.232.123 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 700", "src_ip": "185.60.232.123", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T15:50:56", "source": "nginx", "category": "benign", "severity": "info", "message": "115.234.185.242 - - \"GET / HTTP/1.1\" 200 3825", "src_ip": "115.234.185.242", "status": 200, "path": "/"} {"timestamp": "2026-06-14T15:51:13", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 403 195", "src_ip": "185.220.101.34", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T15:52:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=77.76.45.246 OUT= PROTO=TCP DPT=443", "src_ip": "77.76.45.246", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T15:53:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=51.213.253.56 OUT= PROTO=TCP DPT=443", "src_ip": "51.213.253.56", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T15:55:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T15:55:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T15:55:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T15:55:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T15:55:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T15:55:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T15:55:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T15:55:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T15:55:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T15:55:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T15:55:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T15:55:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T15:56:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=148.214.181.238 OUT= PROTO=TCP DPT=80", "src_ip": "148.214.181.238", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T16:10:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=174.25.152.92 OUT= PROTO=TCP DPT=80", "src_ip": "174.25.152.92", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T16:11:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=114.236.232.104 OUT= PROTO=TCP DPT=80", "src_ip": "114.236.232.104", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T16:12:38", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "postgres", "host": "app-02", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-14T16:16:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.124 port 49340 ssh2", "src_ip": "10.0.0.124", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T16:27:43", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 291", "src_ip": "91.219.236.18", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T16:29:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=113.250.27.254 OUT= PROTO=TCP DPT=443", "src_ip": "113.250.27.254", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T16:34:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.82 port 44083 ssh2", "src_ip": "10.0.4.82", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T16:41:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.221 port 40318 ssh2", "src_ip": "10.0.5.221", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T16:44:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=131.252.52.87 OUT= PROTO=TCP DPT=443", "src_ip": "131.252.52.87", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T16:50:55", "source": "nginx", "category": "benign", "severity": "info", "message": "124.5.99.115 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3452", "src_ip": "124.5.99.115", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T16:53:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=56.236.218.140 OUT= PROTO=TCP DPT=443", "src_ip": "56.236.218.140", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T16:54:11", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/bash", "user": "deploy", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-14T16:56:47", "source": "nginx", "category": "benign", "severity": "info", "message": "144.223.150.33 - - \"GET /health HTTP/1.1\" 200 3825", "src_ip": "144.223.150.33", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T17:00:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=134.90.88.188 OUT= PROTO=TCP DPT=80", "src_ip": "134.90.88.188", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T17:03:53", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.41 dst=185.220.101.34 dport=443 bytes=321 interval=60s", "src_ip": "10.0.0.41", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T17:04:53", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.41 dst=185.220.101.34 dport=443 bytes=229 interval=60s", "src_ip": "10.0.0.41", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T17:05:53", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.41 dst=185.220.101.34 dport=443 bytes=598 interval=60s", "src_ip": "10.0.0.41", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T17:06:17", "source": "nginx", "category": "benign", "severity": "info", "message": "147.211.87.162 - - \"GET / HTTP/1.1\" 200 7943", "src_ip": "147.211.87.162", "status": 200, "path": "/"} {"timestamp": "2026-06-14T17:06:53", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.41 dst=185.220.101.34 dport=443 bytes=440 interval=60s", "src_ip": "10.0.0.41", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T17:07:53", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.41 dst=185.220.101.34 dport=443 bytes=678 interval=60s", "src_ip": "10.0.0.41", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T17:08:53", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.41 dst=185.220.101.34 dport=443 bytes=770 interval=60s", "src_ip": "10.0.0.41", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T17:09:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=58.198.34.105 OUT= PROTO=TCP DPT=443", "src_ip": "58.198.34.105", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T17:10:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.92 port 56795 ssh2", "src_ip": "10.0.2.92", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T17:11:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.197 port 52498 ssh2", "src_ip": "10.0.0.197", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T17:15:24", "source": "nginx", "category": "benign", "severity": "info", "message": "157.64.50.84 - - \"GET / HTTP/1.1\" 200 6047", "src_ip": "157.64.50.84", "status": 200, "path": "/"} {"timestamp": "2026-06-14T17:19:43", "source": "nginx", "category": "benign", "severity": "info", "message": "48.245.47.127 - - \"GET /login HTTP/1.1\" 200 3963", "src_ip": "48.245.47.127", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T17:26:19", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/bin/su -", "user": "svc_backup", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-14T17:28:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=177.207.18.104 OUT= PROTO=TCP DPT=443", "src_ip": "177.207.18.104", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T17:32:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.194 port 48576 ssh2", "src_ip": "10.0.2.194", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T17:34:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=87.207.109.110 OUT= PROTO=TCP DPT=443", "src_ip": "87.207.109.110", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T17:34:19", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.15.57.224 OUT= PROTO=TCP DPT=443", "src_ip": "47.15.57.224", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T17:35:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=94.196.152.41 OUT= PROTO=TCP DPT=80", "src_ip": "94.196.152.41", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T17:42:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.197.228.55 OUT= PROTO=TCP DPT=80", "src_ip": "164.197.228.55", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T17:43:24", "source": "nginx", "category": "benign", "severity": "info", "message": "113.152.229.152 - - \"GET /dashboard HTTP/1.1\" 200 7764", "src_ip": "113.152.229.152", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T17:46:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=100.91.12.222 OUT= PROTO=TCP DPT=443", "src_ip": "100.91.12.222", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T17:49:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.73 port 47354 ssh2", "src_ip": "10.0.3.73", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T17:58:41", "source": "nginx", "category": "benign", "severity": "info", "message": "176.18.103.41 - - \"GET /api/products HTTP/1.1\" 200 1317", "src_ip": "176.18.103.41", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T18:12:53", "source": "nginx", "category": "benign", "severity": "info", "message": "202.95.141.129 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 574", "src_ip": "202.95.141.129", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T18:16:40", "source": "nginx", "category": "benign", "severity": "info", "message": "90.73.100.158 - - \"GET /api/products HTTP/1.1\" 200 283", "src_ip": "90.73.100.158", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T18:20:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.40 port 44187 ssh2", "src_ip": "10.0.2.40", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T18:25:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=111.165.71.154 OUT= PROTO=TCP DPT=443", "src_ip": "111.165.71.154", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T18:27:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.35 port 58150 ssh2", "src_ip": "10.0.0.35", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T18:38:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=13.119.46.39 OUT= PROTO=TCP DPT=80", "src_ip": "13.119.46.39", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T18:42:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.36 port 43275 ssh2", "src_ip": "10.0.0.36", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-14T18:46:06", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/su -", "user": "guest", "host": "db-03", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-14T18:46:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.217 port 48053 ssh2", "src_ip": "10.0.0.217", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T18:48:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.54 port 43855 ssh2", "src_ip": "10.0.3.54", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T18:52:07", "source": "nginx", "category": "benign", "severity": "info", "message": "198.59.212.193 - - \"GET /login HTTP/1.1\" 200 7134", "src_ip": "198.59.212.193", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T18:53:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=136.166.234.228 OUT= PROTO=TCP DPT=80", "src_ip": "136.166.234.228", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T18:55:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.2.193 port 54220 ssh2", "src_ip": "10.0.2.193", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T18:58:10", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 403", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T18:59:22", "source": "nginx", "category": "benign", "severity": "info", "message": "134.237.104.88 - - \"GET /static/app.js HTTP/1.1\" 200 1376", "src_ip": "134.237.104.88", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T19:03:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=195.136.73.37 OUT= PROTO=TCP DPT=80", "src_ip": "195.136.73.37", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T19:04:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.91 port 56700 ssh2", "src_ip": "10.0.5.91", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T19:06:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=56.251.34.138 OUT= PROTO=TCP DPT=443", "src_ip": "56.251.34.138", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T19:14:22", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.177 port 52249 ssh2", "src_ip": "10.0.1.177", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T19:16:13", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 200 490", "src_ip": "193.27.228.114", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T19:17:05", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/bash", "user": "deploy", "host": "app-02", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-14T19:24:25", "source": "nginx", "category": "benign", "severity": "info", "message": "118.77.211.177 - - \"GET /login HTTP/1.1\" 200 3561", "src_ip": "118.77.211.177", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T19:28:55", "source": "nginx", "category": "benign", "severity": "info", "message": "128.220.62.169 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7419", "src_ip": "128.220.62.169", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T19:29:42", "source": "nginx", "category": "benign", "severity": "info", "message": "105.50.25.167 - - \"GET /dashboard HTTP/1.1\" 200 6196", "src_ip": "105.50.25.167", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T19:30:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=162.55.49.231 OUT= PROTO=TCP DPT=80", "src_ip": "162.55.49.231", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T19:30:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.136 port 54042 ssh2", "src_ip": "10.0.2.136", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-14T19:40:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=144.175.88.182 OUT= PROTO=TCP DPT=443", "src_ip": "144.175.88.182", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T19:44:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=88.140.28.91 OUT= PROTO=TCP DPT=80", "src_ip": "88.140.28.91", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T19:47:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=211.167.47.175 OUT= PROTO=TCP DPT=443", "src_ip": "211.167.47.175", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T19:47:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.164 port 57915 ssh2", "src_ip": "10.0.5.164", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-14T19:49:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=185.182.33.112 OUT= PROTO=TCP DPT=80", "src_ip": "185.182.33.112", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T19:57:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.94 port 41715 ssh2", "src_ip": "10.0.4.94", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T19:59:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.141 port 59771 ssh2", "src_ip": "10.0.4.141", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T20:00:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=195.43.220.110 OUT= PROTO=TCP DPT=80", "src_ip": "195.43.220.110", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T20:00:48", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 383", "src_ip": "45.137.21.9", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T20:05:24", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 492", "src_ip": "45.137.21.9", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T20:06:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.33 port 41399 ssh2", "src_ip": "10.0.2.33", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-14T20:11:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=95.68.142.82 OUT= PROTO=TCP DPT=80", "src_ip": "95.68.142.82", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T20:12:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.192 port 42406 ssh2", "src_ip": "10.0.3.192", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T20:17:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=159.16.148.219 OUT= PROTO=TCP DPT=443", "src_ip": "159.16.148.219", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T20:19:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=125.45.255.115 OUT= PROTO=TCP DPT=443", "src_ip": "125.45.255.115", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T20:22:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=87.69.11.114 OUT= PROTO=TCP DPT=443", "src_ip": "87.69.11.114", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T20:24:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.162 port 59256 ssh2", "src_ip": "10.0.4.162", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T20:24:33", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "somchai", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-14T20:27:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 54281 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 51722 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 59125 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55385 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 44771 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:14", "source": "nginx", "category": "benign", "severity": "info", "message": "72.206.7.82 - - \"GET /health HTTP/1.1\" 200 2919", "src_ip": "72.206.7.82", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T20:27:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 59769 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 47778 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 49537 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 53830 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 40264 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 46594 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 51191 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55588 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 59216 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 46403 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 44738 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 58332 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T20:27:55", "source": "nginx", "category": "benign", "severity": "info", "message": "212.230.132.146 - - \"GET /api/products HTTP/1.1\" 200 5069", "src_ip": "212.230.132.146", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T20:28:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.253 port 52036 ssh2", "src_ip": "10.0.0.253", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T20:32:37", "source": "nginx", "category": "benign", "severity": "info", "message": "100.194.163.150 - - \"GET / HTTP/1.1\" 200 4143", "src_ip": "100.194.163.150", "status": 200, "path": "/"} {"timestamp": "2026-06-14T20:34:01", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 402", "src_ip": "209.141.56.12", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T20:34:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=258 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:35:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=513 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:36:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=708 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:37:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=614 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:38:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=378 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:39:22", "source": "nginx", "category": "benign", "severity": "info", "message": "33.223.130.90 - - \"GET /login HTTP/1.1\" 200 2404", "src_ip": "33.223.130.90", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T20:39:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=548 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:40:30", "source": "nginx", "category": "benign", "severity": "info", "message": "30.156.97.176 - - \"GET /login HTTP/1.1\" 200 5874", "src_ip": "30.156.97.176", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T20:40:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=892 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:41:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=403 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:41:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=182.44.201.50 OUT= PROTO=TCP DPT=443", "src_ip": "182.44.201.50", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T20:42:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=810 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:43:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.91 dst=185.220.101.34 dport=443 bytes=572 interval=60s", "src_ip": "10.0.1.91", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-14T20:50:07", "source": "nginx", "category": "benign", "severity": "info", "message": "67.145.128.50 - - \"GET / HTTP/1.1\" 200 394", "src_ip": "67.145.128.50", "status": 200, "path": "/"} {"timestamp": "2026-06-14T20:51:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.160 port 48053 ssh2", "src_ip": "10.0.4.160", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T20:52:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.62 port 43327 ssh2", "src_ip": "10.0.3.62", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T20:59:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T20:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T20:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T20:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T20:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T20:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T20:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T20:59:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T21:01:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 41705 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 52750 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 44762 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 40173 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 48620 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 52151 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 59668 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 59956 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 52593 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 42888 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 45743 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 56978 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 59644 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 57072 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 59577 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:54", "source": "nginx", "category": "benign", "severity": "info", "message": "97.89.148.78 - - \"GET / HTTP/1.1\" 200 6772", "src_ip": "97.89.148.78", "status": 200, "path": "/"} {"timestamp": "2026-06-14T21:01:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 42845 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:01:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 40350 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:02:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 46381 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:02:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 56199 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:02:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 47839 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:02:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 56902 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:02:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 47591 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:02:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 45553 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:02:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 41181 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:02:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 185.220.101.34 port 40009 ssh2", "src_ip": "185.220.101.34", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:05:19", "source": "nginx", "category": "benign", "severity": "info", "message": "113.101.105.198 - - \"GET /dashboard HTTP/1.1\" 200 5035", "src_ip": "113.101.105.198", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T21:13:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=157.101.240.132 OUT= PROTO=TCP DPT=443", "src_ip": "157.101.240.132", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T21:18:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=54.32.108.136 OUT= PROTO=TCP DPT=443", "src_ip": "54.32.108.136", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T21:28:28", "source": "nginx", "category": "benign", "severity": "info", "message": "170.50.67.47 - - \"GET /dashboard HTTP/1.1\" 200 3856", "src_ip": "170.50.67.47", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T21:29:29", "source": "nginx", "category": "benign", "severity": "info", "message": "76.93.203.110 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5589", "src_ip": "76.93.203.110", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T21:29:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.131 port 59437 ssh2", "src_ip": "10.0.4.131", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-14T21:37:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=205.5.84.92 OUT= PROTO=TCP DPT=443", "src_ip": "205.5.84.92", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T21:43:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.203 port 55152 ssh2", "src_ip": "10.0.0.203", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T21:43:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 40637 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 43016 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 58527 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 56124 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 48635 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 41562 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 53018 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 55536 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 46502 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 59719 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 42200 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:44:23", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for oppa from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T21:44:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 193.27.228.114 port 57482 ssh2", "src_ip": "193.27.228.114", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-14T21:48:21", "source": "nginx", "category": "benign", "severity": "info", "message": "138.230.122.96 - - \"GET /health HTTP/1.1\" 200 5231", "src_ip": "138.230.122.96", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T21:51:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 49972 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 54126 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 51504 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 49950 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 42929 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 53178 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 59910 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 59286 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.75 port 40109 ssh2", "src_ip": "10.0.3.75", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T21:51:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 41599 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:51:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 45.137.21.9 port 54381 ssh2", "src_ip": "45.137.21.9", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-14T21:52:28", "source": "nginx", "category": "benign", "severity": "info", "message": "45.102.100.65 - - \"GET /dashboard HTTP/1.1\" 200 3784", "src_ip": "45.102.100.65", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T21:56:38", "source": "nginx", "category": "benign", "severity": "info", "message": "17.65.64.138 - - \"GET /dashboard HTTP/1.1\" 200 2564", "src_ip": "17.65.64.138", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T21:56:43", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "guest", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-14T21:57:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=36.211.231.111 OUT= PROTO=TCP DPT=443", "src_ip": "36.211.231.111", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T22:00:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.149 dst=45.137.21.9 dport=443 bytes=688 interval=300s", "src_ip": "10.0.2.149", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-14T22:05:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.149 dst=45.137.21.9 dport=443 bytes=799 interval=300s", "src_ip": "10.0.2.149", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-14T22:08:33", "source": "nginx", "category": "benign", "severity": "info", "message": "200.83.70.233 - - \"GET /login HTTP/1.1\" 200 6889", "src_ip": "200.83.70.233", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T22:10:10", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.253 dst=45.137.21.9 bytes=6659506176 proto=TCP dport=443 duration=146s", "src_ip": "10.0.2.253", "dst_ip": "45.137.21.9", "bytes_mb": 6351, "off_hours": false} {"timestamp": "2026-06-14T22:10:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.149 dst=45.137.21.9 dport=443 bytes=548 interval=300s", "src_ip": "10.0.2.149", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-14T22:12:19", "source": "nginx", "category": "benign", "severity": "info", "message": "168.156.78.145 - - \"GET /static/app.js HTTP/1.1\" 200 3185", "src_ip": "168.156.78.145", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T22:15:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=78.18.46.247 OUT= PROTO=TCP DPT=80", "src_ip": "78.18.46.247", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T22:15:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.149 dst=45.137.21.9 dport=443 bytes=717 interval=300s", "src_ip": "10.0.2.149", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-14T22:16:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.2.4 port 45854 ssh2", "src_ip": "10.0.2.4", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T22:20:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.149 dst=45.137.21.9 dport=443 bytes=365 interval=300s", "src_ip": "10.0.2.149", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-14T22:23:36", "source": "nginx", "category": "benign", "severity": "info", "message": "42.238.62.124 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5232", "src_ip": "42.238.62.124", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T22:23:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=90.130.85.89 OUT= PROTO=TCP DPT=80", "src_ip": "90.130.85.89", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T22:24:48", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/bin/su -", "user": "www-data", "host": "bastion-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-14T22:25:23", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.149 dst=45.137.21.9 dport=443 bytes=807 interval=300s", "src_ip": "10.0.2.149", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-14T22:27:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 40767 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 58233 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 52297 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 56081 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 43177 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 43625 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 59894 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 45213 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 44315 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 47153 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 53237 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 47135 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 49481 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 59636 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 50466 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 43461 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 53143 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:27:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 53386 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:28:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 50412 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:28:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 57551 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:28:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 185.220.101.34 port 52850 ssh2", "src_ip": "185.220.101.34", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 41424 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:09", "source": "nginx", "category": "benign", "severity": "info", "message": "222.21.125.133 - - \"GET /static/app.js HTTP/1.1\" 200 3440", "src_ip": "222.21.125.133", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T22:29:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 43351 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 45439 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 42275 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 45888 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 40392 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 58976 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 53190 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 55984 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 41423 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 57768 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 40485 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 45245 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49024 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 41102 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 46347 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 42716 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 58131 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 44605 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 52809 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 58247 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:29:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49926 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:30:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 50582 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:30:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 185.220.101.34 port 49235 ssh2", "src_ip": "185.220.101.34", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T22:31:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 44989 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:31:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 44167 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:31:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 54021 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 52489 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 55191 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 52216 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 49296 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 41654 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 57332 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 53458 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 52577 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 42414 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 46094 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 50171 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 55879 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 46046 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 45707 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 53046 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:37", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for deploy from 74.189.141.241 port 51234 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-14T22:32:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 57184 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:32:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 74.189.141.241 port 44220 ssh2", "src_ip": "74.189.141.241", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-14T22:34:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.214 port 49406 ssh2", "src_ip": "10.0.2.214", "user": "root", "action": "login_success"} {"timestamp": "2026-06-14T22:34:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T22:34:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T22:34:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T22:34:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T22:34:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T22:34:30", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T22:34:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T22:34:31", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T22:34:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T22:34:42", "source": "nginx", "category": "benign", "severity": "info", "message": "133.242.159.103 - - \"GET /login HTTP/1.1\" 200 6457", "src_ip": "133.242.159.103", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T22:35:12", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 403 331", "src_ip": "185.220.101.34", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-14T22:36:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=138.252.139.96 OUT= PROTO=TCP DPT=80", "src_ip": "138.252.139.96", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T22:39:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.58 port 44731 ssh2", "src_ip": "10.0.1.58", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-14T22:41:34", "source": "nginx", "category": "benign", "severity": "info", "message": "209.211.26.52 - - \"GET /login HTTP/1.1\" 200 2966", "src_ip": "209.211.26.52", "status": 200, "path": "/login"} {"timestamp": "2026-06-14T22:55:14", "source": "nginx", "category": "benign", "severity": "info", "message": "198.66.108.221 - - \"GET / HTTP/1.1\" 200 6766", "src_ip": "198.66.108.221", "status": 200, "path": "/"} {"timestamp": "2026-06-14T22:55:21", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.208 dst=185.220.101.34 bytes=1946157056 proto=TCP dport=443 duration=472s", "src_ip": "10.0.4.208", "dst_ip": "185.220.101.34", "bytes_mb": 1856, "off_hours": false} {"timestamp": "2026-06-14T22:56:02", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/bash", "user": "somchai", "host": "web-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-14T22:58:24", "source": "nginx", "category": "benign", "severity": "info", "message": "28.159.154.38 - - \"GET /dashboard HTTP/1.1\" 200 4322", "src_ip": "28.159.154.38", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-14T23:03:29", "source": "nginx", "category": "benign", "severity": "info", "message": "179.123.52.101 - - \"GET / HTTP/1.1\" 200 4700", "src_ip": "179.123.52.101", "status": 200, "path": "/"} {"timestamp": "2026-06-14T23:05:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T23:05:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-14T23:05:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T23:05:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T23:05:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T23:05:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T23:05:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T23:05:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-14T23:05:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=222.253.60.58 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "222.253.60.58", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T23:06:29", "source": "nginx", "category": "benign", "severity": "info", "message": "89.128.118.31 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1777", "src_ip": "89.128.118.31", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-14T23:11:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 43760 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 47366 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 41954 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 50079 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 44882 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 44660 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 55358 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 54390 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 58651 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 56399 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=79.2.168.249 OUT= PROTO=TCP DPT=80", "src_ip": "79.2.168.249", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T23:11:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 42635 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 49964 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:11:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 53189 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:12:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 186.119.135.202 port 56180 ssh2", "src_ip": "186.119.135.202", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-14T23:14:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.215 port 44067 ssh2", "src_ip": "10.0.4.215", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-14T23:16:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=193.132.156.182 OUT= PROTO=TCP DPT=80", "src_ip": "193.132.156.182", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T23:21:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=108.58.100.220 OUT= PROTO=TCP DPT=443", "src_ip": "108.58.100.220", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T23:22:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.4.4 port 45630 ssh2", "src_ip": "10.0.4.4", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-14T23:23:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.247 port 53163 ssh2", "src_ip": "10.0.5.247", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T23:23:28", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.56 dst=45.137.21.9 bytes=6035603456 proto=TCP dport=443 duration=81s", "src_ip": "10.0.5.56", "dst_ip": "45.137.21.9", "bytes_mb": 5756, "off_hours": true} {"timestamp": "2026-06-14T23:25:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=183.81.75.5 OUT= PROTO=TCP DPT=443", "src_ip": "183.81.75.5", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T23:25:38", "source": "nginx", "category": "benign", "severity": "info", "message": "208.70.207.48 - - \"GET /health HTTP/1.1\" 200 7339", "src_ip": "208.70.207.48", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T23:28:33", "source": "nginx", "category": "benign", "severity": "info", "message": "119.249.79.49 - - \"GET /api/products HTTP/1.1\" 200 1983", "src_ip": "119.249.79.49", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T23:28:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=213.177.147.29 OUT= PROTO=TCP DPT=80", "src_ip": "213.177.147.29", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T23:29:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=173.119.40.164 OUT= PROTO=TCP DPT=443", "src_ip": "173.119.40.164", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T23:32:56", "source": "nginx", "category": "benign", "severity": "info", "message": "86.20.193.135 - - \"GET /health HTTP/1.1\" 200 2121", "src_ip": "86.20.193.135", "status": 200, "path": "/health"} {"timestamp": "2026-06-14T23:34:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=126.139.251.49 OUT= PROTO=TCP DPT=443", "src_ip": "126.139.251.49", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-14T23:40:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.5.142 port 48259 ssh2", "src_ip": "10.0.5.142", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-14T23:40:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=63.112.163.74 OUT= PROTO=TCP DPT=80", "src_ip": "63.112.163.74", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-14T23:41:57", "source": "nginx", "category": "benign", "severity": "info", "message": "97.102.235.29 - - \"GET /api/products HTTP/1.1\" 200 3861", "src_ip": "97.102.235.29", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-14T23:44:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.176 port 58894 ssh2", "src_ip": "10.0.3.176", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-14T23:45:51", "source": "nginx", "category": "benign", "severity": "info", "message": "116.180.180.213 - - \"GET /static/app.js HTTP/1.1\" 200 3688", "src_ip": "116.180.180.213", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-14T23:49:39", "source": "nginx", "category": "web_attack", "severity": "high", "message": "123.191.239.11 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 192", "src_ip": "123.191.239.11", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-14T23:53:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-14T23:53:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-14T23:53:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-14T23:53:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-14T23:53:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-14T23:53:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-14T23:53:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-14T23:53:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-14T23:53:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-14T23:53:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-14T23:55:18", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.144 dst=185.220.101.34 bytes=7309623296 proto=TCP dport=443 duration=521s", "src_ip": "10.0.4.144", "dst_ip": "185.220.101.34", "bytes_mb": 6971, "off_hours": true} {"timestamp": "2026-06-14T23:55:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=202.222.158.233 OUT= PROTO=TCP DPT=443", "src_ip": "202.222.158.233", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T00:05:02", "source": "nginx", "category": "benign", "severity": "info", "message": "164.243.83.234 - - \"GET / HTTP/1.1\" 200 3332", "src_ip": "164.243.83.234", "status": 200, "path": "/"} {"timestamp": "2026-06-15T00:07:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.92 port 41594 ssh2", "src_ip": "10.0.4.92", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T00:10:09", "source": "nginx", "category": "benign", "severity": "info", "message": "73.116.90.217 - - \"GET /static/app.js HTTP/1.1\" 200 7487", "src_ip": "73.116.90.217", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T00:15:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.13 port 46536 ssh2", "src_ip": "10.0.1.13", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T00:16:38", "source": "nginx", "category": "benign", "severity": "info", "message": "39.75.63.90 - - \"GET / HTTP/1.1\" 200 1868", "src_ip": "39.75.63.90", "status": 200, "path": "/"} {"timestamp": "2026-06-15T00:18:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.93 port 45866 ssh2", "src_ip": "10.0.0.93", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T00:19:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.5.233 port 40592 ssh2", "src_ip": "10.0.5.233", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T00:20:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=193.11.20.64 OUT= PROTO=TCP DPT=443", "src_ip": "193.11.20.64", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T00:21:23", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=169.124.234.11 OUT= PROTO=TCP DPT=80", "src_ip": "169.124.234.11", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T00:22:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T00:22:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T00:22:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T00:22:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T00:22:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T00:22:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T00:22:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T00:22:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T00:22:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=57.221.156.58 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "57.221.156.58", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T00:22:16", "source": "nginx", "category": "benign", "severity": "info", "message": "101.25.100.11 - - \"GET /static/app.js HTTP/1.1\" 200 5436", "src_ip": "101.25.100.11", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T00:22:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=31.170.16.34 OUT= PROTO=TCP DPT=80", "src_ip": "31.170.16.34", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T00:22:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.74 port 40581 ssh2", "src_ip": "10.0.3.74", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T00:26:57", "source": "nginx", "category": "benign", "severity": "info", "message": "13.81.183.129 - - \"GET /health HTTP/1.1\" 200 7253", "src_ip": "13.81.183.129", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T00:27:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.169 port 54740 ssh2", "src_ip": "10.0.5.169", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T00:31:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.24 port 51526 ssh2", "src_ip": "10.0.2.24", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T00:31:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 53099 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:31:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 44112 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:31:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 44327 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 55973 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 43140 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 51681 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 49802 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 57508 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 42941 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 59455 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 41774 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 44976 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 52886 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 48741 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 42333 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 41714 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 52198 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:32:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 45.137.21.9 port 45120 ssh2", "src_ip": "45.137.21.9", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T00:36:27", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=62.93.65.215 OUT= PROTO=TCP DPT=80", "src_ip": "62.93.65.215", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T00:41:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.3.63 port 45795 ssh2", "src_ip": "10.0.3.63", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T00:50:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.195 port 48957 ssh2", "src_ip": "10.0.3.195", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T00:56:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T00:57:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T00:57:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T00:57:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T00:57:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T00:57:01", "source": "nginx", "category": "benign", "severity": "info", "message": "187.4.6.173 - - \"GET /login HTTP/1.1\" 200 3308", "src_ip": "187.4.6.173", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T00:57:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T00:57:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T00:57:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T00:57:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T00:57:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T00:59:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T00:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T00:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T00:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T00:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T00:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T00:59:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T00:59:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T00:59:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T00:59:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T00:59:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T01:00:53", "source": "nginx", "category": "benign", "severity": "info", "message": "170.167.145.95 - - \"GET / HTTP/1.1\" 200 6763", "src_ip": "170.167.145.95", "status": 200, "path": "/"} {"timestamp": "2026-06-15T01:01:49", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 57", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T01:04:42", "source": "nginx", "category": "benign", "severity": "info", "message": "210.247.58.198 - - \"GET / HTTP/1.1\" 200 3140", "src_ip": "210.247.58.198", "status": 200, "path": "/"} {"timestamp": "2026-06-15T01:06:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.82 port 50633 ssh2", "src_ip": "10.0.4.82", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-15T01:06:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=96.236.211.238 OUT= PROTO=TCP DPT=80", "src_ip": "96.236.211.238", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T01:07:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 51160 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:07:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 51349 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:07:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 44973 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:07:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 57440 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:07:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 56350 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:07:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 53203 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:07:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 45570 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:07:19", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T01:07:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 52781 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:08:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=188.170.117.223 OUT= PROTO=TCP DPT=443", "src_ip": "188.170.117.223", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T01:12:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.6 port 55101 ssh2", "src_ip": "10.0.1.6", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T01:13:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.233 port 51247 ssh2", "src_ip": "10.0.0.233", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T01:14:48", "source": "nginx", "category": "benign", "severity": "info", "message": "54.132.152.49 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2704", "src_ip": "54.132.152.49", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T01:14:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=140.251.32.217 OUT= PROTO=TCP DPT=80", "src_ip": "140.251.32.217", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T01:15:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=57.192.223.25 OUT= PROTO=TCP DPT=80", "src_ip": "57.192.223.25", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T01:16:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.244 port 46701 ssh2", "src_ip": "10.0.1.244", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T01:20:19", "source": "nginx", "category": "benign", "severity": "info", "message": "179.19.164.103 - - \"GET /api/products HTTP/1.1\" 200 3478", "src_ip": "179.19.164.103", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T01:29:04", "source": "nginx", "category": "benign", "severity": "info", "message": "98.204.99.102 - - \"GET / HTTP/1.1\" 200 287", "src_ip": "98.204.99.102", "status": 200, "path": "/"} {"timestamp": "2026-06-15T01:29:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=69.170.40.249 OUT= PROTO=TCP DPT=80", "src_ip": "69.170.40.249", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T01:31:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47306 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:31:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 56281 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:31:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53652 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:31:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 52399 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:31:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58093 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:31:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 54511 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:31:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57244 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47146 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 46334 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41276 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 46898 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44869 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 46467 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 52711 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40836 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 43206 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 56641 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 55268 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59132 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40085 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47140 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:32:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 56418 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T01:41:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=37.207.104.124 OUT= PROTO=TCP DPT=80", "src_ip": "37.207.104.124", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T01:42:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=219 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T01:46:37", "source": "nginx", "category": "benign", "severity": "info", "message": "153.49.227.46 - - \"GET /api/products HTTP/1.1\" 200 3524", "src_ip": "153.49.227.46", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T01:47:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=345 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T01:48:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.48 port 42831 ssh2", "src_ip": "10.0.0.48", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T01:51:48", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "guest", "host": "bastion-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-15T01:52:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=536 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T01:53:29", "source": "nginx", "category": "benign", "severity": "info", "message": "202.143.93.117 - - \"GET /health HTTP/1.1\" 200 643", "src_ip": "202.143.93.117", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T01:56:38", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=733 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T01:56:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=73.49.198.33 OUT= PROTO=TCP DPT=443", "src_ip": "73.49.198.33", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T01:57:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=774 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T01:57:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=68.79.253.135 OUT= PROTO=TCP DPT=80", "src_ip": "68.79.253.135", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T01:57:38", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=319 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T01:57:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=502 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T01:58:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=807 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T01:58:38", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=339 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T01:59:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=684 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T01:59:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 40793 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T01:59:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 47542 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T01:59:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 43067 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T01:59:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 57357 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T01:59:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 46326 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T01:59:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 54836 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T01:59:38", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=706 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T01:59:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 45113 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T01:59:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 44719 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T01:59:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 106.59.149.179 port 41838 ssh2", "src_ip": "106.59.149.179", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T02:00:08", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=766 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T02:00:38", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.217 dst=45.137.21.9 dport=443 bytes=764 interval=30s", "src_ip": "10.0.1.217", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-15T02:02:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=655 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T02:07:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=898 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T02:10:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=173.0.36.99 OUT= PROTO=TCP DPT=443", "src_ip": "173.0.36.99", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T02:12:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=598 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T02:17:10", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=195.129.181.66 OUT= PROTO=TCP DPT=80", "src_ip": "195.129.181.66", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T02:17:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=255 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T02:19:02", "source": "nginx", "category": "benign", "severity": "info", "message": "21.62.250.118 - - \"GET /api/products HTTP/1.1\" 200 610", "src_ip": "21.62.250.118", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T02:20:29", "source": "nginx", "category": "benign", "severity": "info", "message": "165.160.15.16 - - \"GET / HTTP/1.1\" 200 4254", "src_ip": "165.160.15.16", "status": 200, "path": "/"} {"timestamp": "2026-06-15T02:22:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=381 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T02:23:46", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.44 dst=185.220.101.34 bytes=5728370688 proto=TCP dport=443 duration=177s", "src_ip": "10.0.2.44", "dst_ip": "185.220.101.34", "bytes_mb": 5463, "off_hours": true} {"timestamp": "2026-06-15T02:27:58", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.26 dst=209.141.56.12 dport=443 bytes=372 interval=300s", "src_ip": "10.0.3.26", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T02:30:06", "source": "nginx", "category": "benign", "severity": "info", "message": "70.114.73.221 - - \"GET /static/app.js HTTP/1.1\" 200 2313", "src_ip": "70.114.73.221", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T02:40:55", "source": "nginx", "category": "benign", "severity": "info", "message": "159.165.132.19 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6680", "src_ip": "159.165.132.19", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T02:47:49", "source": "nginx", "category": "benign", "severity": "info", "message": "48.34.156.190 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5617", "src_ip": "48.34.156.190", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T02:51:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 51625 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:51:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 41668 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:51:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 56624 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:51:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 43228 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:51:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 46751 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:51:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 51065 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:51:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 49335 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:51:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 40308 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:51:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 55484 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 55291 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 58288 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 50769 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 51164 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 43947 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 45427 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 44508 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 59619 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 43911 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 54537 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:52:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 117.23.53.227 port 40113 ssh2", "src_ip": "117.23.53.227", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T02:58:47", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=118.40.172.232 OUT= PROTO=TCP DPT=443", "src_ip": "118.40.172.232", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T02:59:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=124.209.59.118 OUT= PROTO=TCP DPT=80", "src_ip": "124.209.59.118", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T03:00:27", "source": "nginx", "category": "benign", "severity": "info", "message": "40.253.20.114 - - \"GET /api/products HTTP/1.1\" 200 6008", "src_ip": "40.253.20.114", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T03:08:04", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "nattapong", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-15T03:14:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 55400 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 44252 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 59520 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 55765 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 41321 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 52589 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 43952 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 45965 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 57990 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 51103 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 40482 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:14:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 48417 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 46486 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 53737 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 44422 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 52951 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 45317 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 52802 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 57925 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 51530 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 43474 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 56400 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 49606 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:15:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 209.141.56.12 port 41246 ssh2", "src_ip": "209.141.56.12", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T03:23:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=58.227.35.172 OUT= PROTO=TCP DPT=80", "src_ip": "58.227.35.172", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T03:28:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.198 dst=91.219.236.18 dport=443 bytes=539 interval=30s", "src_ip": "10.0.4.198", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-15T03:28:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.198 dst=91.219.236.18 dport=443 bytes=585 interval=30s", "src_ip": "10.0.4.198", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-15T03:29:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.198 dst=91.219.236.18 dport=443 bytes=496 interval=30s", "src_ip": "10.0.4.198", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-15T03:29:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.198 dst=91.219.236.18 dport=443 bytes=651 interval=30s", "src_ip": "10.0.4.198", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-15T03:30:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.198 dst=91.219.236.18 dport=443 bytes=494 interval=30s", "src_ip": "10.0.4.198", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-15T03:30:44", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.198 dst=91.219.236.18 dport=443 bytes=450 interval=30s", "src_ip": "10.0.4.198", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-15T03:31:14", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.198 dst=91.219.236.18 dport=443 bytes=654 interval=30s", "src_ip": "10.0.4.198", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-15T03:36:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=13.251.244.77 OUT= PROTO=TCP DPT=80", "src_ip": "13.251.244.77", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T03:45:22", "source": "nginx", "category": "benign", "severity": "info", "message": "54.78.52.84 - - \"GET /api/products HTTP/1.1\" 200 4836", "src_ip": "54.78.52.84", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T03:45:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.167 port 42119 ssh2", "src_ip": "10.0.1.167", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T03:46:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 51635 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 57230 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 44121 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 41989 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 52834 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 58212 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 41539 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 57320 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 45074 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48475 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 53109 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 40162 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48159 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:46:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 46150 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 45814 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48775 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 55520 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 46352 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 42102 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.207 port 46875 ssh2", "src_ip": "10.0.4.207", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T03:47:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 49751 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:21", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for root from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T03:47:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.200 port 55148 ssh2", "src_ip": "10.0.1.200", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T03:47:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 42147 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 49671 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 45599 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 58724 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:47:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 50076 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T03:53:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.2.211 port 52503 ssh2", "src_ip": "10.0.2.211", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T03:57:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=12.243.244.244 OUT= PROTO=TCP DPT=443", "src_ip": "12.243.244.244", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T03:57:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=174.121.39.107 OUT= PROTO=TCP DPT=80", "src_ip": "174.121.39.107", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T04:01:41", "source": "nginx", "category": "benign", "severity": "info", "message": "86.142.168.132 - - \"GET /api/products HTTP/1.1\" 200 7437", "src_ip": "86.142.168.132", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T04:04:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.5.208 port 58318 ssh2", "src_ip": "10.0.5.208", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T04:16:21", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=12.197.192.245 OUT= PROTO=TCP DPT=443", "src_ip": "12.197.192.245", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T04:18:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=197.31.70.133 OUT= PROTO=TCP DPT=80", "src_ip": "197.31.70.133", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T04:20:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.114 port 52999 ssh2", "src_ip": "10.0.2.114", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T04:24:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=34.189.11.191 OUT= PROTO=TCP DPT=443", "src_ip": "34.189.11.191", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T04:30:46", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/su -", "user": "nattapong", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-15T04:32:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.116 port 41528 ssh2", "src_ip": "10.0.0.116", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T04:36:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.227 dst=91.219.236.18 dport=443 bytes=496 interval=60s", "src_ip": "10.0.2.227", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T04:37:03", "source": "nginx", "category": "benign", "severity": "info", "message": "102.156.150.168 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6873", "src_ip": "102.156.150.168", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T04:37:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.227 dst=91.219.236.18 dport=443 bytes=889 interval=60s", "src_ip": "10.0.2.227", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T04:38:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.227 dst=91.219.236.18 dport=443 bytes=559 interval=60s", "src_ip": "10.0.2.227", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T04:39:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.227 dst=91.219.236.18 dport=443 bytes=628 interval=60s", "src_ip": "10.0.2.227", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T04:40:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.227 dst=91.219.236.18 dport=443 bytes=549 interval=60s", "src_ip": "10.0.2.227", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T04:41:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.227 dst=91.219.236.18 dport=443 bytes=672 interval=60s", "src_ip": "10.0.2.227", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T04:42:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.227 dst=91.219.236.18 dport=443 bytes=353 interval=60s", "src_ip": "10.0.2.227", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T04:46:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.32 port 50092 ssh2", "src_ip": "10.0.2.32", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T04:47:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=34.92.96.98 