aboutsummaryrefslogtreecommitdiff
path: root/test/results/googledns_android10.pcap.out
blob: cf385a67295f0e46c3e6ffeef251f946e64a62c0 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
00487{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"googledns_android10.pcap","alias":"nDPId-test","max-flows-per-thread":2048,"max-idle-flows-per-thread":256,"tick-resolution":1000,"reader-thread-count":1,"idle-scan-period":10000,"generic-max-idle-time":600000,"icmp-max-idle-time":30000,"udp-max-idle-time":180000,"tcp-max-idle-time":7440000,"tcp-max-post-end-flow-time":120000,"max-packets-per-flow-to-send":15,"max-packets-per-flow-to-process":255}
00487{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1592552824409,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":1,"l3_proto":"ip4","src_ip":"8.8.8.8","dst_ip":"192.168.1.159","src_port":853,"dst_port":55856,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00437{"flow_id":1,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552824,"pkt_ts_usec":409182,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0gpUAAHcG7tcICAgIwKgBnwNV2jAOPHBKaWPSFIARAUT59wAAAQEIChWqa0r\/\/5Cw"}
00437{"flow_id":1,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":2,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552824,"pkt_ts_usec":632762,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0gzYAAHcG7jYICAgIwKgBnwNV2jAOPHBKaWPSFIARAUT5GAAAAQEIChWqbCn\/\/5Cw"}
00437{"flow_id":1,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":3,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552824,"pkt_ts_usec":856545,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0g5MAAHcG7dkICAgIwKgBnwNV2jAOPHBKaWPSFIARAUT4OAAAAQEIChWqbQn\/\/5Cw"}
00437{"flow_id":1,"flow_packet_id":4,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":4,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":296508,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0hHAAAHcG7PwICAgIwKgBnwNV2jAOPHBKaWPSFIARAUT2gAAAAQEIChWqbsH\/\/5Cw"}
00487{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":5,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":1,"flow_first_seen":1592552825913,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48044,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00451{"flow_id":2,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":5,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":913529,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA8tGBAAEAGuAjAqAGfCAgEBLusA1UTsXihAAAAAKAC\/\/9hlgAAAgQFtAQCCAr\/\/8zBAAAAAAEDAwg="}
00487{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":6,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":1,"flow_first_seen":1592552825913,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.8.8","src_port":56024,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00451{"flow_id":3,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":6,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":913790,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA8yAFAAEAGoGPAqAGfCAgICNrYA1WXsATAAAAAAKAC\/\/8uSAAAAgQFtAQCCAr\/\/8zBAAAAAAEDAwg="}
