Investigation Workspace

Entity: 3%7eab81c74b51922644 (Tls)

Entity Details
Type
Tls
Linked Entities
IPs Linked to TLS Fingerprint (2)
Hostnames Targeted
Hostname Request Count
www.darcherif.fr 28
Paths Targeted (with Hostname Counts)
Path Distinct Hostnames
sitemap.xml 1
sitemap.txt 1
robots.txt 1
index.php/tag/cps/ 1
index.php/tag/iot/ 1
index.php/2020/05/13/industrial-cyber-security-evf-2019-alexandre-darcherif/ 1
index.php/tag/cyber-security/ 1
index.php/category/non-classe/ 1
index.php/author/admin3157/ 1
index.php/category/cyberattacks/ 1
index.php/2020/01/24/industry-4-0-threat-landscape/ 1
index.php/category/cloud-security/ 1
index.php/category/industry-4-0/ 1
index.php/category/cybercrime/ 1
index.php/2020/01/24/industry-4-0-corrupted-smart-factories-examples/ 1
index.php/2023/04/27/ddos-what-is-it-how-does-it-work-and-how-to-be-protected/ 1
index.php/tag/industry-4-0/ 1
index.php/category/cybersecurity/ 1
ℹ️

Ignore

No malicious activity detected for this TLS fingerprint, zero threat requests, and no WAF flags or security alerts. Traffic appears to be legitimate browsing.

2026-01-13 13:17:44
ℹ️

Ignore

No detected threat requests, WAF flags, or security rule hits. Activity appears to be normal browsing and correlates with non-malicious IP activity.

2026-01-13 13:27:48
ℹ️

Ignore

No malicious activity detected, no WAF flags, and no security rule hits for this TLS fingerprint. Entity is clean.

2026-01-13 13:37:49
ℹ️

Ignore

No malicious activity detected, no WAF flags, and no security rule hits. Associated with normal website browsing patterns.

2026-01-13 13:47:46
ℹ️

Ignore

No malicious activity detected: zero threat requests, no WAF flags, and no security rule hits. Associated activity is benign.

2026-01-13 13:57:51
ℹ️

Ignore

No malicious activity detected for this TLS fingerprint; entity appears benign and does not warrant watchlist inclusion.

2026-01-13 14:08:00
ℹ️

Ignore

No malicious activity detected; requests are typical for benign browsing and there are no WAF flags or security rule hits for this TLS fingerprint.

2026-01-13 14:17:50
ℹ️

Watchlist

No direct malicious indicators, but associated with an IP address (157.180.49.120) that warrants continued monitoring due to its proximity to a blocklisted malicious IP.

2026-01-13 14:27:49
ℹ️

Watchlist

TLS fingerprint associated with IP 157.180.49.120, which is kept in watchlist due to proximity to a blocklisted malicious IP.

2026-01-14 09:59:06
ℹ️

Watchlist

AI identified as medium severity, but no recent malicious activity detected to warrant immediate block.

2026-01-14 10:08:59
ℹ️

Ignore

No activity (0 total requests) detected since being added to the watchlist, and no malicious behavior observed in the current period. Does not warrant continued monitoring based on current data.

2026-01-14 10:18:54
ℹ️

Ignore

No malicious activity detected and not currently on any watchlists.

2026-01-14 10:29:11
ℹ️

Ignore

No malicious activity detected; associated IP showed benign browsing behavior.

2026-01-14 10:38:48
ℹ️

Ignore

No detected malicious activity or WAF flags, indicating benign behavior.

2026-01-14 10:48:55
ℹ️

Ignore

No detected malicious activity, WAF flags, or security rule hits. Behavior consistent with a benign content crawler, correlating with a benign IP.

2026-01-14 11:08:59
ℹ️

Ignore

Associated with benign browsing patterns, no detected threats or WAF flags.

2026-01-14 11:18:58
ℹ️

Ignore

No malicious activity detected during the observed period.

2026-01-14 11:28:57
ℹ️

Watchlist

TLS fingerprint associated with an IP in close proximity to a blocklisted malicious IP (157.180.49.118); observed crawling behavior might be reconnaissance.

2026-01-14 11:39:08
ℹ️

Watchlist

No new threat requests or WAF flags, but previous AI assessment indicated medium confidence and severity, possibly correlated with a suspicious IP. Warrants continued monitoring.

2026-01-14 13:09:09
ℹ️

Ignore

Entity has recorded no activity (0 total requests, 0 threat requests) since being added to the watchlist. No current threat indicators.

2026-01-14 13:29:12
ℹ️

Watchlist

This TLS fingerprint is associated with IP 157.180.49.120, which is numerically close to a blocklisted IP, suggesting potential for related malicious activity.

2026-01-14 13:39:06
ℹ️

Ignore

Activity consists of legitimate web crawling (accessing sitemap, categories, tags) with no detected threats or WAF flags.

2026-01-14 14:19:05
ℹ️

Watchlist

No direct malicious activity detected in current data, but keeping for further observation as it appeared in the suspicious entities queue.

2026-01-14 14:29:07
ℹ️

Ignore

No malicious activity detected, no WAF flags, and no security rule hits. Associated with an IP showing legitimate browsing behavior.

2026-01-15 13:00:18
ℹ️

Watchlist

TLS fingerprint associated with an IP (157.180.49.120) in close proximity to a blocklisted IP, warrants further observation.

2026-01-15 13:10:21
ℹ️

Ignore

No detected threat requests, no WAF flagged paths, and no security rule hits were observed in the latest activity.

2026-01-16 22:52:18