OUT= PROTO=TCP DPT=80", "src_ip": "34.92.96.98", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T04:50:49", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=176.53.19.95 OUT= PROTO=TCP DPT=80", "src_ip": "176.53.19.95", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T04:52:07", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.96 port 53664 ssh2", "src_ip": "10.0.3.96", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T04:57:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=11.250.126.121 OUT= PROTO=TCP DPT=80", "src_ip": "11.250.126.121", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T04:57:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=15.157.115.203 OUT= PROTO=TCP DPT=443", "src_ip": "15.157.115.203", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T05:12:15", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "www-data", "host": "db-03", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-15T05:15:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.194 port 56265 ssh2", "src_ip": "10.0.0.194", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T05:15:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.100 port 51805 ssh2", "src_ip": "10.0.4.100", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T05:19:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=115.0.174.48 OUT= PROTO=TCP DPT=80", "src_ip": "115.0.174.48", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T05:21:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 52890 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41885 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47659 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47710 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 50964 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40197 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40832 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 46554 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 55521 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57197 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 54297 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44744 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59535 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 54059 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40289 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53700 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 46286 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42746 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 54753 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.213 port 58181 ssh2", "src_ip": "10.0.2.213", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T05:21:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 56377 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48345 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:21:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 50540 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:22:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59509 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:22:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 51108 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T05:24:29", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 403 168", "src_ip": "45.137.21.9", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T05:30:47", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=102.153.87.216 OUT= PROTO=TCP DPT=80", "src_ip": "102.153.87.216", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T05:31:48", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 403 65", "src_ip": "91.219.236.18", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T05:37:33", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.100 dst=45.137.21.9 bytes=3048210432 proto=TCP dport=443 duration=259s", "src_ip": "10.0.5.100", "dst_ip": "45.137.21.9", "bytes_mb": 2907, "off_hours": true} {"timestamp": "2026-06-15T05:42:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=176.197.144.176 OUT= PROTO=TCP DPT=443", "src_ip": "176.197.144.176", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T05:43:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.87 port 57573 ssh2", "src_ip": "10.0.0.87", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T05:44:14", "source": "nginx", "category": "web_attack", "severity": "high", "message": "55.7.57.23 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 11", "src_ip": "55.7.57.23", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T05:44:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T05:44:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T05:44:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T05:44:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T05:44:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T05:44:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T05:44:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T05:44:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T05:44:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T05:44:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T05:45:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.194 port 50072 ssh2", "src_ip": "10.0.3.194", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T05:46:22", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/bin/bash", "user": "postgres", "host": "app-02", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-15T05:48:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=89.122.87.81 OUT= PROTO=TCP DPT=80", "src_ip": "89.122.87.81", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T05:52:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T05:52:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T05:52:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T05:52:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T05:52:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T05:52:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T05:52:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T05:52:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T05:52:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T05:52:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T05:52:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T05:54:44", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /search?q= HTTP/1.1\" 200 131", "src_ip": "209.141.56.12", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T06:02:57", "source": "nginx", "category": "benign", "severity": "info", "message": "99.168.81.237 - - \"GET /static/app.js HTTP/1.1\" 200 5934", "src_ip": "99.168.81.237", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T06:03:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 45071 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:03:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 56599 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:03:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 58355 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:03:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 44988 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:03:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 57237 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:03:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 50799 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:03:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 48961 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 55781 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 52714 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 47982 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 45027 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 42563 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 54851 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 43030 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 41093 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 46578 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:04:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 209.141.56.12 port 52796 ssh2", "src_ip": "209.141.56.12", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-15T06:07:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.1.6 port 56643 ssh2", "src_ip": "10.0.1.6", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T06:11:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=182.49.248.215 OUT= PROTO=TCP DPT=80", "src_ip": "182.49.248.215", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T06:16:51", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=107.160.88.118 OUT= PROTO=TCP DPT=443", "src_ip": "107.160.88.118", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T06:17:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.111 port 49125 ssh2", "src_ip": "10.0.4.111", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T06:21:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55264 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 56952 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44205 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44228 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44068 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 59260 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 50572 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 56477 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 45395 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 45014 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T06:22:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 41575 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 58156 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 45531 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 48674 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 58267 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 44191 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 54065 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 45728 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 42513 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 44585 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 51862 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 45051 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 41544 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 47620 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 50626 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 50010 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=193.132.52.126 OUT= PROTO=TCP DPT=80", "src_ip": "193.132.52.126", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T06:23:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 55309 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 44772 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 52039 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:23:39", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T06:23:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 209.141.56.12 port 54662 ssh2", "src_ip": "209.141.56.12", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T06:24:36", "source": "nginx", "category": "benign", "severity": "info", "message": "64.82.210.6 - - \"GET /login HTTP/1.1\" 200 553", "src_ip": "64.82.210.6", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T06:29:44", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: www-data : TTY=pts/0 ; PWD=/home/www-data ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "www-data", "host": "web-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-15T06:30:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T06:30:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T06:30:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T06:30:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T06:30:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T06:30:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T06:30:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=200.187.63.57 OUT= PROTO=TCP DPT=80", "src_ip": "200.187.63.57", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T06:30:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T06:30:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T06:38:11", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "nattapong", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-15T06:40:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41217 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54171 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 40434 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 53514 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 48758 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 48911 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 47694 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41442 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 49226 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41445 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 42064 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 41549 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 59596 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:40:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 55701 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:41:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 51928 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:41:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54679 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:41:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54950 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:41:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 57845 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:41:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 54265 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:41:11", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for admin from 91.219.236.18 port 51234 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T06:41:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 91.219.236.18 port 56008 ssh2", "src_ip": "91.219.236.18", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T06:41:13", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.171 port 46825 ssh2", "src_ip": "10.0.4.171", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T06:50:04", "source": "nginx", "category": "benign", "severity": "info", "message": "49.222.165.250 - - \"GET /static/app.js HTTP/1.1\" 200 7048", "src_ip": "49.222.165.250", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T06:50:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.81 port 48123 ssh2", "src_ip": "10.0.0.81", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T06:54:35", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "deploy", "host": "bastion-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-15T06:56:43", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.47 port 45358 ssh2", "src_ip": "10.0.3.47", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T06:58:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=140.199.101.1 OUT= PROTO=TCP DPT=80", "src_ip": "140.199.101.1", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T06:58:09", "source": "nginx", "category": "benign", "severity": "info", "message": "49.211.157.71 - - \"GET /health HTTP/1.1\" 200 445", "src_ip": "49.211.157.71", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T06:59:24", "source": "nginx", "category": "benign", "severity": "info", "message": "155.18.222.98 - - \"GET /static/app.js HTTP/1.1\" 200 4419", "src_ip": "155.18.222.98", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T07:00:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T07:00:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T07:00:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T07:00:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T07:00:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T07:00:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T07:00:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T07:00:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T07:00:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T07:00:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T07:00:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T07:00:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T07:00:47", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.243 port 43923 ssh2", "src_ip": "10.0.5.243", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-15T07:01:36", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.203 port 45224 ssh2", "src_ip": "10.0.3.203", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T07:07:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=116.170.70.206 OUT= PROTO=TCP DPT=80", "src_ip": "116.170.70.206", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T07:09:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.65 port 46822 ssh2", "src_ip": "10.0.2.65", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T07:20:10", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/bin/su -", "user": "postgres", "host": "db-03", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-15T07:22:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=659 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T07:24:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.94 port 49998 ssh2", "src_ip": "10.0.1.94", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T07:27:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=591 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T07:29:56", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 452", "src_ip": "185.220.101.34", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T07:31:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=50.97.174.237 OUT= PROTO=TCP DPT=443", "src_ip": "50.97.174.237", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T07:31:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.236 port 45426 ssh2", "src_ip": "10.0.3.236", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T07:32:04", "source": "nginx", "category": "benign", "severity": "info", "message": "103.101.32.242 - - \"GET /api/products HTTP/1.1\" 200 6893", "src_ip": "103.101.32.242", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T07:32:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=723 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T07:37:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=855 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T07:37:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=153.41.53.109 OUT= PROTO=TCP DPT=80", "src_ip": "153.41.53.109", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T07:38:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.143 port 58308 ssh2", "src_ip": "10.0.3.143", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T07:39:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.59 dst=91.219.236.18 dport=443 bytes=281 interval=60s", "src_ip": "10.0.4.59", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T07:40:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.59 dst=91.219.236.18 dport=443 bytes=207 interval=60s", "src_ip": "10.0.4.59", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T07:41:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.59 dst=91.219.236.18 dport=443 bytes=616 interval=60s", "src_ip": "10.0.4.59", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T07:42:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=438 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T07:42:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.59 dst=91.219.236.18 dport=443 bytes=386 interval=60s", "src_ip": "10.0.4.59", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T07:43:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 59304 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 47283 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 57358 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 47325 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 56044 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 52125 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 51986 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 43480 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 52819 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 58306 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 40512 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 48613 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 209.141.56.12 port 50500 ssh2", "src_ip": "209.141.56.12", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T07:43:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.59 dst=91.219.236.18 dport=443 bytes=881 interval=60s", "src_ip": "10.0.4.59", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T07:44:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.59 dst=91.219.236.18 dport=443 bytes=749 interval=60s", "src_ip": "10.0.4.59", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T07:45:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.59 dst=91.219.236.18 dport=443 bytes=433 interval=60s", "src_ip": "10.0.4.59", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T07:46:48", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.59 dst=91.219.236.18 dport=443 bytes=427 interval=60s", "src_ip": "10.0.4.59", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-15T07:47:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=715 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T07:50:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T07:50:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T07:50:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T07:50:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T07:50:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T07:50:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T07:50:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T07:50:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T07:52:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=801 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T07:55:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.53 port 42499 ssh2", "src_ip": "10.0.3.53", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-15T07:57:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=213 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T07:59:41", "source": "nginx", "category": "benign", "severity": "info", "message": "21.100.55.9 - - \"GET /health HTTP/1.1\" 200 5604", "src_ip": "21.100.55.9", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T08:02:33", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.6 dst=45.137.21.9 dport=443 bytes=438 interval=300s", "src_ip": "10.0.2.6", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T08:04:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.4 port 49674 ssh2", "src_ip": "10.0.1.4", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T08:05:52", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.210 dst=193.27.228.114 bytes=3822059520 proto=TCP dport=443 duration=577s", "src_ip": "10.0.1.210", "dst_ip": "193.27.228.114", "bytes_mb": 3645, "off_hours": false} {"timestamp": "2026-06-15T08:06:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 46986 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 44861 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 44940 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 46229 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 49415 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 54506 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 47426 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 56622 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 59771 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55521 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 41604 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 45711 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 56759 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 47389 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53986 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 47276 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 41138 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:06:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53012 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:07:02", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T08:07:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55044 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T08:10:56", "source": "nginx", "category": "benign", "severity": "info", "message": "98.83.52.56 - - \"GET /login HTTP/1.1\" 200 4323", "src_ip": "98.83.52.56", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T08:17:25", "source": "nginx", "category": "benign", "severity": "info", "message": "206.73.107.252 - - \"GET /static/app.js HTTP/1.1\" 200 7010", "src_ip": "206.73.107.252", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T08:18:36", "source": "nginx", "category": "benign", "severity": "info", "message": "185.24.23.26 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6621", "src_ip": "185.24.23.26", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T08:19:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.148 port 52733 ssh2", "src_ip": "10.0.0.148", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T08:24:48", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.160 dst=193.27.228.114 bytes=4600102912 proto=TCP dport=443 duration=330s", "src_ip": "10.0.4.160", "dst_ip": "193.27.228.114", "bytes_mb": 4387, "off_hours": false} {"timestamp": "2026-06-15T08:27:04", "source": "nginx", "category": "benign", "severity": "info", "message": "133.50.253.123 - - \"GET /dashboard HTTP/1.1\" 200 7324", "src_ip": "133.50.253.123", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-15T08:28:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T08:28:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T08:28:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T08:28:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T08:28:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T08:28:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T08:28:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T08:28:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T08:28:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T08:28:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T08:28:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T08:28:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T08:28:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.202 port 59320 ssh2", "src_ip": "10.0.1.202", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T08:28:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.1.160 port 44996 ssh2", "src_ip": "10.0.1.160", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T08:30:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.34 port 55574 ssh2", "src_ip": "10.0.1.34", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-15T08:33:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 58119 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:33:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 44022 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:33:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 47703 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:33:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 44651 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:33:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 40697 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:33:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 49145 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 54427 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 41106 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 54868 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 49108 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 42768 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 40617 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 52588 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 52604 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:34:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 209.141.56.12 port 52580 ssh2", "src_ip": "209.141.56.12", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T08:35:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.191 dst=193.27.228.114 dport=443 bytes=485 interval=60s", "src_ip": "10.0.5.191", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T08:36:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.191 dst=193.27.228.114 dport=443 bytes=665 interval=60s", "src_ip": "10.0.5.191", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T08:37:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.191 dst=193.27.228.114 dport=443 bytes=239 interval=60s", "src_ip": "10.0.5.191", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T08:38:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.191 dst=193.27.228.114 dport=443 bytes=758 interval=60s", "src_ip": "10.0.5.191", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T08:39:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.191 dst=193.27.228.114 dport=443 bytes=359 interval=60s", "src_ip": "10.0.5.191", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T08:41:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=181.157.23.57 OUT= PROTO=TCP DPT=443", "src_ip": "181.157.23.57", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T08:41:59", "source": "nginx", "category": "benign", "severity": "info", "message": "89.116.8.199 - - \"GET /login HTTP/1.1\" 200 7479", "src_ip": "89.116.8.199", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T08:44:35", "source": "nginx", "category": "benign", "severity": "info", "message": "27.150.7.117 - - \"GET / HTTP/1.1\" 200 1980", "src_ip": "27.150.7.117", "status": 200, "path": "/"} {"timestamp": "2026-06-15T08:47:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=95.171.63.79 OUT= PROTO=TCP DPT=80", "src_ip": "95.171.63.79", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T08:51:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.2 port 41904 ssh2", "src_ip": "10.0.0.2", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T08:51:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.113 port 44822 ssh2", "src_ip": "10.0.1.113", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T08:52:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 445", "src_ip": "45.137.21.9", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T08:54:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T08:54:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T08:54:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T08:54:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T08:54:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T08:54:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T08:54:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T08:54:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T08:54:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T08:54:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T08:55:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=144.31.213.236 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "144.31.213.236", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T08:55:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.141 port 43016 ssh2", "src_ip": "10.0.2.141", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T09:01:37", "source": "nginx", "category": "benign", "severity": "info", "message": "139.50.209.104 - - \"GET / HTTP/1.1\" 200 1472", "src_ip": "139.50.209.104", "status": 200, "path": "/"} {"timestamp": "2026-06-15T09:02:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=166.192.195.11 OUT= PROTO=TCP DPT=80", "src_ip": "166.192.195.11", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T09:03:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 42081 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 53668 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 43831 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 45286 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51362 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 54294 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 46298 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 49613 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51267 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 47605 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 47199 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51804 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 51113 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 45309 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 55350 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:03:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 42824 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:04:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 52791 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:04:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 209.141.56.12 port 46789 ssh2", "src_ip": "209.141.56.12", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T09:11:51", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-15T09:15:51", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 337", "src_ip": "91.219.236.18", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T09:19:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=12.187.48.112 OUT= PROTO=TCP DPT=80", "src_ip": "12.187.48.112", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T09:20:44", "source": "nginx", "category": "benign", "severity": "info", "message": "12.60.59.175 - - \"GET /api/products HTTP/1.1\" 200 2725", "src_ip": "12.60.59.175", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T09:28:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=115.143.16.177 OUT= PROTO=TCP DPT=443", "src_ip": "115.143.16.177", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T09:33:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.181 port 58748 ssh2", "src_ip": "10.0.2.181", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-15T09:33:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.4.125 port 51309 ssh2", "src_ip": "10.0.4.125", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T09:36:47", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 30", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T09:40:14", "source": "nginx", "category": "benign", "severity": "info", "message": "40.186.14.9 - - \"GET / HTTP/1.1\" 200 814", "src_ip": "40.186.14.9", "status": 200, "path": "/"} {"timestamp": "2026-06-15T09:40:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.71 port 51316 ssh2", "src_ip": "10.0.2.71", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T09:41:54", "source": "nginx", "category": "benign", "severity": "info", "message": "93.247.115.24 - - \"GET /api/products HTTP/1.1\" 200 6476", "src_ip": "93.247.115.24", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T09:43:12", "source": "nginx", "category": "benign", "severity": "info", "message": "203.96.84.243 - - \"GET /health HTTP/1.1\" 200 3504", "src_ip": "203.96.84.243", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T09:43:36", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 375", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T09:43:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=111.182.246.76 OUT= PROTO=TCP DPT=80", "src_ip": "111.182.246.76", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T09:48:51", "source": "nginx", "category": "benign", "severity": "info", "message": "201.88.192.224 - - \"GET /health HTTP/1.1\" 200 2664", "src_ip": "201.88.192.224", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T09:57:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 43731 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 46547 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58025 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 55126 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57879 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 49923 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48279 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 49546 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 46869 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:57:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 56361 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42266 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 42423 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59593 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59078 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57510 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 45050 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53865 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 57593 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53706 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:58:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41204 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T09:59:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.220 port 45332 ssh2", "src_ip": "10.0.2.220", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T10:01:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=169.43.230.113 OUT= PROTO=TCP DPT=443", "src_ip": "169.43.230.113", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T10:02:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.164 port 54417 ssh2", "src_ip": "10.0.5.164", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-15T10:02:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=186.224.119.195 OUT= PROTO=TCP DPT=443", "src_ip": "186.224.119.195", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T10:04:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.157 port 59887 