00451{"flow_id":2,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":7,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":926858,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA8q2cAAHcGygEICAQEwKgBnwNVu6wOvAEKE7F4oqAS6yBkegAAAgQFZAQCCAp\/X4MU\/\/\/MwQEDAwg="}
00451{"flow_id":3,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":8,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":927045,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA8xdcAAHYGrI0ICAgIwKgBnwNV2tjD\/e2fl7AEwaAS6yBjdQAAAgQFZAQCCApkDcpF\/\/\/MwQEDAwg="}
00439{"flow_id":2,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":9,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":928257,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0tGFAAEAGuA\/AqAGfCAgEBLusA1UTsXiiDrwBC4AQAVd8vQAAAQEICv\/\/zMV\/X4MU"}
00651{"flow_id":2,"flow_packet_id":4,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":10,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":928997,"pkt_caplen":220,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":220,"pkt_l4_len":186,"pkt":"EBMx8Tl2ag\/ahpuQCABFAADOtGJAAEAGt3TAqAGfCAgEBLusA1UTsXiiDrwBC4AYAVdpogAAAQEICv\/\/zMV\/X4MUFgMBAJUBAACRAwOw6eX3GPuUCseewx8KJQKq65uZZdDYuRYi0MWCjT+jCwAAHsArwC\/ALMAwzKnMqMAJwBPACsAUAJwAnQAvADUACgEAAEoAAAAPAA0AAApkbnMuZ29vZ2xlABcAAP8BAAEAAAoACAAGAB0AFwAYAAsAAgEAACMAAAANABQAEgQDCAQEAQUDCAUFAQgGBgECAQ=="}
00770{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":10,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":4,"flow_first_seen":1592552825913,"flow_last_seen":1592552825928,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":154,"flow_tot_l4_payload_len":154,"flow_avg_l4_payload_len":38,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48044,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"","unsafe_cipher":0,"cipher":"TLS_NULL_WITH_NULL_NULL"}}
00439{"flow_id":3,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":11,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":929178,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0yAJAAEAGoGrAqAGfCAgICNrYA1WXsATBw\/3toIAQAVd7uAAAAQEICv\/\/zMVkDcpF"}
00652{"flow_id":3,"flow_packet_id":4,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":12,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":929471,"pkt_caplen":220,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":220,"pkt_l4_len":186,"pkt":"EBMx8Tl2ag\/ahpuQCABFAADOyANAAEAGn8\/AqAGfCAgICNrYA1WXsATBw\/3toIAYAVdohAAAAQEICv\/\/zMVkDcpFFgMBAJUBAACRAwOVSYhvB5NCZzUc9GHHE6Pd9b9dT20UrbAk09jz7PnHSwAAHsArwC\/ALMAwzKnMqMAJwBPACsAUAJwAnQAvADUACgEAAEoAAAAPAA0AAApkbnMuZ29vZ2xlABcAAP8BAAEAAAoACAAGAB0AFwAYAAsAAgEAACMAAAANABQAEgQDCAQEAQUDCAUFAQgGBgECAQ=="}
00770{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":12,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":4,"flow_first_seen":1592552825913,"flow_last_seen":1592552825929,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":154,"flow_tot_l4_payload_len":154,"flow_avg_l4_payload_len":38,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.8.8","src_port":56024,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"","unsafe_cipher":0,"cipher":"TLS_NULL_WITH_NULL_NULL"}}
