services.certificate |
4da9487a02dbc6909879433672ed0dc7e0d0a05aa4800e4dbb3b40b2825b0f93 |
|
services.extended_service_name |
RDP |
|
services.jarm.observed_at |
2023-03-21T14:57:03.024972586Z |
|
services.labels |
network-administration |
|
services.labels |
remote-access |
|
services.observed_at |
2023-03-21T18:49:28.883334928Z |
|
services.perspective_id |
PERSPECTIVE_HE |
|
services.port |
3389 |
|
services.rdp.version.raw |
524295 |
|
services.rdp.version.major |
10 |
|
services.rdp.version.minor |
2 |
|
services.rdp.protocol_flags.extended_client_data_supported |
true |
|
services.rdp.protocol_flags.dynvc_graphics_pipeline |
true |
|
services.rdp.protocol_flags.neg_resp_reserved |
true |
|
services.rdp.protocol_flags.restricted_admin_mode |
true |
|
services.rdp.protocol_flags.restricted_auth_mode |
true |
|
services.rdp.selected_security_protocol.standard_rdp |
true |
|
services.rdp.selected_security_protocol.tls |
true |
|
services.rdp.selected_security_protocol.raw_value |
1 |
|
services.rdp.selected_security_protocol.credssp |
false |
|
services.rdp.selected_security_protocol.rdstls |
false |
|
services.rdp.selected_security_protocol.credssp_early_auth |
false |
|
services.rdp.selected_security_protocol.error |
false |
|
services.rdp.selected_security_protocol.error_ssl_required |
false |
|
services.rdp.selected_security_protocol.error_ssl_forbidden |
false |
|
services.rdp.selected_security_protocol.error_ssl_cert_missing |
false |
|
services.rdp.selected_security_protocol.error_bad_flags |
false |
|
services.rdp.selected_security_protocol.error_hybrid_required |
false |
|
services.rdp.selected_security_protocol.error_ssl_user_auth_required |
false |
|
services.rdp.selected_security_protocol.error_unknown |
false |
|
services.rdp.x224_cc_pdu_srcref |
13330 |
|
services.rdp.connect_response.domain_parameters.max_channel_ids |
34 |
|
services.rdp.connect_response.domain_parameters.max_user_id_channels |
3 |
|
services.rdp.connect_response.domain_parameters.num_priorities |
1 |
|
services.rdp.connect_response.domain_parameters.max_provider_height |
1 |
|
services.rdp.connect_response.domain_parameters.max_mcspdu_size |
65528 |
|
services.rdp.connect_response.domain_parameters.domain_protocol_version |
2 |
|
services.rdp.connect_response.domain_parameters.max_token_ids |
0 |
|
services.rdp.connect_response.domain_parameters.min_throughput |
0 |
|
services.rdp.connect_response.connect_id |
0 |
|
services.service_name |
RDP |
|
services.source_ip |
162.142.125.226 |
|
services.tls.version_selected |
TLSv1_2 |
|
services.tls.cipher_selected |
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 |
|
services.tls.certificates.leaf_fp_sha_256 |
4da9487a02dbc6909879433672ed0dc7e0d0a05aa4800e4dbb3b40b2825b0f93 |
|
services.tls.certificates.leaf_data.subject_dn |
CN=WIN-J9D866ESIJ2 |
|
services.tls.certificates.leaf_data.issuer_dn |
CN=WIN-J9D866ESIJ2 |
|
services.tls.certificates.leaf_data.pubkey_bit_size |
2048 |
|
services.tls.certificates.leaf_data.pubkey_algorithm |
RSA |
|
services.tls.certificates.leaf_data.tbs_fingerprint |
708178a765e328fd1ad6b44a0d45455da8097c2c66348aa9c1b5baeb95e3323b |
|
services.tls.certificates.leaf_data.fingerprint |
4da9487a02dbc6909879433672ed0dc7e0d0a05aa4800e4dbb3b40b2825b0f93 |
|
services.tls.certificates.leaf_data.issuer.common_name |
WIN-J9D866ESIJ2 |
|
services.tls.certificates.leaf_data.subject.common_name |
WIN-J9D866ESIJ2 |
|
services.tls.certificates.leaf_data.public_key.key_algorithm |
RSA |
|
services.tls.certificates.leaf_data.public_key.rsa.modulus |
3D1TxZOPxStJF9RW8ztyWQ3APUeelEfz42gezBo2+HzBV5X+78HXhZENPCSRZqBFa+tRE5uG+BGQ3qGcT0d8dZTuXJwa+nAoOS5hpxJrZcfldy2D1vnzjKXWAmHWGcveSU7lbt/UXq+yAM5XLc8poFyGHCLmIcL1WhRgMacGEoPXKTHha0RvaB6r2JRxQBaJ/gyHsm+T6XIBOwN8D6VPV80JUK8zGvIlGXalmJOBJn7dUymFyxc0nYpEo4RGddnLSh0mtilIpeACawruL4awy0Kb6h+VelIlRcSXqDnByKWuTYTP2vSwt7OLcmS/XtmRfZBOwuv7xfyH+EhKUoz1ew== |
|
services.tls.certificates.leaf_data.public_key.rsa.exponent |
AAEAAQ== |
|
services.tls.certificates.leaf_data.public_key.rsa.length |
256 |
|
services.tls.certificates.leaf_data.public_key.fingerprint |
715d07fb72c41d4f1bf4bf6b692add595d9d7c7e2529d835f2d73b89b2c26e71 |
|
services.tls.certificates.leaf_data.signature.self_signed |
true |
|
services.tls.certificates.leaf_data.signature.signature_algorithm |
SHA256-RSA |
|
services.tls.server_key_exchange.ec_params.named_curve |
29 |
|
services.tls.ja3s |
364ff14b04ef93c3b4cfa429d729c0d9 |
|
services.transport_fingerprint.raw |
64000,128,true,MNWST,1460,false,false |
|
services.transport_protocol |
TCP |
|
services.truncated |
false |
|