ssh2", "src_ip": "10.0.1.157", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T10:04:25", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.27 port 51607 ssh2", "src_ip": "10.0.3.27", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T10:10:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.106 port 50921 ssh2", "src_ip": "10.0.2.106", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T10:11:07", "source": "nginx", "category": "benign", "severity": "info", "message": "37.120.3.125 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2782", "src_ip": "37.120.3.125", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T10:12:36", "source": "nginx", "category": "benign", "severity": "info", "message": "161.109.207.111 - - \"GET /health HTTP/1.1\" 200 2126", "src_ip": "161.109.207.111", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T10:13:14", "source": "nginx", "category": "benign", "severity": "info", "message": "11.25.145.3 - - \"GET /static/app.js HTTP/1.1\" 200 2213", "src_ip": "11.25.145.3", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T10:21:31", "source": "nginx", "category": "benign", "severity": "info", "message": "135.187.107.93 - - \"GET /health HTTP/1.1\" 200 4779", "src_ip": "135.187.107.93", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T10:25:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=56.168.247.132 OUT= PROTO=TCP DPT=443", "src_ip": "56.168.247.132", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T10:26:54", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "svc_backup", "host": "web-01", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-15T10:27:26", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=47.31.221.114 OUT= PROTO=TCP DPT=443", "src_ip": "47.31.221.114", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T10:29:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=191.107.3.51 OUT= PROTO=TCP DPT=443", "src_ip": "191.107.3.51", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T10:31:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.79 port 48295 ssh2", "src_ip": "10.0.5.79", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T10:32:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 50627 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 48606 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 44756 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 47100 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 45288 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 43477 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 45005 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 46033 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 51591 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 52176 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 56657 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 45045 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 58357 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 42184 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 49569 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 41873 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 45997 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:32:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 58549 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:33:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 47937 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:33:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 51060 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:33:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 41615 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:33:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 55688 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:33:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 43759 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 48319 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 56322 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 54641 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 43816 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 58711 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 54422 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 45311 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 50849 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 40088 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 59526 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 59079 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 56067 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 58991 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 44281 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 57268 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 43686 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:34:53", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for somchai from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T10:34:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 50711 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:35:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 45.137.21.9 port 57004 ssh2", "src_ip": "45.137.21.9", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T10:39:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T10:39:11", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T10:39:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T10:39:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T10:39:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T10:39:12", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T10:39:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T10:39:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T10:39:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T10:39:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T10:39:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T10:40:56", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/su -", "user": "somchai", "host": "web-01", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-15T10:41:49", "source": "nginx", "category": "benign", "severity": "info", "message": "36.88.130.121 - - \"GET /dashboard HTTP/1.1\" 200 2449", "src_ip": "36.88.130.121", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-15T10:42:27", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.31 port 43817 ssh2", "src_ip": "10.0.1.31", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T10:45:11", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.55 dst=185.220.101.34 bytes=5306843136 proto=TCP dport=443 duration=108s", "src_ip": "10.0.1.55", "dst_ip": "185.220.101.34", "bytes_mb": 5061, "off_hours": false} {"timestamp": "2026-06-15T10:51:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=25.154.189.131 OUT= PROTO=TCP DPT=443", "src_ip": "25.154.189.131", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T10:56:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.17.109.191 OUT= PROTO=TCP DPT=443", "src_ip": "167.17.109.191", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T10:57:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.146 dst=209.141.56.12 dport=443 bytes=506 interval=30s", "src_ip": "10.0.4.146", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T10:57:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.52 port 57841 ssh2", "src_ip": "10.0.0.52", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T10:57:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.146 dst=209.141.56.12 dport=443 bytes=387 interval=30s", "src_ip": "10.0.4.146", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T10:58:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.146 dst=209.141.56.12 dport=443 bytes=242 interval=30s", "src_ip": "10.0.4.146", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T10:58:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.146 dst=209.141.56.12 dport=443 bytes=372 interval=30s", "src_ip": "10.0.4.146", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T10:58:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 50905 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:58:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 55288 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:58:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 57668 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:58:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 51254 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 45383 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 52987 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 53729 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 56429 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 44753 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 51195 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:13", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.146 dst=209.141.56.12 dport=443 bytes=493 interval=30s", "src_ip": "10.0.4.146", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T10:59:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 45224 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:17", "source": "nginx", "category": "web_attack", "severity": "high", "message": "190.221.215.15 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 375", "src_ip": "190.221.215.15", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T10:59:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 44571 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 58037 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 41375 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 43401 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 209.141.56.12 port 40132 ssh2", "src_ip": "209.141.56.12", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T10:59:43", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.146 dst=209.141.56.12 dport=443 bytes=773 interval=30s", "src_ip": "10.0.4.146", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T11:05:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=178.240.146.138 OUT= PROTO=TCP DPT=80", "src_ip": "178.240.146.138", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T11:10:17", "source": "nginx", "category": "benign", "severity": "info", "message": "203.211.11.44 - - \"GET / HTTP/1.1\" 200 4669", "src_ip": "203.211.11.44", "status": 200, "path": "/"} {"timestamp": "2026-06-15T11:12:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T11:12:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T11:12:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T11:12:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T11:12:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T11:12:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T11:12:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T11:12:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T11:12:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T11:12:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T11:12:46", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T11:12:47", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=165.95.240.74 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "165.95.240.74", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T11:20:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.173 port 59289 ssh2", "src_ip": "10.0.2.173", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T11:31:55", "source": "nginx", "category": "benign", "severity": "info", "message": "91.103.39.254 - - \"GET /health HTTP/1.1\" 200 7396", "src_ip": "91.103.39.254", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T11:32:12", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=68.145.16.101 OUT= PROTO=TCP DPT=443", "src_ip": "68.145.16.101", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T11:33:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.201 port 44801 ssh2", "src_ip": "10.0.4.201", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T11:34:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.250 port 54867 ssh2", "src_ip": "10.0.1.250", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T11:41:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T11:41:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T11:41:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T11:41:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T11:41:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T11:41:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T11:41:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T11:41:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T11:41:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T11:43:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=111.190.55.116 OUT= PROTO=TCP DPT=80", "src_ip": "111.190.55.116", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T11:48:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=178.9.52.104 OUT= PROTO=TCP DPT=443", "src_ip": "178.9.52.104", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T11:53:09", "source": "nginx", "category": "benign", "severity": "info", "message": "208.28.21.49 - - \"GET / HTTP/1.1\" 200 2715", "src_ip": "208.28.21.49", "status": 200, "path": "/"} {"timestamp": "2026-06-15T11:55:22", "source": "nginx", "category": "benign", "severity": "info", "message": "217.92.119.182 - - \"GET /api/products HTTP/1.1\" 200 1785", "src_ip": "217.92.119.182", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T11:58:07", "source": "nginx", "category": "benign", "severity": "info", "message": "140.133.175.208 - - \"GET /health HTTP/1.1\" 200 4628", "src_ip": "140.133.175.208", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T11:59:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.4.11 port 55366 ssh2", "src_ip": "10.0.4.11", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T12:00:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 44280 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 43065 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 53341 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 50992 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 40094 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 52971 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 54416 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 44326 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 59492 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 41882 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 55060 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 53037 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 43144 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:00:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 43.52.124.96 port 57605 ssh2", "src_ip": "43.52.124.96", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T12:01:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=35.168.13.73 OUT= PROTO=TCP DPT=80", "src_ip": "35.168.13.73", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T12:12:35", "source": "nginx", "category": "benign", "severity": "info", "message": "62.77.192.53 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 510", "src_ip": "62.77.192.53", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T12:13:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=200.43.105.98 OUT= PROTO=TCP DPT=80", "src_ip": "200.43.105.98", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T12:15:28", "source": "nginx", "category": "benign", "severity": "info", "message": "151.245.31.23 - - \"GET /api/products HTTP/1.1\" 200 3337", "src_ip": "151.245.31.23", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T12:15:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.138 port 49240 ssh2", "src_ip": "10.0.0.138", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T12:18:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 49357 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44018 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 56095 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 42426 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 50472 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 45657 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 45704 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 43976 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44550 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 54585 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 56188 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 51825 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 49828 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 51384 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 50134 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 42127 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 56670 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 57765 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 55315 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:18:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 58752 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:19:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 44252 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:19:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for guest from 185.220.101.34 port 42825 ssh2", "src_ip": "185.220.101.34", "user": "guest", "action": "login_failed"} {"timestamp": "2026-06-15T12:19:45", "source": "nginx", "category": "benign", "severity": "info", "message": "122.81.249.249 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 689", "src_ip": "122.81.249.249", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T12:27:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=163.36.6.253 OUT= PROTO=TCP DPT=443", "src_ip": "163.36.6.253", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T12:27:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=67.216.229.231 OUT= PROTO=TCP DPT=443", "src_ip": "67.216.229.231", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T12:28:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=204.101.53.54 OUT= PROTO=TCP DPT=443", "src_ip": "204.101.53.54", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T12:31:51", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 200 180", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-15T12:32:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.39 port 53035 ssh2", "src_ip": "10.0.0.39", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T12:33:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.79 port 54267 ssh2", "src_ip": "10.0.1.79", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T12:34:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=684 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:35:33", "source": "nginx", "category": "benign", "severity": "info", "message": "42.185.196.207 - - \"GET /api/products HTTP/1.1\" 200 6382", "src_ip": "42.185.196.207", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T12:35:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=592 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:36:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=751 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:36:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.201 port 51740 ssh2", "src_ip": "10.0.4.201", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T12:37:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=300 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:38:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.216 dst=45.137.21.9 dport=443 bytes=450 interval=60s", "src_ip": "10.0.4.216", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-15T12:38:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=632 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:39:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.216 dst=45.137.21.9 dport=443 bytes=673 interval=60s", "src_ip": "10.0.4.216", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-15T12:39:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=801 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:40:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.216 dst=45.137.21.9 dport=443 bytes=271 interval=60s", "src_ip": "10.0.4.216", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-15T12:40:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=835 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:40:50", "source": "nginx", "category": "benign", "severity": "info", "message": "53.133.233.77 - - \"GET /health HTTP/1.1\" 200 2677", "src_ip": "53.133.233.77", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T12:41:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.216 dst=45.137.21.9 dport=443 bytes=207 interval=60s", "src_ip": "10.0.4.216", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-15T12:41:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=559 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:42:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.216 dst=45.137.21.9 dport=443 bytes=233 interval=60s", "src_ip": "10.0.4.216", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-15T12:42:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=702 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:42:59", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T12:43:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T12:43:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T12:43:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T12:43:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T12:43:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T12:43:00", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T12:43:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T12:43:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T12:43:01", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T12:43:11", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 102", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T12:43:36", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.216 dst=45.137.21.9 dport=443 bytes=898 interval=60s", "src_ip": "10.0.4.216", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-15T12:43:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.9 dst=185.220.101.34 dport=443 bytes=227 interval=60s", "src_ip": "10.0.2.9", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T12:44:26", "source": "nginx", "category": "benign", "severity": "info", "message": "13.171.5.126 - - \"GET /static/app.js HTTP/1.1\" 200 741", "src_ip": "13.171.5.126", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T12:44:31", "source": "nginx", "category": "benign", "severity": "info", "message": "31.66.28.161 - - \"GET /dashboard HTTP/1.1\" 200 2767", "src_ip": "31.66.28.161", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-15T12:48:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.178 port 50641 ssh2", "src_ip": "10.0.2.178", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T12:53:40", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.87 port 56547 ssh2", "src_ip": "10.0.1.87", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T13:01:06", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 304", "src_ip": "91.219.236.18", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T13:01:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.46 port 54529 ssh2", "src_ip": "10.0.0.46", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T13:02:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=109.104.109.209 OUT= PROTO=TCP DPT=443", "src_ip": "109.104.109.209", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T13:07:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=162.204.160.21 OUT= PROTO=TCP DPT=80", "src_ip": "162.204.160.21", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T13:09:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T13:09:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T13:09:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T13:09:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T13:09:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T13:09:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T13:09:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T13:09:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T13:09:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T13:10:52", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "svc_backup", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-15T13:13:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T13:13:48", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T13:13:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T13:13:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T13:13:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T13:13:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T13:13:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T13:13:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T13:13:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=84.141.219.134 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "84.141.219.134", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T13:15:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=104.242.35.52 OUT= PROTO=TCP DPT=80", "src_ip": "104.242.35.52", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T13:21:37", "source": "nginx", "category": "web_attack", "severity": "high", "message": "197.169.223.101 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 461", "src_ip": "197.169.223.101", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-15T13:28:22", "source": "nginx", "category": "benign", "severity": "info", "message": "171.225.57.251 - - \"GET /health HTTP/1.1\" 200 7947", "src_ip": "171.225.57.251", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T13:29:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T13:29:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T13:29:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T13:29:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T13:29:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T13:29:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T13:29:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T13:29:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T13:29:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T13:29:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T13:29:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T13:29:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T13:30:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=144.200.206.94 OUT= PROTO=TCP DPT=443", "src_ip": "144.200.206.94", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T13:35:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.232 port 53462 ssh2", "src_ip": "10.0.2.232", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T13:35:15", "source": "nginx", "category": "benign", "severity": "info", "message": "199.98.87.250 - - \"GET /health HTTP/1.1\" 200 2826", "src_ip": "199.98.87.250", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T13:35:16", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.23 port 56358 ssh2", "src_ip": "10.0.5.23", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T13:37:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.1.8 port 59240 ssh2", "src_ip": "10.0.1.8", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-15T13:41:55", "source": "nginx", "category": "benign", "severity": "info", "message": "46.48.63.192 - - \"GET /api/products HTTP/1.1\" 200 1346", "src_ip": "46.48.63.192", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T13:45:56", "source": "nginx", "category": "benign", "severity": "info", "message": "39.210.236.63 - - \"GET /api/products HTTP/1.1\" 200 7072", "src_ip": "39.210.236.63", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T13:48:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.137 port 41591 ssh2", "src_ip": "10.0.0.137", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T13:59:05", "source": "nginx", "category": "benign", "severity": "info", "message": "185.175.133.251 - - \"GET /health HTTP/1.1\" 200 5997", "src_ip": "185.175.133.251", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T14:02:05", "source": "nginx", "category": "benign", "severity": "info", "message": "79.109.33.110 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3406", "src_ip": "79.109.33.110", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T14:02:37", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.2.97 port 53599 ssh2", "src_ip": "10.0.2.97", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T14:04:57", "source": "nginx", "category": "benign", "severity": "info", "message": "142.34.217.89 - - \"GET /login HTTP/1.1\" 200 2484", "src_ip": "142.34.217.89", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T14:07:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 44057 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 44087 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 49763 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 59057 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 51107 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 40170 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 50742 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 51838 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 49804 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 53949 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 57474 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 58768 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 42037 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 47662 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 44586 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 43210 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 52375 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 48114 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 42685 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 44261 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 59083 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 47038 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 42558 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:07:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 198.30.190.67 port 57244 ssh2", "src_ip": "198.30.190.67", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T14:09:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.153 port 58606 ssh2", "src_ip": "10.0.0.153", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T14:12:37", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.49 dst=45.137.21.9 bytes=5911871488 proto=TCP dport=443 duration=259s", "src_ip": "10.0.1.49", "dst_ip": "45.137.21.9", "bytes_mb": 5638, "off_hours": false} {"timestamp": "2026-06-15T14:13:28", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.125 port 59831 ssh2", "src_ip": "10.0.5.125", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T14:16:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.185 port 59948 ssh2", "src_ip": "10.0.1.185", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T14:17:03", "source": "nginx", "category": "benign", "severity": "info", "message": "73.246.24.9 - - \"GET /health HTTP/1.1\" 200 3333", "src_ip": "73.246.24.9", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T14:20:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=55.34.180.204 OUT= PROTO=TCP DPT=80", "src_ip": "55.34.180.204", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T14:31:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=164.113.29.8 OUT= PROTO=TCP DPT=443", "src_ip": "164.113.29.8", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T14:35:36", "source": "nginx", "category": "benign", "severity": "info", "message": "79.12.104.149 - - \"GET / HTTP/1.1\" 200 5187", "src_ip": "79.12.104.149", "status": 200, "path": "/"} {"timestamp": "2026-06-15T14:37:06", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/cat /etc/shadow", "user": "nattapong", "host": "app-02", "command": "/usr/bin/cat /etc/shadow", "action": "sudo"} {"timestamp": "2026-06-15T14:40:15", "source": "nginx", "category": "benign", "severity": "info", "message": "171.18.252.71 - - \"GET /login HTTP/1.1\" 200 4882", "src_ip": "171.18.252.71", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T14:42:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.250.153.122 OUT= PROTO=TCP DPT=80", "src_ip": "147.250.153.122", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T14:48:46", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 250", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T14:50:04", "source": "nginx", "category": "benign", "severity": "info", "message": "221.1.144.186 - - \"GET /api/products HTTP/1.1\" 200 7060", "src_ip": "221.1.144.186", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T14:51:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.154 port 42226 ssh2", "src_ip": "10.0.0.154", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T14:52:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=85.124.81.198 OUT= PROTO=TCP DPT=443", "src_ip": "85.124.81.198", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T14:57:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=193.176.110.97 OUT= PROTO=TCP DPT=80", "src_ip": "193.176.110.97", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T14:58:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.250 dst=45.137.21.9 dport=443 bytes=466 interval=300s", "src_ip": "10.0.0.250", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T14:58:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=45.35.141.198 OUT= PROTO=TCP DPT=443", "src_ip": "45.35.141.198", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T15:03:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.250 dst=45.137.21.9 dport=443 bytes=511 interval=300s", "src_ip": "10.0.0.250", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T15:04:59", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=143.207.244.159 OUT= PROTO=TCP DPT=80", "src_ip": "143.207.244.159", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T15:08:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.250 dst=45.137.21.9 dport=443 bytes=747 interval=300s", "src_ip": "10.0.0.250", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T15:13:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.250 dst=45.137.21.9 dport=443 bytes=341 interval=300s", "src_ip": "10.0.0.250", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T15:14:54", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 403 242", "src_ip": "185.220.101.34", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T15:18:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.250 dst=45.137.21.9 dport=443 bytes=364 interval=300s", "src_ip": "10.0.0.250", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T15:23:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.250 dst=45.137.21.9 dport=443 bytes=323 interval=300s", "src_ip": "10.0.0.250", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T15:28:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.250 dst=45.137.21.9 dport=443 bytes=662 interval=300s", "src_ip": "10.0.0.250", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T15:31:23", "source": "nginx", "category": "benign", "severity": "info", "message": "124.128.233.184 - - \"GET / HTTP/1.1\" 200 7289", "src_ip": "124.128.233.184", "status": 200, "path": "/"} {"timestamp": "2026-06-15T15:33:27", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.250 dst=45.137.21.9 dport=443 bytes=564 interval=300s", "src_ip": "10.0.0.250", "dst_ip": "45.137.21.9", "beacon_interval": 300} {"timestamp": "2026-06-15T15:36:10", "source": "nginx", "category": "benign", "severity": "info", "message": "218.28.232.34 - - \"GET /static/app.js HTTP/1.1\" 200 3603", "src_ip": "218.28.232.34", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T15:37:01", "source": "nginx", "category": "benign", "severity": "info", "message": "43.150.31.95 - - \"GET /static/app.js HTTP/1.1\" 200 635", "src_ip": "43.150.31.95", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T15:37:22", "source": "nginx", "category": "benign", "severity": "info", "message": "209.228.40.98 - - \"GET /static/app.js HTTP/1.1\" 200 2547", "src_ip": "209.228.40.98", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T15:37:29", "source": "nginx", "category": "benign", "severity": "info", "message": "197.195.177.109 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7665", "src_ip": "197.195.177.109", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T15:38:17", "source": "nginx", "category": "benign", "severity": "info", "message": "41.235.249.117 - - \"GET /api/products HTTP/1.1\" 200 5984", "src_ip": "41.235.249.117", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T15:43:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 47325 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 45071 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 50187 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 42200 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 45014 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 46576 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 40211 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 46694 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 55523 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 56574 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 43991 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 57914 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 43966 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 44642 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 43174 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 52802 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 53256 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 46030 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 54389 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 44792 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:43", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for root from 190.104.73.144 port 51234 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T15:44:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 