00438{"flow_id":2,"flow_packet_id":5,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":13,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":940289,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0q3UAAHgGyPsICAQEwKgBnwNVu6wOvAELE7F5PIAQAPB8fAAAAQEICn9fgyL\/\/8zF"}
00439{"flow_id":3,"flow_packet_id":5,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":14,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":941529,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0xdkAAHYGrJMICAgIwKgBnwNV2tjD\/e2gl7AFW4AQAPB7dgAAAQEICmQNylT\/\/8zF"}
02349{"flow_id":2,"flow_packet_id":6,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":15,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":957880,"pkt_caplen":1484,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1484,"pkt_l4_len":1450,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAW+q3sAAHgGw2sICAQEwKgBnwNVu6wOvAELE7F5PIAQAPCh8QAAAQEICn9fgzP\/\/8zFFgMDAD8CAAA7AwNe7G15nhrimki9bfrsYlGl8blRww\/L601ET1dOR1JEAQDALwAAEwAXAAD\/AQABAAALAAIBAAAjAAAWAwMKgAsACnwACnkABiUwggYhMIIFCaADAgECAhAvmt6tSZ\/54QIAAAAAayAjMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNVBAYTAlVTMR4wHAYDVQQKExVHb29nbGUgVHJ1c3QgU2VydmljZXMxEzARBgNVBAMTCkdUUyBDQSAxTzEwHhcNMjAwNTI2MTUyMDAyWhcNMjAwODE4MTUyMDAyWjBkMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNTW91bnRhaW4gVmlldzETMBEGA1UEChMKR29vZ2xlIExMQzETMBEGA1UEAxMKZG5zLmdvb2dsZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOSUeQONctZz3uIqdtC8TGzE8AMaYsmZY88YVzUreJdL\/0dCZYsl1UYc2OvENRHpKfNCZpRv3xMOZvi3kh0QIb5zzddzOkkBUd2hU7s3ZwZK+HaanofZZUCn6DHRVW+tAvbhDsfNhYq7nC6j\/GNW5VGjRotNORp5ATy1MpfZF93XgmaHNixqtpC\/0gM5Gwth6D+1fVJsvBEgZyIPBayP3lOd1yAvzdIkSpwWaZ+TKW+85OK4yyy7S2o1vCDDK3Zq6\/jUumhBP5SJmDA5tr4dukkEoqVyhPnxGcB4hDmwyVDU2U8rmqCGQULfKb12DBmiiJOYbm5pqVj1JBv0+p3j1E0CAwEAAaOCAu8wggLrMA4GA1UdDwEB\/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSFRNGvRXRy0wAb7J2sKkmYhLWe3zAfBgNVHSMEGDAWgBSY0fhuEOvPm+xgnxiQG6DrfQn9KzBoBggrBgEFBQcBAQRcMFowKwYIKwYBBQUHMAGGH2h0dHA6Ly9vY3NwLnBraS5nb29nL2d0czFvMWNvcmUwKwYIKwYBBQUHMAKGH2h0dHA6Ly9wa2kuZ29vZy9nc3IyL0dUUzFPMS5jcnQwgawGA1UdEQSBpDCBoYIKZG5zLmdvb2dsZYIQKi5kbnMuZ29vZ2xlLmNvbYILODg4OC5nb29nbGWCDmRucy5nb29nbGUuY29tghBkbnM2NC5kbnMuZ29vZ2xlhxAgAUhgSGAAAAAAAAAAAABkhxAgAUhgSGAAAAAAAAAAAGRkhxAgAUhgSGAAAAAAAAAAAIhEhxAgAUhgSGAAAAAAAAAAAIiIhwQICAQEhwQICAgIMCEGA1UdIAQaMBgwCAYGZ4EMAQICMAwGCisGAQQB1nkCBQMwMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5wa2kuZ29vZy9HVFMxTzFjb3JlLmNybDCCAQMGCisGAQQB1nkCBAIEgfQEgfEA7wB2AAe3XBvlfWj\/8bDGHSMVx7rmV3xXlLdq7rxhOhpp06IcAAABclHIpS8AAAQDAEcwRQIhAL8PRht0GjLwxvKgvt3ME7Lvn501gSRHUbzJgY3HddfrAiBITPBWXKB\/EsGN\/qthElwjtyifjXyQCtZL82ZOsBNAqgB1AF6nc\/nfVsDntTZIfdBJ4DJ6kZoMhKESEoQYdZaBcUVYAAABclHIo2oAAAQDAEYwRAIgW3oiEOXHmxVJukyPKedbFKLAHU+NWNHGdGVRZy3Vv9QCIBZ565g8plNNkx9OSGvGcmllJquFv0Vpmmf0ZrIkVQCpMA0GCSqGSIb3DQEBCwUAA4IBAQBP8NFNA2o7BvU4C0BZ\/YuA2G4="}
00827{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":15,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":6,"flow_first_seen":1592552825913,"flow_last_seen":1592552825957,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":1572,"flow_avg_l4_payload_len":262,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48044,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"b44baa8a20901c5663b3a9664ba8a767","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"}}
