services.certificate |
4707dfea9416d96a71593f3aae9d7aab921ad04576867cb8b09318741647afbc |
|
services.extended_service_name |
RDP |
|
services.jarm.fingerprint |
26d26d16d26d26d22c26d26d26d26dfd9c9d14e4f4f67f94f0359f8b28f532 |
|
services.jarm.cipher_and_version_fingerprint |
26d26d16d26d26d22c26d26d26d26d |
|
services.jarm.tls_extensions_sha256 |
fd9c9d14e4f4f67f94f0359f8b28f532 |
|
services.jarm.observed_at |
2023-01-15T16:41:54.941919605Z |
|
services.observed_at |
2023-01-28T08:37:43.846445988Z |
|
services.perspective_id |
PERSPECTIVE_ORANGE |
|
services.port |
3389 |
|
services.rdp.version.raw |
524292 |
|
services.rdp.version.major |
5 |
|
services.rdp.version.minor |
0 |
|
services.rdp.protocol_flags.extended_client_data_supported |
true |
|
services.rdp.protocol_flags.dynvc_graphics_pipeline |
true |
|
services.rdp.protocol_flags.neg_resp_reserved |
true |
|
services.rdp.protocol_flags.restricted_admin_mode |
true |
|
services.rdp.protocol_flags.restricted_auth_mode |
false |
|
services.rdp.selected_security_protocol.standard_rdp |
true |
|
services.rdp.selected_security_protocol.tls |
true |
|
services.rdp.selected_security_protocol.raw_value |
1 |
|
services.rdp.selected_security_protocol.credssp |
false |
|
services.rdp.selected_security_protocol.rdstls |
false |
|
services.rdp.selected_security_protocol.credssp_early_auth |
false |
|
services.rdp.selected_security_protocol.error |
false |
|
services.rdp.selected_security_protocol.error_ssl_required |
false |
|
services.rdp.selected_security_protocol.error_ssl_forbidden |
false |
|
services.rdp.selected_security_protocol.error_ssl_cert_missing |
false |
|
services.rdp.selected_security_protocol.error_bad_flags |
false |
|
services.rdp.selected_security_protocol.error_hybrid_required |
false |
|
services.rdp.selected_security_protocol.error_ssl_user_auth_required |
false |
|
services.rdp.selected_security_protocol.error_unknown |
false |
|
services.rdp.x224_cc_pdu_srcref |
13330 |
|
services.rdp.connect_response.domain_parameters.max_channel_ids |
34 |
|
services.rdp.connect_response.domain_parameters.max_user_id_channels |
3 |
|
services.rdp.connect_response.domain_parameters.num_priorities |
1 |
|
services.rdp.connect_response.domain_parameters.max_provider_height |
1 |
|
services.rdp.connect_response.domain_parameters.max_mcspdu_size |
65528 |
|
services.rdp.connect_response.domain_parameters.domain_protocol_version |
2 |
|
services.rdp.connect_response.domain_parameters.max_token_ids |
0 |
|
services.rdp.connect_response.domain_parameters.min_throughput |
0 |
|
services.rdp.connect_response.connect_id |
0 |
|
services.service_name |
RDP |
|
services.source_ip |
167.94.145.57 |
|
services.tls.version_selected |
TLSv1_2 |
|
services.tls.cipher_selected |
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA |
|
services.tls.certificates.leaf_fp_sha_256 |
4707dfea9416d96a71593f3aae9d7aab921ad04576867cb8b09318741647afbc |
|
services.tls.certificates.leaf_data.subject_dn |
CN=WIN-P9NRMH5G6M8 |
|
services.tls.certificates.leaf_data.issuer_dn |
CN=WIN-P9NRMH5G6M8 |
|
services.tls.certificates.leaf_data.pubkey_bit_size |
2048 |
|
services.tls.certificates.leaf_data.pubkey_algorithm |
RSA |
|
services.tls.certificates.leaf_data.tbs_fingerprint |
33f2c97d8408cb5aaffdd8fc165671ea7c15858045626ddf88cb4aceab31e27d |
|
services.tls.certificates.leaf_data.fingerprint |
4707dfea9416d96a71593f3aae9d7aab921ad04576867cb8b09318741647afbc |
|
services.tls.certificates.leaf_data.issuer.common_name |
WIN-P9NRMH5G6M8 |
|
services.tls.certificates.leaf_data.subject.common_name |
WIN-P9NRMH5G6M8 |
|
services.tls.certificates.leaf_data.public_key.key_algorithm |
RSA |
|
services.tls.certificates.leaf_data.public_key.rsa.modulus |
uXketq4mxwToy+4KGI4NX0bNT7CosZyErSk2SfqO1LxGVfoAjDOewy4MYwI4o+omSaxfVYS/kIGSDiv4pcQXpXGhJ6rCvXjPzUo0cdE1hMMdndC6EOHX7YJkUAMBl02j8333XwnstpevD912EYFvznFQh6A8GeI8Fu6Lp5LI4/TrtpdPgzJTxx91FtdcvrCLukQO14dlMYkcWBReFiAdoi/FizBP2epCgSD61Zwe5pO+fMl4/3TkkI183QODCw5ci/B170b3AYNIIy9F01f0f7xGzDAI4Q5kFKkGBodLwD06E5vjpFxB4yBaN/tmR7hUWjsRGFrSIw2KcrrVBVsbLQ== |
|
services.tls.certificates.leaf_data.public_key.rsa.exponent |
AAEAAQ== |
|
services.tls.certificates.leaf_data.public_key.rsa.length |
256 |
|
services.tls.certificates.leaf_data.public_key.fingerprint |
d8e4f67c1fa2dcf7da73cb5c1dab49ad8391c74db643672fad0e211b1e4a4034 |
|
services.tls.certificates.leaf_data.signature.self_signed |
true |
|
services.tls.certificates.leaf_data.signature.signature_algorithm |
SHA256-RSA |
|
services.tls.server_key_exchange.ec_params.named_curve |
23 |
|
services.tls.ja3s |
8529fd8de0d7f73186ef5ea8b4531a76 |
|
services.transport_fingerprint.raw |
64000,128,true,MNWST,1460,false,false |
|
services.transport_protocol |
TCP |
|
services.truncated |
false |
|