44036 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:44:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 40709 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:45:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 190.104.73.144 port 47886 ssh2", "src_ip": "190.104.73.144", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T15:49:12", "source": "nginx", "category": "benign", "severity": "info", "message": "182.0.143.185 - - \"GET /dashboard HTTP/1.1\" 200 6205", "src_ip": "182.0.143.185", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-15T15:52:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.4.85 port 52803 ssh2", "src_ip": "10.0.4.85", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T15:53:19", "source": "nginx", "category": "web_attack", "severity": "high", "message": "75.209.150.155 - - \"GET /search?q= HTTP/1.1\" 403 15", "src_ip": "75.209.150.155", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T15:54:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.198 dst=185.220.101.34 dport=443 bytes=325 interval=60s", "src_ip": "10.0.1.198", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T15:55:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.198 dst=185.220.101.34 dport=443 bytes=456 interval=60s", "src_ip": "10.0.1.198", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T15:55:43", "source": "nginx", "category": "benign", "severity": "info", "message": "29.163.195.94 - - \"GET /static/app.js HTTP/1.1\" 200 3734", "src_ip": "29.163.195.94", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T15:56:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.198 dst=185.220.101.34 dport=443 bytes=701 interval=60s", "src_ip": "10.0.1.198", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T15:56:48", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.39 port 54012 ssh2", "src_ip": "10.0.3.39", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T15:57:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.198 dst=185.220.101.34 dport=443 bytes=709 interval=60s", "src_ip": "10.0.1.198", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T15:58:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.198 dst=185.220.101.34 dport=443 bytes=436 interval=60s", "src_ip": "10.0.1.198", "dst_ip": "185.220.101.34", "beacon_interval": 60} {"timestamp": "2026-06-15T16:02:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T16:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T16:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T16:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T16:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T16:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T16:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T16:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T16:02:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T16:02:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T16:02:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T16:04:32", "source": "nginx", "category": "benign", "severity": "info", "message": "120.98.137.45 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 646", "src_ip": "120.98.137.45", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T16:04:32", "source": "nginx", "category": "benign", "severity": "info", "message": "84.202.1.115 - - \"GET /static/app.js HTTP/1.1\" 200 5193", "src_ip": "84.202.1.115", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T16:07:05", "source": "nginx", "category": "benign", "severity": "info", "message": "103.185.30.78 - - \"GET /static/app.js HTTP/1.1\" 200 2550", "src_ip": "103.185.30.78", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T16:08:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=30.230.27.208 OUT= PROTO=TCP DPT=443", "src_ip": "30.230.27.208", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T16:15:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 387", "src_ip": "91.219.236.18", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T16:18:50", "source": "nginx", "category": "benign", "severity": "info", "message": "130.50.240.195 - - \"GET /health HTTP/1.1\" 200 2823", "src_ip": "130.50.240.195", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T16:30:09", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 331", "src_ip": "185.220.101.34", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T16:36:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.137 port 52254 ssh2", "src_ip": "10.0.5.137", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T16:36:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=126.249.0.114 OUT= PROTO=TCP DPT=443", "src_ip": "126.249.0.114", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T16:42:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T16:42:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T16:42:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T16:42:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T16:42:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T16:42:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T16:42:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T16:42:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T16:42:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T16:42:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T16:42:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=42.19.106.7 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "42.19.106.7", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T16:45:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.235 port 55971 ssh2", "src_ip": "10.0.0.235", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T16:46:16", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/bash", "user": "deploy", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-15T16:48:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 43162 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 51218 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 51974 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 48613 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 47442 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 40832 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 58037 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 51390 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 56538 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 43641 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 53027 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 44136 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 47269 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 46510 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 58444 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 54829 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 57470 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 58130 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 57395 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 49689 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 46385 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 57676 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:48:55", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 91.219.236.18 port 51234 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T16:48:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 51597 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:49:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 59691 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:49:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 57204 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T16:52:11", "source": "nginx", "category": "benign", "severity": "info", "message": "138.157.254.6 - - \"GET / HTTP/1.1\" 200 7943", "src_ip": "138.157.254.6", "status": 200, "path": "/"} {"timestamp": "2026-06-15T17:03:41", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=208.251.244.112 OUT= PROTO=TCP DPT=443", "src_ip": "208.251.244.112", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T17:03:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 48654 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T17:03:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 54116 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T17:03:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 47023 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T17:03:51", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.4.86 port 58602 ssh2", "src_ip": "10.0.4.86", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T17:03:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 44573 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T17:03:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 42917 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T17:03:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 41670 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T17:04:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 55097 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T17:04:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45620 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T17:06:14", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.230 dst=45.137.21.9 bytes=5830082560 proto=TCP dport=443 duration=559s", "src_ip": "10.0.3.230", "dst_ip": "45.137.21.9", "bytes_mb": 5560, "off_hours": false} {"timestamp": "2026-06-15T17:07:28", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=196.244.191.60 OUT= PROTO=TCP DPT=80", "src_ip": "196.244.191.60", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T17:10:31", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.226 port 55240 ssh2", "src_ip": "10.0.0.226", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T17:20:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=179.173.94.165 OUT= PROTO=TCP DPT=443", "src_ip": "179.173.94.165", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T17:20:25", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.105 dst=45.137.21.9 bytes=4099932160 proto=TCP dport=443 duration=122s", "src_ip": "10.0.5.105", "dst_ip": "45.137.21.9", "bytes_mb": 3910, "off_hours": false} {"timestamp": "2026-06-15T17:23:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 44444 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 45693 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 58634 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 46577 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 48175 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 54956 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 51808 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 52204 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 52070 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 56551 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 44059 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 46524 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 58751 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 47253 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 59465 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 45819 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 59230 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 41001 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 45358 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 42961 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 40899 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:23:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 41626 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:24:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 51460 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:24:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 185.220.101.34 port 47376 ssh2", "src_ip": "185.220.101.34", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T17:26:45", "source": "nginx", "category": "benign", "severity": "info", "message": "169.234.189.113 - - \"GET /login HTTP/1.1\" 200 4796", "src_ip": "169.234.189.113", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T17:26:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.5.69 port 54831 ssh2", "src_ip": "10.0.5.69", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T17:32:43", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.4.29 dst=45.137.21.9 bytes=6134169600 proto=TCP dport=443 duration=75s", "src_ip": "10.0.4.29", "dst_ip": "45.137.21.9", "bytes_mb": 5850, "off_hours": false} {"timestamp": "2026-06-15T17:33:07", "source": "nginx", "category": "web_attack", "severity": "high", "message": "114.211.169.98 - - \"GET /search?q= HTTP/1.1\" 403 396", "src_ip": "114.211.169.98", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T17:33:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=417 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T17:38:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.90 port 43322 ssh2", "src_ip": "10.0.0.90", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T17:38:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=371 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T17:43:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=349 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T17:45:01", "source": "nginx", "category": "benign", "severity": "info", "message": "162.236.243.145 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4044", "src_ip": "162.236.243.145", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T17:47:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.179 port 52199 ssh2", "src_ip": "10.0.0.179", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T17:48:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=324 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T17:49:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=205.78.110.222 OUT= PROTO=TCP DPT=443", "src_ip": "205.78.110.222", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T17:49:34", "source": "nginx", "category": "benign", "severity": "info", "message": "24.43.28.70 - - \"GET /health HTTP/1.1\" 200 5523", "src_ip": "24.43.28.70", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T17:53:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=245 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T17:57:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.51 port 59775 ssh2", "src_ip": "10.0.3.51", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T17:58:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=319 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T17:58:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=176.22.80.158 OUT= PROTO=TCP DPT=80", "src_ip": "176.22.80.158", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T18:02:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 59947 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 52716 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 43963 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 57699 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 52679 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 46214 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 54266 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 52970 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 59554 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 56306 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 53107 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 45181 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 51925 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 44177 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:02:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 41506 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:03:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 52401 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:03:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 59480 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:03:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 53535 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:03:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=215 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T18:03:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 56091 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:03:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 160.7.68.248 port 49678 ssh2", "src_ip": "160.7.68.248", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-15T18:03:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T18:03:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T18:03:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T18:03:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T18:03:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T18:03:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T18:03:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T18:03:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T18:03:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T18:03:52", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T18:03:53", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T18:05:06", "source": "nginx", "category": "benign", "severity": "info", "message": "31.128.100.163 - - \"GET /static/app.js HTTP/1.1\" 200 2448", "src_ip": "31.128.100.163", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T18:06:35", "source": "nginx", "category": "benign", "severity": "info", "message": "180.208.175.96 - - \"GET /login HTTP/1.1\" 200 2074", "src_ip": "180.208.175.96", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T18:08:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=389 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T18:13:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.184 dst=209.141.56.12 dport=443 bytes=435 interval=300s", "src_ip": "10.0.0.184", "dst_ip": "209.141.56.12", "beacon_interval": 300} {"timestamp": "2026-06-15T18:16:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.3.146 port 52354 ssh2", "src_ip": "10.0.3.146", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-15T18:20:18", "source": "nginx", "category": "benign", "severity": "info", "message": "109.36.213.246 - - \"GET /api/products HTTP/1.1\" 200 7436", "src_ip": "109.36.213.246", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T18:24:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=205.125.172.170 OUT= PROTO=TCP DPT=443", "src_ip": "205.125.172.170", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T18:25:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 57981 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 45506 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 43790 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 47974 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 45584 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 57716 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 54250 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 50698 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 48441 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 50905 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 42930 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 49186 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 40957 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 55607 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:25:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 44033 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:26:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 44448 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:26:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 56120 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T18:28:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.0.216 port 49329 ssh2", "src_ip": "10.0.0.216", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-15T18:28:13", "source": "nginx", "category": "web_attack", "severity": "high", "message": "45.137.21.9 - - \"GET /search?q= HTTP/1.1\" 200 420", "src_ip": "45.137.21.9", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T18:28:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=153.168.231.41 OUT= PROTO=TCP DPT=80", "src_ip": "153.168.231.41", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T18:29:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.94 port 51470 ssh2", "src_ip": "10.0.1.94", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T18:29:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=145.172.222.228 OUT= PROTO=TCP DPT=80", "src_ip": "145.172.222.228", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T18:31:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=160.190.52.165 OUT= PROTO=TCP DPT=443", "src_ip": "160.190.52.165", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T18:35:12", "source": "nginx", "category": "benign", "severity": "info", "message": "145.52.241.60 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3790", "src_ip": "145.52.241.60", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T18:35:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=75.244.145.149 OUT= PROTO=TCP DPT=443", "src_ip": "75.244.145.149", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T18:40:24", "source": "nginx", "category": "benign", "severity": "info", "message": "183.52.106.233 - - \"GET /login HTTP/1.1\" 200 4281", "src_ip": "183.52.106.233", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T18:44:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=67.110.110.96 OUT= PROTO=TCP DPT=80", "src_ip": "67.110.110.96", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T18:47:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=199.172.23.167 OUT= PROTO=TCP DPT=443", "src_ip": "199.172.23.167", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T18:49:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 43537 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:49:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 54534 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:49:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 42647 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:49:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 42152 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:49:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 49011 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:49:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 59932 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:49:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 43749 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 59575 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 53559 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 59181 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 56565 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 50655 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 49663 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 54796 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 54096 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 54860 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 53631 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 58066 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 53984 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 47045 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:50:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 91.219.236.18 port 43115 ssh2", "src_ip": "91.219.236.18", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T18:55:17", "source": "nginx", "category": "benign", "severity": "info", "message": "66.242.236.72 - - \"GET / HTTP/1.1\" 200 6180", "src_ip": "66.242.236.72", "status": 200, "path": "/"} {"timestamp": "2026-06-15T18:55:36", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.190 port 45968 ssh2", "src_ip": "10.0.4.190", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T18:55:58", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 500 326", "src_ip": "193.27.228.114", "status": 500, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T18:57:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=215.193.80.38 OUT= PROTO=TCP DPT=443", "src_ip": "215.193.80.38", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T19:00:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=147.99.245.254 OUT= PROTO=TCP DPT=443", "src_ip": "147.99.245.254", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T19:05:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.0.9 port 42940 ssh2", "src_ip": "10.0.0.9", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T19:07:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=178.52.140.132 OUT= PROTO=TCP DPT=80", "src_ip": "178.52.140.132", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T19:10:58", "source": "nginx", "category": "benign", "severity": "info", "message": "166.107.50.170 - - \"GET /health HTTP/1.1\" 200 566", "src_ip": "166.107.50.170", "status": 200, "path": "/health"} {"timestamp": "2026-06-15T19:13:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 41292 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 59353 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 54088 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 48798 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 44157 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 50842 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 59830 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 59954 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 49463 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 40529 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 59602 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 47530 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 59844 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 57769 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 59979 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:36", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 395", "src_ip": "185.220.101.34", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-15T19:14:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 48217 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 49563 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 51363 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 44259 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 58138 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 42163 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:14:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 91.219.236.18 port 42752 ssh2", "src_ip": "91.219.236.18", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-15T19:15:19", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.128 port 42152 ssh2", "src_ip": "10.0.4.128", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T19:17:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T19:17:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T19:17:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T19:17:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T19:17:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T19:17:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T19:17:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T19:17:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T19:17:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T19:17:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T19:17:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T19:17:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T19:19:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T19:19:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T19:19:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T19:19:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T19:19:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T19:19:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T19:19:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T19:19:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T19:20:38", "source": "nginx", "category": "benign", "severity": "info", "message": "66.37.84.110 - - \"GET /dashboard HTTP/1.1\" 200 7517", "src_ip": "66.37.84.110", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-15T19:25:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.0.95 port 44368 ssh2", "src_ip": "10.0.0.95", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-15T19:27:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 44348 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:27:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 41197 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:27:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 52700 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:27:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 40134 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:27:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 50921 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:27:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 57116 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:27:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 57058 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:27:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 41442 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:27:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 58925 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 49390 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 41511 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 59473 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 48966 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 40499 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 57777 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 46876 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 46571 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 50239 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 57441 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 54454 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 44892 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 43855 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 58337 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:28:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for nattapong from 45.137.21.9 port 43354 ssh2", "src_ip": "45.137.21.9", "user": "nattapong", "action": "login_failed"} {"timestamp": "2026-06-15T19:33:09", "source": "nginx", "category": "benign", "severity": "info", "message": "93.10.255.130 - - \"GET /static/app.js HTTP/1.1\" 200 3377", "src_ip": "93.10.255.130", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T19:41:34", "source": "nginx", "category": "benign", "severity": "info", "message": "73.160.167.199 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3376", "src_ip": "73.160.167.199", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-15T19:42:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=123.162.137.50 OUT= PROTO=TCP DPT=443", "src_ip": "123.162.137.50", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T19:45:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=83.51.99.76 OUT= PROTO=TCP DPT=80", "src_ip": "83.51.99.76", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T19:47:26", "source": "nginx", "category": "web_attack", "severity": "high", "message": "133.146.23.43 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 194", "src_ip": "133.146.23.43", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T19:47:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 49522 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 46025 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 51433 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 55464 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 40215 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 54719 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 58035 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 52961 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 44513 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 50722 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 40638 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 51908 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 42272 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 41060 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 45248 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:47:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 54086 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:48:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 55399 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:48:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 42169 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:48:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 50879 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:48:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.149 port 50703 ssh2", "src_ip": "10.0.0.149", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T19:48:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 43762 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:48:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 32.87.225.59 port 49947 ssh2", "src_ip": "32.87.225.59", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-15T19:50:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=39.33.215.250 OUT= PROTO=TCP DPT=443", "src_ip": "39.33.215.250", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T19:52:38", "source": "nginx", "category": "benign", "severity": "info", "message": "176.181.207.193 - - \"GET /api/products HTTP/1.1\" 200 4488", "src_ip": "176.181.207.193", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T19:56:20", "source": "nginx", "category": "benign", "severity": "info", "message": "11.117.126.156 - - \"GET / HTTP/1.1\" 200 6000", "src_ip": "11.117.126.156", "status": 200, "path": "/"} {"timestamp": "2026-06-15T19:56:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.206 port 55835 ssh2", "src_ip": "10.0.0.206", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T19:58:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.144 dst=193.27.228.114 dport=443 bytes=670 interval=60s", "src_ip": "10.0.3.144", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T19:59:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.144 dst=193.27.228.114 dport=443 bytes=682 interval=60s", "src_ip": "10.0.3.144", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T20:00:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.144 dst=193.27.228.114 dport=443 bytes=708 interval=60s", "src_ip": "10.0.3.144", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T20:01:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.144 dst=193.27.228.114 dport=443 bytes=461 interval=60s", "src_ip": "10.0.3.144", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T20:02:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.144 dst=193.27.228.114 dport=443 bytes=206 interval=60s", "src_ip": "10.0.3.144", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T20:03:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.144 dst=193.27.228.114 dport=443 bytes=670 interval=60s", "src_ip": "10.0.3.144", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T20:04:03", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.144 dst=193.27.228.114 dport=443 bytes=218 interval=60s", "src_ip": "10.0.3.144", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-15T20:06:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=190.131.25.94 OUT= PROTO=TCP DPT=80", "src_ip": "190.131.25.94", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T20:10:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=140.10.199.224 OUT= PROTO=TCP DPT=443", "src_ip": "140.10.199.224", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T20:15:59", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: guest : TTY=pts/0 ; PWD=/home/guest ; USER=root ; COMMAND=/bin/bash", "user": "guest", "host": "app-02", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-15T20:16:06", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.5.173 dst=45.137.21.9 bytes=4160749568 proto=TCP dport=443 duration=580s", "src_ip": "10.0.5.173", "dst_ip": "45.137.21.9", "bytes_mb": 3968, "off_hours": false} {"timestamp": "2026-06-15T20:25:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40562 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:25:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58296 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:25:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41952 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:25:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44377 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:25:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 49656 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:25:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 51824 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:25:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 44723 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:26:01", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 185.220.101.34 port 51234 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T20:26:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53797 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:31:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.73 port 59919 ssh2", "src_ip": "10.0.4.73", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T20:33:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.249 port 44753 ssh2", "src_ip": "10.0.0.249", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T20:35:41", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/bin/bash", "user": "somchai", "host": "db-03", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-15T20:38:36", "source": "nginx", "category": "benign", "severity": "info", "message": "182.11.174.105 - - \"GET /api/products HTTP/1.1\" 200 