02354{"flow_id":2,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":16,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":957993,"pkt_caplen":1484,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1484,"pkt_l4_len":1450,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAW+q3wAAHgGw2oICAQEwKgBnwNVu6wOvAaVE7F5PIAQAPAEzwAAAQEICn9fgzP\/\/8zFBWU\/U1SwWFqB51XKOk\/9gYc9EfnV8DMmwcygUgaToHLYUMwUZiFSJ1LqRJEm3oknKcmGpn6E+8rpojBhPvTewD8kzc3KtWn0xIyDeDz+Z1J8g\/uv+o2If+iKyGWYGf4RT\/KFSb\/lYkCgp373jBd81x2dBToH41zJgQMiTcRji8A4I0eyWkRpuReYMwBKatDuD2J7yUI9b+O06es4KhBC9a+DKwwGcm20clrv8FMBPBA3oxgf2d7Tp3YHw5XBW1+9IPzq88tSTj+WKJs15ATWPHPRFsSXyMFQZgstMB5d3dOB2ANmme6AIIj99uss4gAETjCCBEowggMyoAMCAQICDQHjtJqhjYqpgSVpULgwDQYJKoZIhvcNAQELBQAwTDEgMB4GA1UECxMXR2xvYmFsU2lnbiBSb290IENBIC0gUjIxEzARBgNVBAoTCkdsb2JhbFNpZ24xEzARBgNVBAMTCkdsb2JhbFNpZ24wHhcNMTcwNjE1MDAwMDQyWhcNMjExMjE1MDAwMDQyWjBCMQswCQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMRMwEQYDVQQDEwpHVFMgQ0EgMU8xMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0BjPRdSLzdOc5EDvfrTdaSEbyc88jkx1uQ8xGYQ9njwp71ANEJNvBYCAnyqgvRJLAuE9n1gWJP4wnwt0d1WTHUv3TeGSghD2UawMw7IilA80a5gQSecLnYM53SDGHC3v0RhhZecjgyCoIxL\/0iR\/1C\/nRGpbTddQZrCvnkJjBfvgHMRjYa+fajP\/Ype9SNnTfBRn3HXcLmno+G14adC3EAW48THCOyT9GjN0+CPg7GsZihbG482kzQvbs6RZYDiIO60ducaMp1Mb\/LzZpKu83Txh15MVmO6BvY\/iZEcgQAZO16yX6LnAWRKhSSUj5O1wNCyltGN8+aM9g9HNbSSsBwIDAQABo4IBMzCCAS8wDgYDVR0PAQH\/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH\/AgEAMB0GA1UdDgQWBBSY0fhuEOvPm+xgnxiQG6DrfQn9KzAfBgNVHSMEGDAWgBSb4gdXZxwewGoG3lm0mi3f3BmGLjA1BggrBgEFBQcBAQQpMCcwJQYIKwYBBQUHMAGGGWh0dHA6Ly9vY3NwLnBraS5nb29nL2dzcjIwMgYDVR0fBCswKTAnoCWgI4YhaHR0cDovL2NybC5wa2kuZ29vZy9nc3IyL2dzcjIuY3JsMD8GA1UdIAQ4MDYwNAYGZ4EMAQICMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8vcGtpLmdvb2cvcmVwb3NpdG9yeS8wDQYJKoZIhvcNAQELBQADggEBABqAPjZ5+\/MuqUY3fV5UFjWux04Imf690TRpJlJmBz0KuknLYvTxGo78EU9olkx0K9Nn3rKjqgWNhE1MIGUPpZbaDRb4bDvbbwQjiGs6bMFgvWifcY7uLVg0B\/DVVOmGWf17Xg0hlPWMyaj42PKtzA8a85qnqQQn+aPJsP8CeGthusc1K+hW+k\/DHAzttjy0S+rtzOE87NwNjNY+m8pCWIvMFiEXQLyi1mbv2sQVW82JqpsJJucy0g1uZyACWxCwkAmcDB+erdg76qH8bOgQXAhSGVEqcbuserXdFe0ryQgqLIq0piGrY\/\/XUklQ0Im3rfKv+1CuL+GVDfNGrZ2c9coWAwMBLAwAASgDAB0g4nmrM262XiykqlB2xZzqc4FfMkSM5xnUvsKMyRbrTFQIBAEAc9yvpTXoneegkGptgrdLO8zLJfwWP3QvPGg="}
01129{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":16,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":7,"flow_first_seen":1592552825913,"flow_last_seen":1592552825957,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":2990,"flow_avg_l4_payload_len":427,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48044,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","server_names":"dns.google,*.dns.google.com,8888.google,dns.google.com,dns64.dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"b44baa8a20901c5663b3a9664ba8a767","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","issuerDN":"C=US, O=Google Trust Services, CN=GTS CA 1O1","issuerDN":"C=US, ST=California, L=Mountain View, O=Google LLC, CN=dns.google","fingerprint":"5B:59:09:FC:7D:50:E6:F7:D1:08:8E:57:42:A2:D8:AE:1F:03:FF:EC"}}
00767{"flow_id":2,"flow_packet_id":8,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":17,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":958075,"pkt_caplen":305,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":305,"pkt_l4_len":271,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAEjq30AAHgGyAQICAQEwKgBnwNVu6wOvAwfE7F5PIAYAPCBTwAAAQEICn9fgzP\/\/8zFWkXoaRZWKwjLSUJGN3CmDF5dRNLykDwG7pTkFkLN7gp\/102O6AmwwdVceRHgogGvAykqYxKCmAi77yZ4Ft3DRhWHkP57qZJu3+2PxOP2VPziPKgJ+WulpnZmEM\/6aXA72fn15Q\/r0IUSLwpglfA2aaOTek0bfdKz6On4IdcjxIKFGo635zNHz4MngRG9urLcfGYnSr8Qi7SwcOcGknBFO7H52eKxKLwygtnmepN8U5+eUSHT3eUeqARJbDeeVVg43xpyB\/9thjuefxarX+24DRIRgWkhS4nZrfqe\/D18PQYU\/eyjmTwWAwMABA4AAAA="}
02349{"flow_id":3,"flow_packet_id":6,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":18,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":959083,"pkt_caplen":1484,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1484,"pkt_l4_len":1450,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAW+xeoAAHYGpvgICAgIwKgBnwNV2tjD\/e2gl7AFW4AQAPBNlQAAAQEICmQNymX\/\/8zFFgMDAD8CAAA7AwNe7G15+krGjyXGxyOdK20AGJ3di6M5uQtET1dOR1JEAQDALwAAEwAXAAD\/AQABAAALAAIBAAAjAAAWAwMKgAsACnwACnkABiUwggYhMIIFCaADAgECAhAvmt6tSZ\/54QIAAAAAayAjMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNVBAYTAlVTMR4wHAYDVQQKExVHb29nbGUgVHJ1c3QgU2VydmljZXMxEzARBgNVBAMTCkdUUyBDQSAxTzEwHhcNMjAwNTI2MTUyMDAyWhcNMjAwODE4MTUyMDAyWjBkMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNTW91bnRhaW4gVmlldzETMBEGA1UEChMKR29vZ2xlIExMQzETMBEGA1UEAxMKZG5zLmdvb2dsZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOSUeQONctZz3uIqdtC8TGzE8AMaYsmZY88YVzUreJdL\/0dCZYsl1UYc2OvENRHpKfNCZpRv3xMOZvi3kh0QIb5zzddzOkkBUd2hU7s3ZwZK+HaanofZZUCn6DHRVW+tAvbhDsfNhYq7nC6j\/GNW5VGjRotNORp5ATy1MpfZF93XgmaHNixqtpC\/0gM5Gwth6D+1fVJsvBEgZyIPBayP3lOd1yAvzdIkSpwWaZ+TKW+85OK4yyy7S2o1vCDDK3Zq6\/jUumhBP5SJmDA5tr4dukkEoqVyhPnxGcB4hDmwyVDU2U8rmqCGQULfKb12DBmiiJOYbm5pqVj1JBv0+p3j1E0CAwEAAaOCAu8wggLrMA4GA1UdDwEB\/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSFRNGvRXRy0wAb7J2sKkmYhLWe3zAfBgNVHSMEGDAWgBSY0fhuEOvPm+xgnxiQG6DrfQn9KzBoBggrBgEFBQcBAQRcMFowKwYIKwYBBQUHMAGGH2h0dHA6Ly9vY3NwLnBraS5nb29nL2d0czFvMWNvcmUwKwYIKwYBBQUHMAKGH2h0dHA6Ly9wa2kuZ29vZy9nc3IyL0dUUzFPMS5jcnQwgawGA1UdEQSBpDCBoYIKZG5zLmdvb2dsZYIQKi5kbnMuZ29vZ2xlLmNvbYILODg4OC5nb29nbGWCDmRucy5nb29nbGUuY29tghBkbnM2NC5kbnMuZ29vZ2xlhxAgAUhgSGAAAAAAAAAAAABkhxAgAUhgSGAAAAAAAAAAAGRkhxAgAUhgSGAAAAAAAAAAAIhEhxAgAUhgSGAAAAAAAAAAAIiIhwQICAQEhwQICAgIMCEGA1UdIAQaMBgwCAYGZ4EMAQICMAwGCisGAQQB1nkCBQMwMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5wa2kuZ29vZy9HVFMxTzFjb3JlLmNybDCCAQMGCisGAQQB1nkCBAIEgfQEgfEA7wB2AAe3XBvlfWj\/8bDGHSMVx7rmV3xXlLdq7rxhOhpp06IcAAABclHIpS8AAAQDAEcwRQIhAL8PRht0GjLwxvKgvt3ME7Lvn501gSRHUbzJgY3HddfrAiBITPBWXKB\/EsGN\/qthElwjtyifjXyQCtZL82ZOsBNAqgB1AF6nc\/nfVsDntTZIfdBJ4DJ6kZoMhKESEoQYdZaBcUVYAAABclHIo2oAAAQDAEYwRAIgW3oiEOXHmxVJukyPKedbFKLAHU+NWNHGdGVRZy3Vv9QCIBZ565g8plNNkx9OSGvGcmllJquFv0Vpmmf0ZrIkVQCpMA0GCSqGSIb3DQEBCwUAA4IBAQBP8NFNA2o7BvU4C0BZ\/YuA2G4="}