5339", "src_ip": "182.11.174.105", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-15T20:40:51", "source": "nginx", "category": "benign", "severity": "info", "message": "210.99.175.77 - - \"GET /login HTTP/1.1\" 200 4106", "src_ip": "210.99.175.77", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T20:46:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=166.21.229.247 OUT= PROTO=TCP DPT=80", "src_ip": "166.21.229.247", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T20:59:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 43485 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 59720 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 41344 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 54606 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 42453 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 57483 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46240 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 44188 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 53703 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 55538 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 51236 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 45470 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 45035 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 54695 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 42218 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 53729 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 48274 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T20:59:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 51381 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:00:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 43847 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:00:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 56510 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:01:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.174 port 46762 ssh2", "src_ip": "10.0.3.174", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T21:02:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.5.107 port 51077 ssh2", "src_ip": "10.0.5.107", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T21:03:17", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: postgres : TTY=pts/0 ; PWD=/home/postgres ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "postgres", "host": "web-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-15T21:03:46", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "svc_backup", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-15T21:08:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=81.146.8.129 OUT= PROTO=TCP DPT=443", "src_ip": "81.146.8.129", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T21:09:41", "source": "nginx", "category": "benign", "severity": "info", "message": "112.160.142.64 - - \"GET / HTTP/1.1\" 200 412", "src_ip": "112.160.142.64", "status": 200, "path": "/"} {"timestamp": "2026-06-15T21:12:02", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.200 dst=209.141.56.12 bytes=7046430720 proto=TCP dport=443 duration=136s", "src_ip": "10.0.1.200", "dst_ip": "209.141.56.12", "bytes_mb": 6720, "off_hours": false} {"timestamp": "2026-06-15T21:12:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.5.2 port 40454 ssh2", "src_ip": "10.0.5.2", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-15T21:24:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.226 dst=209.141.56.12 dport=443 bytes=620 interval=30s", "src_ip": "10.0.1.226", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T21:24:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.226 dst=209.141.56.12 dport=443 bytes=418 interval=30s", "src_ip": "10.0.1.226", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T21:25:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.226 dst=209.141.56.12 dport=443 bytes=283 interval=30s", "src_ip": "10.0.1.226", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T21:25:59", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.226 dst=209.141.56.12 dport=443 bytes=738 interval=30s", "src_ip": "10.0.1.226", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T21:26:29", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.226 dst=209.141.56.12 dport=443 bytes=607 interval=30s", "src_ip": "10.0.1.226", "dst_ip": "209.141.56.12", "beacon_interval": 30} {"timestamp": "2026-06-15T21:27:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=57.153.118.225 OUT= PROTO=TCP DPT=443", "src_ip": "57.153.118.225", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T21:27:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=484 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T21:28:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 42057 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:28:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 51279 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:28:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 54612 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:28:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 42891 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:28:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 41979 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:28:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 54093 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:28:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 59272 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:28:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 59841 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:29:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 42158 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:29:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 48599 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T21:32:36", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/bin/su -", "user": "deploy", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-15T21:32:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=874 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T21:33:27", "source": "nginx", "category": "benign", "severity": "info", "message": "52.212.17.8 - - \"GET / HTTP/1.1\" 200 5369", "src_ip": "52.212.17.8", "status": 200, "path": "/"} {"timestamp": "2026-06-15T21:34:55", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T21:34:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T21:34:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T21:34:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T21:34:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T21:34:56", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T21:34:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T21:34:57", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T21:34:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T21:34:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T21:34:58", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T21:35:23", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.1.99 dst=91.219.236.18 bytes=7030702080 proto=TCP dport=443 duration=471s", "src_ip": "10.0.1.99", "dst_ip": "91.219.236.18", "bytes_mb": 6705, "off_hours": false} {"timestamp": "2026-06-15T21:35:30", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.95 port 41572 ssh2", "src_ip": "10.0.3.95", "user": "root", "action": "login_success"} {"timestamp": "2026-06-15T21:35:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.5.16 port 51711 ssh2", "src_ip": "10.0.5.16", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T21:36:53", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 403 332", "src_ip": "185.220.101.34", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T21:37:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=88.254.153.45 OUT= PROTO=TCP DPT=80", "src_ip": "88.254.153.45", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T21:37:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=451 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T21:42:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=255 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T21:46:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=203.117.246.171 OUT= PROTO=TCP DPT=80", "src_ip": "203.117.246.171", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T21:47:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=350 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T21:48:32", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T21:48:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T21:48:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T21:48:33", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T21:48:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T21:48:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T21:48:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T21:48:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T21:48:34", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T21:48:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T21:51:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 58052 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 46071 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 58204 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 52495 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 43388 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45546 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 58892 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 57998 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 46281 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45452 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 41301 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45919 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:51:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 53974 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:52:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 40699 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:52:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 47610 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-15T21:52:12", "source": "nginx", "category": "benign", "severity": "info", "message": "74.72.183.186 - - \"GET /static/app.js HTTP/1.1\" 200 929", "src_ip": "74.72.183.186", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T21:52:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=894 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T21:53:06", "source": "nginx", "category": "benign", "severity": "info", "message": "116.96.35.47 - - \"GET /login HTTP/1.1\" 200 2572", "src_ip": "116.96.35.47", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T21:57:36", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.238 port 42373 ssh2", "src_ip": "10.0.0.238", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-15T21:57:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=277 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T22:01:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=42.207.7.158 OUT= PROTO=TCP DPT=80", "src_ip": "42.207.7.158", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T22:02:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=30.84.224.193 OUT= PROTO=TCP DPT=443", "src_ip": "30.84.224.193", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T22:02:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=677 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T22:03:03", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.3.134 port 42853 ssh2", "src_ip": "10.0.3.134", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-15T22:07:54", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.61 dst=193.27.228.114 dport=443 bytes=751 interval=300s", "src_ip": "10.0.2.61", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-15T22:12:22", "source": "nginx", "category": "benign", "severity": "info", "message": "91.70.138.16 - - \"GET /login HTTP/1.1\" 200 1561", "src_ip": "91.70.138.16", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T22:17:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.2.31 port 52836 ssh2", "src_ip": "10.0.2.31", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-15T22:21:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 56972 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 57662 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 44142 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 41663 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 57662 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 59886 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 42430 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 57205 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 48557 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 42738 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 57986 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:21:27", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for admin from 154.245.202.233 port 51234 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-15T22:21:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for admin from 154.245.202.233 port 43065 ssh2", "src_ip": "154.245.202.233", "user": "admin", "action": "login_failed"} {"timestamp": "2026-06-15T22:22:21", "source": "nginx", "category": "benign", "severity": "info", "message": "172.153.162.35 - - \"GET /dashboard HTTP/1.1\" 200 7850", "src_ip": "172.153.162.35", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-15T22:22:59", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 22", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-15T22:31:12", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.146 port 40888 ssh2", "src_ip": "10.0.4.146", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-15T22:34:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 54214 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 56658 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 43232 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 45842 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:15", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 50495 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 46671 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 52151 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 52500 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 41465 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 46085 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 43811 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 50838 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 52776 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 52182 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 46774 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 44642 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 48933 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 40155 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 40510 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 41466 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 58695 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:34:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 40335 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:35:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 48066 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:35:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 48460 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:35:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 185.220.101.34 port 50149 ssh2", "src_ip": "185.220.101.34", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-15T22:39:59", "source": "nginx", "category": "benign", "severity": "info", "message": "31.235.148.166 - - \"GET /login HTTP/1.1\" 200 1646", "src_ip": "31.235.148.166", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T22:42:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=58.81.84.184 OUT= PROTO=TCP DPT=80", "src_ip": "58.81.84.184", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T22:48:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=163.229.7.27 OUT= PROTO=TCP DPT=443", "src_ip": "163.229.7.27", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T22:51:06", "source": "nginx", "category": "benign", "severity": "info", "message": "174.218.202.233 - - \"GET /dashboard HTTP/1.1\" 200 2677", "src_ip": "174.218.202.233", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-15T22:54:20", "source": "nginx", "category": "benign", "severity": "info", "message": "34.59.64.231 - - \"GET / HTTP/1.1\" 200 2082", "src_ip": "34.59.64.231", "status": 200, "path": "/"} {"timestamp": "2026-06-15T22:55:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=211.82.223.91 OUT= PROTO=TCP DPT=443", "src_ip": "211.82.223.91", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T22:56:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=181.120.44.173 OUT= PROTO=TCP DPT=80", "src_ip": "181.120.44.173", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T22:57:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T22:57:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T22:57:35", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T22:57:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T22:57:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T22:57:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T22:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T22:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T22:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T22:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T22:57:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=99.210.135.99 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "99.210.135.99", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T23:01:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=58.98.110.190 OUT= PROTO=TCP DPT=443", "src_ip": "58.98.110.190", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T23:04:52", "source": "nginx", "category": "benign", "severity": "info", "message": "131.167.79.135 - - \"GET /login HTTP/1.1\" 200 3132", "src_ip": "131.167.79.135", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T23:07:47", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=22.7.127.209 OUT= PROTO=TCP DPT=80", "src_ip": "22.7.127.209", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T23:08:15", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 293", "src_ip": "193.27.228.114", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-15T23:11:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=136.32.63.193 OUT= PROTO=TCP DPT=80", "src_ip": "136.32.63.193", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T23:21:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-15T23:21:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-15T23:21:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-15T23:21:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-15T23:21:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-15T23:21:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-15T23:21:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-15T23:21:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-15T23:21:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-15T23:21:40", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-15T23:21:41", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-15T23:21:42", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=27.12.188.84 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "27.12.188.84", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-15T23:21:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=34.87.220.139 OUT= PROTO=TCP DPT=443", "src_ip": "34.87.220.139", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T23:22:06", "source": "nginx", "category": "benign", "severity": "info", "message": "34.178.113.227 - - \"GET /login HTTP/1.1\" 200 5634", "src_ip": "34.178.113.227", "status": 200, "path": "/login"} {"timestamp": "2026-06-15T23:30:24", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/bin/bash", "user": "nattapong", "host": "bastion-01", "command": "/bin/bash", "action": "sudo"} {"timestamp": "2026-06-15T23:31:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.2.29 port 51437 ssh2", "src_ip": "10.0.2.29", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-15T23:38:19", "source": "nginx", "category": "benign", "severity": "info", "message": "174.85.60.126 - - \"GET /static/app.js HTTP/1.1\" 200 5134", "src_ip": "174.85.60.126", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T23:38:30", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=12.33.107.172 OUT= PROTO=TCP DPT=80", "src_ip": "12.33.107.172", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T23:42:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=36.136.126.198 OUT= PROTO=TCP DPT=80", "src_ip": "36.136.126.198", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T23:43:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=217.116.162.213 OUT= PROTO=TCP DPT=443", "src_ip": "217.116.162.213", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-15T23:55:15", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=216.159.110.60 OUT= PROTO=TCP DPT=80", "src_ip": "216.159.110.60", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T23:56:58", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=106.29.13.185 OUT= PROTO=TCP DPT=80", "src_ip": "106.29.13.185", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-15T23:57:46", "source": "nginx", "category": "benign", "severity": "info", "message": "108.55.232.97 - - \"GET /static/app.js HTTP/1.1\" 200 3840", "src_ip": "108.55.232.97", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-15T23:57:50", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=138.249.68.20 OUT= PROTO=TCP DPT=80", "src_ip": "138.249.68.20", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T00:01:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=865 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:01:40", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.0.47 port 57604 ssh2", "src_ip": "10.0.0.47", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-16T00:02:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=582 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:03:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=648 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:03:47", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.231 port 42149 ssh2", "src_ip": "10.0.5.231", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-16T00:04:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=729 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:05:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=662 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:06:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=323 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:07:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=453 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:08:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=430 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:09:03", "source": "nginx", "category": "web_attack", "severity": "high", "message": "140.112.237.198 - - \"GET /search?q= HTTP/1.1\" 200 99", "src_ip": "140.112.237.198", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-16T00:09:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=265 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:09:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=145.19.172.225 OUT= PROTO=TCP DPT=80", "src_ip": "145.19.172.225", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T00:10:35", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.81 dst=193.27.228.114 dport=443 bytes=546 interval=60s", "src_ip": "10.0.5.81", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T00:10:58", "source": "nginx", "category": "benign", "severity": "info", "message": "125.156.197.2 - - \"GET /api/products HTTP/1.1\" 200 1629", "src_ip": "125.156.197.2", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-16T00:12:46", "source": "nginx", "category": "benign", "severity": "info", "message": "153.60.241.136 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5610", "src_ip": "153.60.241.136", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T00:13:39", "source": "nginx", "category": "benign", "severity": "info", "message": "168.49.244.127 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7008", "src_ip": "168.49.244.127", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T00:15:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T00:15:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-16T00:15:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T00:15:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T00:15:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T00:15:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T00:15:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T00:15:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T00:15:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T00:16:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.61 port 52551 ssh2", "src_ip": "10.0.1.61", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-16T00:18:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=83.12.191.132 OUT= PROTO=TCP DPT=443", "src_ip": "83.12.191.132", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T00:23:45", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=198.114.178.230 OUT= PROTO=TCP DPT=80", "src_ip": "198.114.178.230", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T00:27:39", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 403 298", "src_ip": "193.27.228.114", "status": 403, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-16T00:28:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=221.144.113.21 OUT= PROTO=TCP DPT=80", "src_ip": "221.144.113.21", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T00:28:52", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=71.242.134.214 OUT= PROTO=TCP DPT=80", "src_ip": "71.242.134.214", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T00:31:25", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=184.180.74.132 OUT= PROTO=TCP DPT=443", "src_ip": "184.180.74.132", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T00:34:23", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.3.28 port 58411 ssh2", "src_ip": "10.0.3.28", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-16T00:36:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T00:36:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T00:36:43", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T00:36:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T00:36:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T00:36:44", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T00:36:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T00:36:45", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=91.219.236.18 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "91.219.236.18", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T00:39:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.160 port 50335 ssh2", "src_ip": "10.0.2.160", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-16T00:41:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=180.173.95.121 OUT= PROTO=TCP DPT=80", "src_ip": "180.173.95.121", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T00:43:34", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=49.48.200.50 OUT= PROTO=TCP DPT=443", "src_ip": "49.48.200.50", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T00:47:08", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T00:47:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T00:47:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T00:47:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T00:47:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T00:47:09", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T00:47:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T00:47:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T00:47:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T00:47:10", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T00:51:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=26.17.38.242 OUT= PROTO=TCP DPT=80", "src_ip": "26.17.38.242", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T00:52:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.82 dst=45.137.21.9 dport=443 bytes=798 interval=30s", "src_ip": "10.0.5.82", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T00:52:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=19.115.88.231 OUT= PROTO=TCP DPT=80", "src_ip": "19.115.88.231", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T00:52:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.82 dst=45.137.21.9 dport=443 bytes=688 interval=30s", "src_ip": "10.0.5.82", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T00:52:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.5.37 port 59039 ssh2", "src_ip": "10.0.5.37", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-16T00:53:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.82 dst=45.137.21.9 dport=443 bytes=714 interval=30s", "src_ip": "10.0.5.82", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T00:53:45", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.82 dst=45.137.21.9 dport=443 bytes=743 interval=30s", "src_ip": "10.0.5.82", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T00:54:15", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.82 dst=45.137.21.9 dport=443 bytes=361 interval=30s", "src_ip": "10.0.5.82", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T00:55:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T00:55:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T00:55:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T00:55:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T00:55:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T00:55:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-16T00:55:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T00:55:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T00:55:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T00:55:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T00:55:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T00:56:56", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.1.242 port 59656 ssh2", "src_ip": "10.0.1.242", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-16T01:07:02", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T01:07:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T01:07:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T01:07:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T01:07:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T01:07:03", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T01:07:04", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T01:07:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T01:10:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=88.4.153.239 OUT= PROTO=TCP DPT=80", "src_ip": "88.4.153.239", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T01:10:12", "source": "nginx", "category": "benign", "severity": "info", "message": "14.193.34.187 - - \"GET / HTTP/1.1\" 200 3382", "src_ip": "14.193.34.187", "status": 200, "path": "/"} {"timestamp": "2026-06-16T01:13:50", "source": "nginx", "category": "benign", "severity": "info", "message": "127.164.96.252 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2156", "src_ip": "127.164.96.252", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T01:15:51", "source": "nginx", "category": "benign", "severity": "info", "message": "26.40.165.202 - - \"GET /dashboard HTTP/1.1\" 200 1010", "src_ip": "26.40.165.202", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T01:23:15", "source": "nginx", "category": "benign", "severity": "info", "message": "125.199.244.51 - - \"GET /static/app.js HTTP/1.1\" 200 6500", "src_ip": "125.199.244.51", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T01:23:35", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "deploy", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-16T01:24:40", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.5.56 port 52427 ssh2", "src_ip": "10.0.5.56", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T01:31:14", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=212.226.176.228 OUT= PROTO=TCP DPT=443", "src_ip": "212.226.176.228", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T01:31:35", "source": "nginx", "category": "benign", "severity": "info", "message": "147.194.117.64 - - \"GET /dashboard HTTP/1.1\" 200 3035", "src_ip": "147.194.117.64", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T01:39:49", "source": "nginx", "category": "web_attack", "severity": "high", "message": "126.89.135.234 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 301", "src_ip": "126.89.135.234", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T01:47:41", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.3.10 port 40976 ssh2", "src_ip": "10.0.3.10", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-16T01:48:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 49250 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:48:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 52710 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:48:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 55339 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:48:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 44653 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:48:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 42180 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 58335 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 55793 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 46632 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 44968 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 45163 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 54016 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 50821 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 52156 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 50483 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 48771 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 55888 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 45857 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 46816 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 52591 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 59415 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 50376 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 51172 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:38", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for svc_backup from 193.27.228.114 port 51234 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-16T01:49:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 47273 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:49:52", "source": "nginx", "category": "benign", "severity": "info", "message": "51.76.1.26 - - \"GET /login HTTP/1.1\" 200 4586", "src_ip": "51.76.1.26", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T01:49:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 193.27.228.114 port 42006 ssh2", "src_ip": "193.27.228.114", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T01:51:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=143.202.25.169 OUT= PROTO=TCP DPT=443", "src_ip": "143.202.25.169", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T01:54:29", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: svc_backup : TTY=pts/0 ; PWD=/home/svc_backup ; USER=root ; COMMAND=/bin/su -", "user": "svc_backup", "host": "app-02", "command": "/bin/su -", "action": "sudo"} {"timestamp": "2026-06-16T02:01:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=95.151.242.230 OUT= PROTO=TCP DPT=443", "src_ip": "95.151.242.230", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T02:01:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=104.17.19.146 OUT= PROTO=TCP DPT=443", "src_ip": "104.17.19.146", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T02:05:26", "source": "nginx", "category": "benign", "severity": "info", "message": "157.20.249.67 - - \"GET /login HTTP/1.1\" 200 5183", "src_ip": "157.20.249.67", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T02:09:36", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=21.1.205.119 OUT= PROTO=TCP DPT=80", "src_ip": "21.1.205.119", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T02:10:12", "source": "nginx", "category": "benign", "severity": "info", "message": "28.198.25.99 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 831", "src_ip": "28.198.25.99", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T02:10:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 56153 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 49017 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 52642 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 49287 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 53660 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 43517 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 59023 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 44855 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 43936 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:10:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 41116 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:11:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for somchai from 132.245.148.75 port 52760 ssh2", "src_ip": "132.245.148.75", "user": "somchai", "action": "login_failed"} {"timestamp": "2026-06-16T02:13:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.252 port 47012 ssh2", "src_ip": "10.0.3.252", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-16T02:14:55", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.50 port 51874 