00827{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":18,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":6,"flow_first_seen":1592552825913,"flow_last_seen":1592552825959,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":1572,"flow_avg_l4_payload_len":262,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.8.8","src_port":56024,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"b44baa8a20901c5663b3a9664ba8a767","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"}}
02356{"flow_id":3,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":19,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":960222,"pkt_caplen":1484,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1484,"pkt_l4_len":1450,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAW+xesAAHYGpvcICAgIwKgBnwNV2tjD\/fMql7AFW4AQAPCIOwAAAQEICmQNymX\/\/8zFBWU\/U1SwWFqB51XKOk\/9gYc9EfnV8DMmwcygUgaToHLYUMwUZiFSJ1LqRJEm3oknKcmGpn6E+8rpojBhPvTewD8kzc3KtWn0xIyDeDz+Z1J8g\/uv+o2If+iKyGWYGf4RT\/KFSb\/lYkCgp373jBd81x2dBToH41zJgQMiTcRji8A4I0eyWkRpuReYMwBKatDuD2J7yUI9b+O06es4KhBC9a+DKwwGcm20clrv8FMBPBA3oxgf2d7Tp3YHw5XBW1+9IPzq88tSTj+WKJs15ATWPHPRFsSXyMFQZgstMB5d3dOB2ANmme6AIIj99uss4gAETjCCBEowggMyoAMCAQICDQHjtJqhjYqpgSVpULgwDQYJKoZIhvcNAQELBQAwTDEgMB4GA1UECxMXR2xvYmFsU2lnbiBSb290IENBIC0gUjIxEzARBgNVBAoTCkdsb2JhbFNpZ24xEzARBgNVBAMTCkdsb2JhbFNpZ24wHhcNMTcwNjE1MDAwMDQyWhcNMjExMjE1MDAwMDQyWjBCMQswCQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMRMwEQYDVQQDEwpHVFMgQ0EgMU8xMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0BjPRdSLzdOc5EDvfrTdaSEbyc88jkx1uQ8xGYQ9njwp71ANEJNvBYCAnyqgvRJLAuE9n1gWJP4wnwt0d1WTHUv3TeGSghD2UawMw7IilA80a5gQSecLnYM53SDGHC3v0RhhZecjgyCoIxL\/0iR\/1C\/nRGpbTddQZrCvnkJjBfvgHMRjYa+fajP\/Ype9SNnTfBRn3HXcLmno+G14adC3EAW48THCOyT9GjN0+CPg7GsZihbG482kzQvbs6RZYDiIO60ducaMp1Mb\/LzZpKu83Txh15MVmO6BvY\/iZEcgQAZO16yX6LnAWRKhSSUj5O1wNCyltGN8+aM9g9HNbSSsBwIDAQABo4IBMzCCAS8wDgYDVR0PAQH\/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH\/AgEAMB0GA1UdDgQWBBSY0fhuEOvPm+xgnxiQG6DrfQn9KzAfBgNVHSMEGDAWgBSb4gdXZxwewGoG3lm0mi3f3BmGLjA1BggrBgEFBQcBAQQpMCcwJQYIKwYBBQUHMAGGGWh0dHA6Ly9vY3NwLnBraS5nb29nL2dzcjIwMgYDVR0fBCswKTAnoCWgI4YhaHR0cDovL2NybC5wa2kuZ29vZy9nc3IyL2dzcjIuY3JsMD8GA1UdIAQ4MDYwNAYGZ4EMAQICMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8vcGtpLmdvb2cvcmVwb3NpdG9yeS8wDQYJKoZIhvcNAQELBQADggEBABqAPjZ5+\/MuqUY3fV5UFjWux04Imf690TRpJlJmBz0KuknLYvTxGo78EU9olkx0K9Nn3rKjqgWNhE1MIGUPpZbaDRb4bDvbbwQjiGs6bMFgvWifcY7uLVg0B\/DVVOmGWf17Xg0hlPWMyaj42PKtzA8a85qnqQQn+aPJsP8CeGthusc1K+hW+k\/DHAzttjy0S+rtzOE87NwNjNY+m8pCWIvMFiEXQLyi1mbv2sQVW82JqpsJJucy0g1uZyACWxCwkAmcDB+erdg76qH8bOgQXAhSGVEqcbuserXdFe0ryQgqLIq0piGrY\/\/XUklQ0Im3rfKv+1CuL+GVDfNGrZ2c9coWAwMBLAwAASgDAB0gz7rMJbgrJvLNELNJ4ltNigCj+UX2TiWQMThYrp6byhkIBAEAqwkJBMouQT82rL\/jSgisqQw4wiLt1+Xmi+E="}
01129{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":19,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":7,"flow_first_seen":1592552825913,"flow_last_seen":1592552825960,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":2990,"flow_avg_l4_payload_len":427,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.8.8","src_port":56024,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","server_names":"dns.google,*.dns.google.com,8888.google,dns.google.com,dns64.dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"b44baa8a20901c5663b3a9664ba8a767","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","issuerDN":"C=US, O=Google Trust Services, CN=GTS CA 1O1","issuerDN":"C=US, ST=California, L=Mountain View, O=Google LLC, CN=dns.google","fingerprint":"5B:59:09:FC:7D:50:E6:F7:D1:08:8E:57:42:A2:D8:AE:1F:03:FF:EC"}}