ssh2", "src_ip": "10.0.0.50", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T02:17:43", "source": "nginx", "category": "benign", "severity": "info", "message": "113.4.151.31 - - \"GET /dashboard HTTP/1.1\" 200 2610", "src_ip": "113.4.151.31", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T02:17:53", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=124.12.197.162 OUT= PROTO=TCP DPT=443", "src_ip": "124.12.197.162", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T02:18:23", "source": "nginx", "category": "benign", "severity": "info", "message": "148.233.22.73 - - \"GET /api/products HTTP/1.1\" 200 346", "src_ip": "148.233.22.73", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-16T02:24:56", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.141 dst=45.137.21.9 bytes=3847225344 proto=TCP dport=443 duration=509s", "src_ip": "10.0.0.141", "dst_ip": "45.137.21.9", "bytes_mb": 3669, "off_hours": true} {"timestamp": "2026-06-16T02:26:15", "source": "nginx", "category": "benign", "severity": "info", "message": "11.91.171.88 - - \"GET / HTTP/1.1\" 200 6168", "src_ip": "11.91.171.88", "status": 200, "path": "/"} {"timestamp": "2026-06-16T02:31:17", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.0.161 dst=91.219.236.18 bytes=7116685312 proto=TCP dport=443 duration=513s", "src_ip": "10.0.0.161", "dst_ip": "91.219.236.18", "bytes_mb": 6787, "off_hours": true} {"timestamp": "2026-06-16T02:33:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.3.12 port 56561 ssh2", "src_ip": "10.0.3.12", "user": "root", "action": "login_success"} {"timestamp": "2026-06-16T02:33:31", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=202.34.78.239 OUT= PROTO=TCP DPT=443", "src_ip": "202.34.78.239", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T02:34:07", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=110.178.179.136 OUT= PROTO=TCP DPT=80", "src_ip": "110.178.179.136", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T02:34:37", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=191.38.53.85 OUT= PROTO=TCP DPT=443", "src_ip": "191.38.53.85", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T02:35:42", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.4.174 port 40554 ssh2", "src_ip": "10.0.4.174", "user": "root", "action": "login_success"} {"timestamp": "2026-06-16T02:38:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.183 dst=193.27.228.114 dport=443 bytes=678 interval=60s", "src_ip": "10.0.0.183", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T02:39:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.183 dst=193.27.228.114 dport=443 bytes=621 interval=60s", "src_ip": "10.0.0.183", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T02:40:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.183 dst=193.27.228.114 dport=443 bytes=346 interval=60s", "src_ip": "10.0.0.183", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T02:41:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.183 dst=193.27.228.114 dport=443 bytes=652 interval=60s", "src_ip": "10.0.0.183", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T02:42:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.201 dst=193.27.228.114 dport=443 bytes=208 interval=300s", "src_ip": "10.0.5.201", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-16T02:42:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.183 dst=193.27.228.114 dport=443 bytes=456 interval=60s", "src_ip": "10.0.0.183", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T02:43:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.183 dst=193.27.228.114 dport=443 bytes=532 interval=60s", "src_ip": "10.0.0.183", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T02:44:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.183 dst=193.27.228.114 dport=443 bytes=899 interval=60s", "src_ip": "10.0.0.183", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T02:47:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.201 dst=193.27.228.114 dport=443 bytes=827 interval=300s", "src_ip": "10.0.5.201", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-16T02:47:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 45841 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 42806 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 58691 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 43805 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 49509 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 43363 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 49314 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 42755 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 56817 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 49277 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 56507 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:47:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 59021 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:48:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 49322 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:48:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 53506 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:48:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 59909 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:48:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 53001 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:48:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for oppa from 155.30.168.46 port 59040 ssh2", "src_ip": "155.30.168.46", "user": "oppa", "action": "login_failed"} {"timestamp": "2026-06-16T02:50:53", "source": "nginx", "category": "benign", "severity": "info", "message": "34.143.162.41 - - \"GET /login HTTP/1.1\" 200 3171", "src_ip": "34.143.162.41", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T02:51:34", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 200 189", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T02:52:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.201 dst=193.27.228.114 dport=443 bytes=643 interval=300s", "src_ip": "10.0.5.201", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-16T02:52:54", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.248 port 49981 ssh2", "src_ip": "10.0.4.248", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-16T02:52:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.130 port 58762 ssh2", "src_ip": "10.0.1.130", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-16T02:55:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.3.227 port 55883 ssh2", "src_ip": "10.0.3.227", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T02:55:59", "source": "nginx", "category": "benign", "severity": "info", "message": "195.68.209.230 - - \"GET /static/app.js HTTP/1.1\" 200 2615", "src_ip": "195.68.209.230", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T02:57:06", "source": "nginx", "category": "benign", "severity": "info", "message": "148.252.117.99 - - \"GET / HTTP/1.1\" 200 4959", "src_ip": "148.252.117.99", "status": 200, "path": "/"} {"timestamp": "2026-06-16T02:57:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.201 dst=193.27.228.114 dport=443 bytes=709 interval=300s", "src_ip": "10.0.5.201", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-16T03:02:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.201 dst=193.27.228.114 dport=443 bytes=407 interval=300s", "src_ip": "10.0.5.201", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-16T03:03:31", "source": "nginx", "category": "benign", "severity": "info", "message": "18.200.80.242 - - \"GET /static/app.js HTTP/1.1\" 200 1921", "src_ip": "18.200.80.242", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T03:07:06", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.201 dst=193.27.228.114 dport=443 bytes=819 interval=300s", "src_ip": "10.0.5.201", "dst_ip": "193.27.228.114", "beacon_interval": 300} {"timestamp": "2026-06-16T03:07:24", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.2.142 port 56768 ssh2", "src_ip": "10.0.2.142", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-16T03:09:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 45904 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 58762 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 42851 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:26", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 52701 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 51405 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 54104 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 58455 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:35", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 54864 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 41949 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 41564 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:43", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 52947 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 53755 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:09:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 91.219.236.18 port 50850 ssh2", "src_ip": "91.219.236.18", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:10:46", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.28 port 44580 ssh2", "src_ip": "10.0.3.28", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-16T03:10:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 41131 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:10:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 49270 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:10:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 58534 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 44584 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 43350 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 41290 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 51806 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 41830 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 42093 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 53521 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 44321 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 51080 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 45353 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:21", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 42279 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 47700 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:23", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 53125 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 42036 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:11:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 193.27.228.114 port 53643 ssh2", "src_ip": "193.27.228.114", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T03:13:42", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 200 370", "src_ip": "193.27.228.114", "status": 200, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T03:14:20", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.140 port 40483 ssh2", "src_ip": "10.0.5.140", "user": "root", "action": "login_success"} {"timestamp": "2026-06-16T03:14:49", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.5.241 port 55587 ssh2", "src_ip": "10.0.5.241", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-16T03:19:23", "source": "nginx", "category": "benign", "severity": "info", "message": "157.193.176.105 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 796", "src_ip": "157.193.176.105", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T03:21:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.112 port 45513 ssh2", "src_ip": "10.0.1.112", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-16T03:24:00", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 228", "src_ip": "185.220.101.34", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T03:26:04", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.188 port 56273 ssh2", "src_ip": "10.0.3.188", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-16T03:30:05", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=60.211.95.218 OUT= PROTO=TCP DPT=443", "src_ip": "60.211.95.218", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T03:33:34", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.157 port 59405 ssh2", "src_ip": "10.0.0.157", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T03:35:36", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 200 176", "src_ip": "185.220.101.34", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-16T03:37:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for deploy from 10.0.2.189 port 49198 ssh2", "src_ip": "10.0.2.189", "user": "deploy", "action": "login_success"} {"timestamp": "2026-06-16T03:39:11", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=175.74.56.69 OUT= PROTO=TCP DPT=443", "src_ip": "175.74.56.69", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T03:41:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.0.25 port 43539 ssh2", "src_ip": "10.0.0.25", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-16T03:44:13", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T03:44:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T03:44:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T03:44:14", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T03:44:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T03:44:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T03:44:15", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T03:44:16", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T03:44:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.45 port 47975 ssh2", "src_ip": "10.0.5.45", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-16T03:47:21", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.1.144 port 45079 ssh2", "src_ip": "10.0.1.144", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-16T03:49:13", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=131.143.127.250 OUT= PROTO=TCP DPT=80", "src_ip": "131.143.127.250", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T03:54:33", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=126.110.210.25 OUT= PROTO=TCP DPT=80", "src_ip": "126.110.210.25", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T03:58:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=533 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T03:58:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=619 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T03:58:43", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 422", "src_ip": "193.27.228.114", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T03:59:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=661 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T03:59:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 48094 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 59599 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 56284 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=368 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T03:59:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 51055 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:32", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 48048 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 48346 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 55870 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:38", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 46190 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:42", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 48871 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:45", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 55043 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 44077 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 51186 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 58044 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 40107 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 42360 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 56221 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T03:59:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for svc_backup from 63.236.88.31 port 58043 ssh2", "src_ip": "63.236.88.31", "user": "svc_backup", "action": "login_failed"} {"timestamp": "2026-06-16T04:00:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=458 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T04:00:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=412 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T04:01:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=718 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T04:01:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=245 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T04:02:00", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.21 dst=45.137.21.9 dport=443 bytes=673 interval=30s", "src_ip": "10.0.2.21", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T04:04:47", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "deploy", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-16T04:07:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=702 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:07:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=305 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:08:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=212 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:08:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=787 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:09:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=491 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:09:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=680 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:10:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=690 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:10:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=651 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:11:21", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=548 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:11:45", "source": "nginx", "category": "benign", "severity": "info", "message": "195.160.176.3 - - \"GET /health HTTP/1.1\" 200 2491", "src_ip": "195.160.176.3", "status": 200, "path": "/health"} {"timestamp": "2026-06-16T04:11:51", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.5.243 dst=185.220.101.34 dport=443 bytes=388 interval=30s", "src_ip": "10.0.5.243", "dst_ip": "185.220.101.34", "beacon_interval": 30} {"timestamp": "2026-06-16T04:11:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.145 port 45992 ssh2", "src_ip": "10.0.5.145", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-16T04:14:47", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=149.240.243.144 OUT= PROTO=TCP DPT=80", "src_ip": "149.240.243.144", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T04:17:11", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.1.3 port 42326 ssh2", "src_ip": "10.0.1.3", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-16T04:17:53", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.187 port 58594 ssh2", "src_ip": "10.0.4.187", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-16T04:18:34", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.94 dst=91.219.236.18 dport=443 bytes=585 interval=300s", "src_ip": "10.0.2.94", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-16T04:20:22", "source": "nginx", "category": "benign", "severity": "info", "message": "133.116.8.137 - - \"GET /login HTTP/1.1\" 200 7021", "src_ip": "133.116.8.137", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T04:21:04", "source": "nginx", "category": "benign", "severity": "info", "message": "54.92.156.44 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 7095", "src_ip": "54.92.156.44", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T04:22:11", "source": "nginx", "category": "web_attack", "severity": "high", "message": "193.27.228.114 - - \"GET /search?q= HTTP/1.1\" 403 439", "src_ip": "193.27.228.114", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-16T04:23:34", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.94 dst=91.219.236.18 dport=443 bytes=671 interval=300s", "src_ip": "10.0.2.94", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-16T04:23:53", "source": "nginx", "category": "benign", "severity": "info", "message": "20.249.204.125 - - \"GET /static/app.js HTTP/1.1\" 200 5041", "src_ip": "20.249.204.125", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T04:28:34", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.94 dst=91.219.236.18 dport=443 bytes=553 interval=300s", "src_ip": "10.0.2.94", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-16T04:28:40", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=131.51.64.223 OUT= PROTO=TCP DPT=80", "src_ip": "131.51.64.223", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T04:33:34", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.94 dst=91.219.236.18 dport=443 bytes=835 interval=300s", "src_ip": "10.0.2.94", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-16T04:38:34", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.94 dst=91.219.236.18 dport=443 bytes=382 interval=300s", "src_ip": "10.0.2.94", "dst_ip": "91.219.236.18", "beacon_interval": 300} {"timestamp": "2026-06-16T04:41:39", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.4.141 port 52874 ssh2", "src_ip": "10.0.4.141", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T04:42:59", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.5.141 port 49757 ssh2", "src_ip": "10.0.5.141", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-16T04:45:12", "source": "nginx", "category": "benign", "severity": "info", "message": "12.110.198.133 - - \"GET /dashboard HTTP/1.1\" 200 596", "src_ip": "12.110.198.133", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T04:45:33", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.125 port 49998 ssh2", "src_ip": "10.0.2.125", "user": "root", "action": "login_success"} {"timestamp": "2026-06-16T04:47:45", "source": "nginx", "category": "benign", "severity": "info", "message": "215.232.147.188 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1255", "src_ip": "215.232.147.188", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T04:47:46", "source": "nginx", "category": "benign", "severity": "info", "message": "109.79.229.66 - - \"GET /static/app.js HTTP/1.1\" 200 256", "src_ip": "109.79.229.66", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T04:52:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 40641 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T04:52:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 58149 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T04:52:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 58610 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T04:52:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 43554 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T04:52:53", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 40047 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T04:52:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 46337 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T04:53:03", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 209.141.56.12 port 51234 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-16T04:53:05", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 50038 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T04:53:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 209.141.56.12 port 53921 ssh2", "src_ip": "209.141.56.12", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:01:23", "source": "nginx", "category": "benign", "severity": "info", "message": "137.24.201.77 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 3923", "src_ip": "137.24.201.77", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T05:06:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 48589 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:41", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 40470 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:44", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 50313 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 51933 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 58717 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 54519 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 56594 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:50", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 57613 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 52108 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 50109 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:06:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 47232 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:07:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 44287 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:07:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 53252 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:07:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 44286 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:07:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 40946 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:07:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 51026 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:07:16", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 45.137.21.9 port 51234 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-16T05:07:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 46039 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:07:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 45.137.21.9 port 49476 ssh2", "src_ip": "45.137.21.9", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T05:09:57", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.0.88 port 51031 ssh2", "src_ip": "10.0.0.88", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T05:10:44", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=142.208.52.7 OUT= PROTO=TCP DPT=80", "src_ip": "142.208.52.7", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T05:11:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T05:11:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T05:11:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T05:11:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T05:11:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T05:11:24", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T05:11:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T05:11:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T05:11:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-16T05:11:25", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T05:11:26", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T05:16:06", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=59.189.134.101 OUT= PROTO=TCP DPT=443", "src_ip": "59.189.134.101", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T05:16:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=195.60.94.82 OUT= PROTO=TCP DPT=80", "src_ip": "195.60.94.82", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T05:18:05", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.3.36 port 55225 ssh2", "src_ip": "10.0.3.36", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-16T05:19:33", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /search?q= HTTP/1.1\" 200 223", "src_ip": "185.220.101.34", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-16T05:20:35", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.1.39 port 41804 ssh2", "src_ip": "10.0.1.39", "user": "root", "action": "login_success"} {"timestamp": "2026-06-16T05:25:41", "source": "nginx", "category": "benign", "severity": "info", "message": "64.93.132.96 - - \"GET /health HTTP/1.1\" 200 2194", "src_ip": "64.93.132.96", "status": 200, "path": "/health"} {"timestamp": "2026-06-16T05:28:25", "source": "nginx", "category": "benign", "severity": "info", "message": "24.198.32.53 - - \"GET /static/app.js HTTP/1.1\" 200 3588", "src_ip": "24.198.32.53", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T05:30:22", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=134.197.62.3 OUT= PROTO=TCP DPT=80", "src_ip": "134.197.62.3", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T05:31:47", "source": "nginx", "category": "benign", "severity": "info", "message": "101.48.183.224 - - \"GET /static/app.js HTTP/1.1\" 200 7923", "src_ip": "101.48.183.224", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T05:32:43", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=65.104.190.204 OUT= PROTO=TCP DPT=443", "src_ip": "65.104.190.204", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T05:37:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.4.220 port 59308 ssh2", "src_ip": "10.0.4.220", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-16T05:42:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for oppa from 10.0.3.155 port 54224 ssh2", "src_ip": "10.0.3.155", "user": "oppa", "action": "login_success"} {"timestamp": "2026-06-16T05:43:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T05:43:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-16T05:43:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T05:43:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T05:43:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T05:43:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T05:43:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T05:43:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T05:43:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T05:43:23", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=185.220.101.34 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "185.220.101.34", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T05:44:02", "source": "nginx", "category": "benign", "severity": "info", "message": "208.62.165.39 - - \"GET / HTTP/1.1\" 200 7478", "src_ip": "208.62.165.39", "status": 200, "path": "/"} {"timestamp": "2026-06-16T05:44:35", "source": "nginx", "category": "benign", "severity": "info", "message": "175.168.65.172 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 6990", "src_ip": "175.168.65.172", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T05:44:38", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=92.226.218.213 OUT= PROTO=TCP DPT=443", "src_ip": "92.226.218.213", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T05:47:36", "source": "nginx", "category": "benign", "severity": "info", "message": "39.181.19.174 - - \"GET /login HTTP/1.1\" 200 5845", "src_ip": "39.181.19.174", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T05:48:34", "source": "nginx", "category": "benign", "severity": "info", "message": "186.145.207.71 - - \"GET / HTTP/1.1\" 200 4370", "src_ip": "186.145.207.71", "status": 200, "path": "/"} {"timestamp": "2026-06-16T05:49:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=36.244.117.212 OUT= PROTO=TCP DPT=443", "src_ip": "36.244.117.212", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T05:55:50", "source": "nginx", "category": "benign", "severity": "info", "message": "112.3.191.176 - - \"GET /dashboard HTTP/1.1\" 200 602", "src_ip": "112.3.191.176", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T05:56:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=206.171.201.90 OUT= PROTO=TCP DPT=443", "src_ip": "206.171.201.90", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T05:57:28", "source": "nginx", "category": "benign", "severity": "info", "message": "136.227.85.229 - - \"GET /static/app.js HTTP/1.1\" 200 7847", "src_ip": "136.227.85.229", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T05:58:59", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 47134 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 51773 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 47727 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 57485 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 45997 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48250 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 47952 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:11", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 40328 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 50260 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48294 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 48215 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 47921 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 40405 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 45706 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:19", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 55617 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:20", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 44108 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 41289 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T05:59:47", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for root from 209.141.56.12 port 53890 ssh2", "src_ip": "209.141.56.12", "user": "root", "action": "login_failed"} {"timestamp": "2026-06-16T06:02:56", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=62.110.225.220 OUT= PROTO=TCP DPT=443", "src_ip": "62.110.225.220", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T06:03:57", "source": "nginx", "category": "benign", "severity": "info", "message": "39.144.15.61 - - \"GET /dashboard HTTP/1.1\" 200 5952", "src_ip": "39.144.15.61", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T06:06:42", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=165.70.240.87 OUT= PROTO=TCP DPT=80", "src_ip": "165.70.240.87", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T06:06:54", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=182.108.148.17 OUT= PROTO=TCP DPT=80", "src_ip": "182.108.148.17", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T06:13:12", "source": "nginx", "category": "benign", "severity": "info", "message": "41.174.238.146 - - \"GET /health HTTP/1.1\" 200 5904", "src_ip": "41.174.238.146", "status": 200, "path": "/health"} {"timestamp": "2026-06-16T06:15:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.197 port 45369 ssh2", "src_ip": "10.0.1.197", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-16T06:15:20", "source": "nginx", "category": "benign", "severity": "info", "message": "133.65.100.173 - - \"GET /login HTTP/1.1\" 200 802", "src_ip": "133.65.100.173", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T06:17:46", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 55316 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:17:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47953 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:17:48", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 58627 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:17:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 40133 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:17:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 47772 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:17:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59247 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:17:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 41416 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:17:58", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 59083 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:17:59", "source": "nginx", "category": "benign", "severity": "info", "message": "37.197.72.41 - - \"GET /api/products HTTP/1.1\" 200 4951", "src_ip": "37.197.72.41", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-16T06:18:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 50244 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:18:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 48278 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:18:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 49080 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:18:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 49738 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:18:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53205 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:18:16", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for postgres from 185.220.101.34 port 51234 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-16T06:18:19", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T06:18:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T06:18:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T06:18:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T06:18:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T06:18:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T06:18:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T06:18:20", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T06:18:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T06:18:21", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T06:18:22", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=66.128.153.63 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "66.128.153.63", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T06:18:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 45582 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:18:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 185.220.101.34 port 53960 ssh2", "src_ip": "185.220.101.34", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:18:45", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.206 port 53085 ssh2", "src_ip": "10.0.1.206", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-16T06:19:18", "source": "nginx", "category": "web_attack", "severity": "high", "message": "211.101.39.186 - - \"GET /search?q= HTTP/1.1\" 403 340", "src_ip": "211.101.39.186", "status": 403, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-16T06:21:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=625 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:22:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=653 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:23:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=495 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:24:16", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=189.208.65.196 OUT= PROTO=TCP DPT=443", "src_ip": "189.208.65.196", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T06:24:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=367 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:25:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=634 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:25:37", "source": "nginx", "category": "web_attack", "severity": "high", "message": "110.121.147.178 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 403 213", "src_ip": "110.121.147.178", "status": 403, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T06:26:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=624 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:27:08", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=1' AND SLEEP(5)-- HTTP/1.1\" 500 309", "src_ip": "209.141.56.12", "status": 500, "path": "/api/products?id=1' AND SLEEP(5)--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T06:27:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=342 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:28:01", "source": "nginx", "category": "benign", "severity": "info", "message": "167.113.32.163 - - \"GET /health HTTP/1.1\" 200 4003", "src_ip": "167.113.32.163", "status": 200, "path": "/health"} {"timestamp": "2026-06-16T06:28:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=801 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:29:17", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=167.206.113.176 OUT= PROTO=TCP DPT=80", "src_ip": "167.206.113.176", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T06:29:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=812 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:30:28", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.188 dst=45.137.21.9 dport=443 bytes=288 interval=60s", "src_ip": "10.0.1.188", "dst_ip": "45.137.21.9", "beacon_interval": 60} {"timestamp": "2026-06-16T06:31:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=95.62.210.91 OUT= PROTO=TCP DPT=443", "src_ip": "95.62.210.91", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T06:32:05", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: somchai : TTY=pts/0 ; PWD=/home/somchai ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "somchai", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-16T06:36:37", "source": "nginx", "category": "benign", "severity": "info", "message": "217.119.114.67 - - \"GET / HTTP/1.1\" 200 2583", "src_ip": "217.119.114.67", "status": 200, "path": "/"} {"timestamp": "2026-06-16T06:37:54", "source": "nginx", "category": "benign", "severity": "info", "message": "59.242.237.9 - - \"GET / HTTP/1.1\" 200 5860", "src_ip": "59.242.237.9", "status": 200, "path": "/"} {"timestamp": "2026-06-16T06:40:06", "source": "nginx", "category": "benign", "severity": "info", "message": "16.148.120.94 - - \"GET /dashboard HTTP/1.1\" 200 6367", "src_ip": "16.148.120.94", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T06:44:11", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "nattapong", "host": "bastion-01", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-16T06:44:43", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.4 dst=45.137.21.9 bytes=3460300800 proto=TCP dport=443 duration=147s", "src_ip": "10.0.2.4", "dst_ip": "45.137.21.9", "bytes_mb": 3300, "off_hours": false} {"timestamp": "2026-06-16T06:45:25", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 43045 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:27", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 53122 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 46756 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:29", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 55416 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 54050 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 42109 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:33", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 55690 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45906 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:37", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 40943 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 44459 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.170 port 50134 ssh2", "src_ip": "10.0.4.170", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-16T06:45:49", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 44345 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:52", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 47417 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:45:55", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 49625 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:46:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 91.219.236.18 port 45624 ssh2", "src_ip": "91.219.236.18", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T06:49:15", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.2.199 port 52924 ssh2", "src_ip": "10.0.2.199", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-16T06:55:44", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.4.56 port 56576 ssh2", "src_ip": "10.0.4.56", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-16T06:58:26", "source": "nginx", "category": "benign", "severity": "info", "message": "128.71.142.201 - - \"GET /health HTTP/1.1\" 200 5593", "src_ip": "128.71.142.201", "status": 200, "path": "/health"} {"timestamp": "2026-06-16T07:05:16", "source": "nginx", "category": "web_attack", "severity": "high", "message": "103.149.157.242 - - \"GET /api/products?id='; DROP TABLE sessions;-- HTTP/1.1\" 403 365", "src_ip": "103.149.157.242", "status": 403, "path": "/api/products?id='; DROP TABLE sessions;--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T07:07:02", "source": "nginx", "category": "benign", "severity": "info", "message": "212.215.250.31 - - \"GET /login HTTP/1.1\" 200 2902", "src_ip": "212.215.250.31", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T07:10:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T07:10:49", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T07:10:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T07:10:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T07:10:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T07:10:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T07:10:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T07:10:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-16T07:10:50", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T07:10:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T07:10:51", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=45.137.21.9 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "45.137.21.9", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T07:20:48", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.110 dst=91.219.236.18 bytes=8194621440 proto=TCP dport=443 duration=375s", "src_ip": "10.0.2.110", "dst_ip": "91.219.236.18", "bytes_mb": 7815, "off_hours": false} {"timestamp": "2026-06-16T07:21:24", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=192.33.148.74 OUT= PROTO=TCP DPT=80", "src_ip": "192.33.148.74", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T07:21:55", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=173.165.161.39 OUT= PROTO=TCP DPT=443", "src_ip": "173.165.161.39", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T07:23:02", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=26.30.230.102 OUT= PROTO=TCP DPT=443", "src_ip": "26.30.230.102", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T07:34:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=91.133.104.172 OUT= PROTO=TCP DPT=443", "src_ip": "91.133.104.172", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T07:40:50", "source": "nginx", "category": "benign", "severity": "info", "message": "24.201.64.104 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 248", "src_ip": "24.201.64.104", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T07:40:57", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=118.230.13.98 OUT= PROTO=TCP DPT=80", "src_ip": "118.230.13.98", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T07:41:10", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.1.153 port 59450 ssh2", "src_ip": "10.0.1.153", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-16T07:43:09", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=185.89.33.151 OUT= PROTO=TCP DPT=80", "src_ip": "185.89.33.151", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T07:45:00", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=48.247.183.11 OUT= PROTO=TCP DPT=80", "src_ip": "48.247.183.11", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T07:48:32", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: nattapong : TTY=pts/0 ; PWD=/home/nattapong ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "nattapong", "host": "db-03", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-16T07:53:09", "source": "nginx", "category": "web_attack", "severity": "high", "message": "185.220.101.34 - - \"GET /api/products?id=UNION SELECT username,password FROM users-- HTTP/1.1\" 403 365", "src_ip": "185.220.101.34", "status": 403, "path": "/api/products?id=UNION SELECT username,password FROM users--", "attack_kind": "sqli"} {"timestamp": "2026-06-16T07:58:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=160.51.54.145 OUT= PROTO=TCP DPT=80", "src_ip": "160.51.54.145", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T08:00:26", "source": "nginx", "category": "benign", "severity": "info", "message": "184.169.196.194 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 1346", "src_ip": "184.169.196.194", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T08:01:58", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.2.254 dst=185.220.101.34 bytes=1254096896 proto=TCP dport=443 duration=438s", "src_ip": "10.0.2.254", "dst_ip": "185.220.101.34", "bytes_mb": 1196, "off_hours": false} {"timestamp": "2026-06-16T08:03:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.222 dst=91.219.236.18 dport=443 bytes=618 interval=60s", "src_ip": "10.0.1.222", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-16T08:04:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.222 dst=91.219.236.18 dport=443 bytes=552 interval=60s", "src_ip": "10.0.1.222", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-16T08:05:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.222 dst=91.219.236.18 dport=443 bytes=674 interval=60s", "src_ip": "10.0.1.222", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-16T08:06:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.222 dst=91.219.236.18 dport=443 bytes=731 interval=60s", "src_ip": "10.0.1.222", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-16T08:07:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.222 dst=91.219.236.18 dport=443 bytes=831 interval=60s", "src_ip": "10.0.1.222", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-16T08:08:20", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.1.222 dst=91.219.236.18 dport=443 bytes=645 interval=60s", "src_ip": "10.0.1.222", "dst_ip": "91.219.236.18", "beacon_interval": 60} {"timestamp": "2026-06-16T08:08:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 33.209.231.254 port 58045 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-16T08:08:31", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 33.209.231.254 port 47158 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-16T08:08:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 33.209.231.254 port 47231 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-16T08:08:34", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 33.209.231.254 port 43436 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-16T08:08:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 33.209.231.254 port 51465 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-16T08:08:39", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 33.209.231.254 port 43635 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-16T08:08:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 33.209.231.254 port 43520 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-16T08:08:46", "source": "auth", "category": "brute_force", "severity": "critical", "message": "Accepted password for deploy from 33.209.231.254 port 51234 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_success", "note": "success_after_bruteforce"} {"timestamp": "2026-06-16T08:08:51", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for deploy from 33.209.231.254 port 40902 ssh2", "src_ip": "33.209.231.254", "user": "deploy", "action": "login_failed"} {"timestamp": "2026-06-16T08:10:00", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.5.136 port 54259 ssh2", "src_ip": "10.0.5.136", "user": "root", "action": "login_success"} {"timestamp": "2026-06-16T08:10:09", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.204 port 48519 ssh2", "src_ip": "10.0.1.204", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T08:13:41", "source": "nginx", "category": "benign", "severity": "info", "message": "61.136.26.252 - - \"GET /dashboard HTTP/1.1\" 200 5345", "src_ip": "61.136.26.252", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T08:14:11", "source": "nginx", "category": "benign", "severity": "info", "message": "94.196.170.220 - - \"GET / HTTP/1.1\" 200 1371", "src_ip": "94.196.170.220", "status": 200, "path": "/"} {"timestamp": "2026-06-16T08:14:18", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.0.109 port 55953 ssh2", "src_ip": "10.0.0.109", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-16T08:17:28", "source": "nginx", "category": "benign", "severity": "info", "message": "53.95.160.48 - - \"GET /static/app.js HTTP/1.1\" 200 3595", "src_ip": "53.95.160.48", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T08:19:17", "source": "nginx", "category": "benign", "severity": "info", "message": "130.116.233.249 - - \"GET /health HTTP/1.1\" 200 4879", "src_ip": "130.116.233.249", "status": 200, "path": "/health"} {"timestamp": "2026-06-16T08:21:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T08:21:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T08:21:27", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T08:21:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T08:21:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T08:21:28", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T08:21:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T08:21:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T08:21:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-16T08:21:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T08:21:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T08:21:29", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=159.217.79.227 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "159.217.79.227", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T08:24:01", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.0.241 port 48490 ssh2", "src_ip": "10.0.0.241", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-16T08:24:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=6379 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 6379, "action": "drop"} {"timestamp": "2026-06-16T08:24:36", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=53 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 53, "action": "drop"} {"timestamp": "2026-06-16T08:24:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=21 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 21, "action": "drop"} {"timestamp": "2026-06-16T08:24:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T08:24:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T08:24:37", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T08:24:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-16T08:24:38", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=22 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 22, "action": "drop"} {"timestamp": "2026-06-16T08:24:39", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=193.27.228.114 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "193.27.228.114", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T08:25:39", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=175.211.160.254 OUT= PROTO=TCP DPT=443", "src_ip": "175.211.160.254", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T08:26:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for root from 10.0.2.238 port 55677 ssh2", "src_ip": "10.0.2.238", "user": "root", "action": "login_success"} {"timestamp": "2026-06-16T08:26:30", "source": "nginx", "category": "benign", "severity": "info", "message": "64.0.33.42 - - \"GET /health HTTP/1.1\" 200 506", "src_ip": "64.0.33.42", "status": 200, "path": "/health"} {"timestamp": "2026-06-16T08:26:48", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=40.97.205.161 OUT= PROTO=TCP DPT=443", "src_ip": "40.97.205.161", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T08:34:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.30 port 55254 ssh2", "src_ip": "10.0.1.30", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T08:39:20", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=18.89.99.85 OUT= PROTO=TCP DPT=443", "src_ip": "18.89.99.85", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T08:44:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=115.90.96.229 OUT= PROTO=TCP DPT=443", "src_ip": "115.90.96.229", "dst_port": 443, "action": "allow"} {"timestamp": "2026-06-16T08:44:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=532 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:44:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=846 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:45:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=597 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:45:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=894 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:46:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=336 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:46:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=540 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:46:49", "source": "nginx", "category": "web_attack", "severity": "high", "message": "209.141.56.12 - - \"GET /api/products?id=' OR '1'='1 HTTP/1.1\" 500 67", "src_ip": "209.141.56.12", "status": 500, "path": "/api/products?id=' OR '1'='1", "attack_kind": "sqli"} {"timestamp": "2026-06-16T08:47:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=379 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:47:45", "source": "nginx", "category": "benign", "severity": "info", "message": "47.161.92.200 - - \"GET / HTTP/1.1\" 200 4194", "src_ip": "47.161.92.200", "status": 200, "path": "/"} {"timestamp": "2026-06-16T08:47:47", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=850 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:48:17", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.247 dst=193.27.228.114 dport=443 bytes=525 interval=30s", "src_ip": "10.0.2.247", "dst_ip": "193.27.228.114", "beacon_interval": 30} {"timestamp": "2026-06-16T08:49:08", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.3.235 port 40639 ssh2", "src_ip": "10.0.3.235", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-16T08:50:06", "source": "nginx", "category": "benign", "severity": "info", "message": "89.37.62.67 - - \"GET /dashboard HTTP/1.1\" 200 6826", "src_ip": "89.37.62.67", "status": 200, "path": "/dashboard"} {"timestamp": "2026-06-16T08:58:55", "source": "nginx", "category": "benign", "severity": "info", "message": "105.13.175.83 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 2166", "src_ip": "105.13.175.83", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T09:00:04", "source": "nginx", "category": "benign", "severity": "info", "message": "38.61.202.211 - - \"GET /login HTTP/1.1\" 200 7984", "src_ip": "38.61.202.211", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T09:03:01", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=88.222.176.254 OUT= PROTO=TCP DPT=80", "src_ip": "88.222.176.254", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T09:05:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.206 dst=91.219.236.18 dport=443 bytes=875 interval=30s", "src_ip": "10.0.0.206", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-16T09:06:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.206 dst=91.219.236.18 dport=443 bytes=371 interval=30s", "src_ip": "10.0.0.206", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-16T09:06:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.206 dst=91.219.236.18 dport=443 bytes=385 interval=30s", "src_ip": "10.0.0.206", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-16T09:07:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.206 dst=91.219.236.18 dport=443 bytes=319 interval=30s", "src_ip": "10.0.0.206", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-16T09:07:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.206 dst=91.219.236.18 dport=443 bytes=410 interval=30s", "src_ip": "10.0.0.206", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-16T09:08:22", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.206 dst=91.219.236.18 dport=443 bytes=406 interval=30s", "src_ip": "10.0.0.206", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-16T09:08:52", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.0.206 dst=91.219.236.18 dport=443 bytes=588 interval=30s", "src_ip": "10.0.0.206", "dst_ip": "91.219.236.18", "beacon_interval": 30} {"timestamp": "2026-06-16T09:15:55", "source": "nginx", "category": "benign", "severity": "info", "message": "204.64.56.216 - - \"GET /static/app.js HTTP/1.1\" 200 620", "src_ip": "204.64.56.216", "status": 200, "path": "/static/app.js"} {"timestamp": "2026-06-16T09:19:29", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.1.160 port 42956 ssh2", "src_ip": "10.0.1.160", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-16T09:20:28", "source": "system", "category": "priv_esc", "severity": "critical", "message": "sudo: deploy : TTY=pts/0 ; PWD=/home/deploy ; USER=root ; COMMAND=/usr/bin/passwd root", "user": "deploy", "host": "app-02", "command": "/usr/bin/passwd root", "action": "sudo"} {"timestamp": "2026-06-16T09:21:26", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for guest from 10.0.4.190 port 57178 ssh2", "src_ip": "10.0.4.190", "user": "guest", "action": "login_success"} {"timestamp": "2026-06-16T09:25:29", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=163.229.75.230 OUT= PROTO=TCP DPT=80", "src_ip": "163.229.75.230", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T09:25:32", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=69.91.175.36 OUT= PROTO=TCP DPT=80", "src_ip": "69.91.175.36", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T09:27:08", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=59.164.243.129 OUT= PROTO=TCP DPT=80", "src_ip": "59.164.243.129", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T09:27:58", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for nattapong from 10.0.1.46 port 45143 ssh2", "src_ip": "10.0.1.46", "user": "nattapong", "action": "login_success"} {"timestamp": "2026-06-16T09:31:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.88 port 46828 ssh2", "src_ip": "10.0.3.88", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-16T09:31:32", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for admin from 10.0.0.4 port 40440 ssh2", "src_ip": "10.0.0.4", "user": "admin", "action": "login_success"} {"timestamp": "2026-06-16T09:31:34", "source": "firewall", "category": "data_exfil", "severity": "critical", "message": "OUTBOUND src=10.0.3.230 dst=193.27.228.114 bytes=694157312 proto=TCP dport=443 duration=563s", "src_ip": "10.0.3.230", "dst_ip": "193.27.228.114", "bytes_mb": 662, "off_hours": false} {"timestamp": "2026-06-16T09:32:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=5432 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 5432, "action": "drop"} {"timestamp": "2026-06-16T09:32:05", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3389 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3389, "action": "drop"} {"timestamp": "2026-06-16T09:32:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=3306 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 3306, "action": "drop"} {"timestamp": "2026-06-16T09:32:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=27017 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 27017, "action": "drop"} {"timestamp": "2026-06-16T09:32:06", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=443 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 443, "action": "drop"} {"timestamp": "2026-06-16T09:32:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=8080 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 8080, "action": "drop"} {"timestamp": "2026-06-16T09:32:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=25 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 25, "action": "drop"} {"timestamp": "2026-06-16T09:32:07", "source": "firewall", "category": "port_scan", "severity": "medium", "message": "DROP IN=209.141.56.12 OUT= PROTO=TCP DPT=80 FLAGS=SYN", "src_ip": "209.141.56.12", "dst_port": 80, "action": "drop"} {"timestamp": "2026-06-16T09:33:52", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for svc_backup from 10.0.5.184 port 47286 ssh2", "src_ip": "10.0.5.184", "user": "svc_backup", "action": "login_success"} {"timestamp": "2026-06-16T09:34:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.230 dst=185.220.101.34 dport=443 bytes=668 interval=300s", "src_ip": "10.0.3.230", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-16T09:35:32", "source": "nginx", "category": "benign", "severity": "info", "message": "169.15.254.228 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 4669", "src_ip": "169.15.254.228", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T09:36:02", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.4.118 port 59896 ssh2", "src_ip": "10.0.4.118", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-16T09:38:04", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=56.233.184.239 OUT= PROTO=TCP DPT=80", "src_ip": "56.233.184.239", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T09:38:17", "source": "nginx", "category": "web_attack", "severity": "high", "message": "91.219.236.18 - - \"GET /search?q= HTTP/1.1\" 200 446", "src_ip": "91.219.236.18", "status": 200, "path": "/search?q=", "attack_kind": "xss"} {"timestamp": "2026-06-16T09:39:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.230 dst=185.220.101.34 dport=443 bytes=203 interval=300s", "src_ip": "10.0.3.230", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-16T09:40:34", "source": "nginx", "category": "benign", "severity": "info", "message": "200.11.252.202 - - \"GET /api/orders?page=2 HTTP/1.1\" 200 5021", "src_ip": "200.11.252.202", "status": 200, "path": "/api/orders?page=2"} {"timestamp": "2026-06-16T09:43:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.105 dst=45.137.21.9 dport=443 bytes=281 interval=30s", "src_ip": "10.0.2.105", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T09:44:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.105 dst=45.137.21.9 dport=443 bytes=900 interval=30s", "src_ip": "10.0.2.105", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T09:44:09", "source": "nginx", "category": "benign", "severity": "info", "message": "69.139.136.206 - - \"GET / HTTP/1.1\" 200 695", "src_ip": "69.139.136.206", "status": 200, "path": "/"} {"timestamp": "2026-06-16T09:44:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.230 dst=185.220.101.34 dport=443 bytes=555 interval=300s", "src_ip": "10.0.3.230", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-16T09:44:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.105 dst=45.137.21.9 dport=443 bytes=896 interval=30s", "src_ip": "10.0.2.105", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T09:45:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.105 dst=45.137.21.9 dport=443 bytes=535 interval=30s", "src_ip": "10.0.2.105", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T09:45:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.105 dst=45.137.21.9 dport=443 bytes=391 interval=30s", "src_ip": "10.0.2.105", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T09:46:01", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.105 dst=45.137.21.9 dport=443 bytes=745 interval=30s", "src_ip": "10.0.2.105", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T09:46:31", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.2.105 dst=45.137.21.9 dport=443 bytes=545 interval=30s", "src_ip": "10.0.2.105", "dst_ip": "45.137.21.9", "beacon_interval": 30} {"timestamp": "2026-06-16T09:46:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 59813 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:46:56", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 57111 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:46:57", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 54948 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 44757 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:01", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 44814 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 49647 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:04", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 56398 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:06", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 51999 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:07", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 46238 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:08", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 46060 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 52586 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 49647 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 58525 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 54086 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 58637 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 58660 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:47:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for postgres from 171.215.192.223 port 46371 ssh2", "src_ip": "171.215.192.223", "user": "postgres", "action": "login_failed"} {"timestamp": "2026-06-16T09:48:50", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.2.234 port 59836 ssh2", "src_ip": "10.0.2.234", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-16T09:49:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.230 dst=185.220.101.34 dport=443 bytes=425 interval=300s", "src_ip": "10.0.3.230", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-16T09:50:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=133.140.48.204 OUT= PROTO=TCP DPT=80", "src_ip": "133.140.48.204", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T09:54:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.230 dst=185.220.101.34 dport=443 bytes=275 interval=300s", "src_ip": "10.0.3.230", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-16T09:59:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.230 dst=185.220.101.34 dport=443 bytes=290 interval=300s", "src_ip": "10.0.3.230", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-16T10:03:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.188 dst=193.27.228.114 dport=443 bytes=315 interval=60s", "src_ip": "10.0.4.188", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T10:04:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.188 dst=193.27.228.114 dport=443 bytes=690 interval=60s", "src_ip": "10.0.4.188", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T10:04:30", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.3.230 dst=185.220.101.34 dport=443 bytes=237 interval=300s", "src_ip": "10.0.3.230", "dst_ip": "185.220.101.34", "beacon_interval": 300} {"timestamp": "2026-06-16T10:05:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.188 dst=193.27.228.114 dport=443 bytes=241 interval=60s", "src_ip": "10.0.4.188", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T10:06:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.188 dst=193.27.228.114 dport=443 bytes=342 interval=60s", "src_ip": "10.0.4.188", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T10:07:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.188 dst=193.27.228.114 dport=443 bytes=894 interval=60s", "src_ip": "10.0.4.188", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T10:08:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.188 dst=193.27.228.114 dport=443 bytes=764 interval=60s", "src_ip": "10.0.4.188", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T10:09:19", "source": "firewall", "category": "c2_beacon", "severity": "critical", "message": "CONN src=10.0.4.188 dst=193.27.228.114 dport=443 bytes=319 interval=60s", "src_ip": "10.0.4.188", "dst_ip": "193.27.228.114", "beacon_interval": 60} {"timestamp": "2026-06-16T10:15:46", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=151.214.62.217 OUT= PROTO=TCP DPT=80", "src_ip": "151.214.62.217", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T10:17:10", "source": "nginx", "category": "benign", "severity": "info", "message": "136.93.143.102 - - \"GET /login HTTP/1.1\" 200 6345", "src_ip": "136.93.143.102", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T10:18:14", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for somchai from 10.0.1.195 port 45575 ssh2", "src_ip": "10.0.1.195", "user": "somchai", "action": "login_success"} {"timestamp": "2026-06-16T10:21:18", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=17.31.183.216 OUT= PROTO=TCP DPT=80", "src_ip": "17.31.183.216", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T10:22:47", "source": "nginx", "category": "benign", "severity": "info", "message": "96.75.40.60 - - \"GET /api/products HTTP/1.1\" 200 5411", "src_ip": "96.75.40.60", "status": 200, "path": "/api/products"} {"timestamp": "2026-06-16T10:24:01", "source": "nginx", "category": "benign", "severity": "info", "message": "93.77.240.34 - - \"GET / HTTP/1.1\" 200 5045", "src_ip": "93.77.240.34", "status": 200, "path": "/"} {"timestamp": "2026-06-16T10:24:10", "source": "nginx", "category": "benign", "severity": "info", "message": "115.135.8.135 - - \"GET /health HTTP/1.1\" 200 5737", "src_ip": "115.135.8.135", "status": 200, "path": "/health"} {"timestamp": "2026-06-16T10:27:35", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=213.14.18.29 OUT= PROTO=TCP DPT=80", "src_ip": "213.14.18.29", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T10:37:17", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for www-data from 10.0.3.104 port 47994 ssh2", "src_ip": "10.0.3.104", "user": "www-data", "action": "login_success"} {"timestamp": "2026-06-16T10:38:03", "source": "firewall", "category": "benign", "severity": "info", "message": "ALLOW IN=20.78.35.172 OUT= PROTO=TCP DPT=80", "src_ip": "20.78.35.172", "dst_port": 80, "action": "allow"} {"timestamp": "2026-06-16T10:43:58", "source": "nginx", "category": "benign", "severity": "info", "message": "213.200.113.222 - - \"GET /login HTTP/1.1\" 200 4674", "src_ip": "213.200.113.222", "status": 200, "path": "/login"} {"timestamp": "2026-06-16T10:47:06", "source": "auth", "category": "benign", "severity": "info", "message": "Accepted password for postgres from 10.0.5.78 port 41224 ssh2", "src_ip": "10.0.5.78", "user": "postgres", "action": "login_success"} {"timestamp": "2026-06-16T10:48:00", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 47429 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:02", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 52533 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 59736 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:03", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 49987 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:09", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 41655 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:10", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 57692 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:12", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 41349 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:13", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 47277 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:14", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 56462 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:16", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 51015 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:17", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 55592 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:18", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 44901 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:22", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 59501 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:24", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 47235 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:28", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 49495 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 52873 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:30", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 44850 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:36", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 56538 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:40", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 42787 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"} {"timestamp": "2026-06-16T10:48:54", "source": "auth", "category": "brute_force", "severity": "high", "message": "Failed password for www-data from 91.219.236.18 port 41615 ssh2", "src_ip": "91.219.236.18", "user": "www-data", "action": "login_failed"}