00769{"flow_id":3,"flow_packet_id":8,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":20,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":960306,"pkt_caplen":305,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":305,"pkt_l4_len":271,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAEjxewAAHYGq5EICAgIwKgBnwNV2tjD\/fi0l7AFW4AYAPBBaAAAAQEICmQNymX\/\/8zFxYLVsh0XBPBon\/dZK5fwP0f+D6HQBgodlevFaX40Qojl6fN5kYFp\/IMamekDmny2Tg+MQYdHS+NKqsqN9JkaZdY57lJcoOtbiFZlorHig6Gur0c3O64+IY9\/yzForraiSJSH05G8FeV1u2pdTO3ohu1K2vcU4NSoV1T7GxWd4M4gz8nhxQnJzW1EK3wgWliMbyOJPXeTKIRwsf\/8siihdwQBVxH+fTy1LIc3v4onjL8JdSGFTqyv1emQ12oetaF0Y5mfXrLSAFsT4A5mNd1\/wWJpF9CmCjcQ20MzmMAtWB0t\/3WTT\/MWAwMABA4AAAA="}
00439{"flow_id":2,"flow_packet_id":9,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":21,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":963546,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0tGNAAEAGuA3AqAGfCAgEBLusA1UTsXk8DrwGlYAQAWJ2ZwAAAQEICv\/\/zM1\/X4Mz"}
00440{"flow_id":2,"flow_packet_id":10,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":22,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":963743,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0tGRAAEAGuAzAqAGfCAgEBLusA1UTsXk8DrwMH4AQAW1w0gAAAQEICv\/\/zM1\/X4Mz"}
00440{"flow_id":2,"flow_packet_id":11,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":23,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":963819,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0tGVAAEAGuAvAqAGfCAgEBLusA1UTsXk8DrwNDoAQAW1v4wAAAQEICv\/\/zM1\/X4Mz"}
00439{"flow_id":3,"flow_packet_id":9,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":24,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":963893,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0yARAAEAGoGjAqAGfCAgICNrYA1WXsAVbw\/3zKoAQAWJ1YQAAAQEICv\/\/zM1kDcpl"}
00440{"flow_id":3,"flow_packet_id":10,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":25,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":963966,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0yAVAAEAGoGfAqAGfCAgICNrYA1WXsAVbw\/34tIAQAW1vywAAAQEICv\/\/zM5kDcpl"}
00440{"flow_id":3,"flow_packet_id":11,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":26,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":964071,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0yAZAAEAGoGbAqAGfCAgICNrYA1WXsAVbw\/35o4AQAW1u3AAAAQEICv\/\/zM5kDcpl"}
00567{"flow_id":3,"flow_packet_id":12,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":27,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":966672,"pkt_caplen":159,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":159,"pkt_l4_len":125,"pkt":"EBMx8Tl2ag\/ahpuQCABFAACRyAdAAEAGoAjAqAGfCAgICNrYA1WXsAVbw\/35o4AYAW2IqwAAAQEICv\/\/zM9kDcplFgMDACUQAAAhILeCNg8jv6jCikgxhfkU3HgT7WoBqRBJXMyl0pUWnAEeFAMDAAEBFgMDACgAAAAAAAAAAJhbzSCk2Tht0cc+LCBCU1nYBazVcI2EU09kNu20VVUE"}
00569{"flow_id":2,"flow_packet_id":12,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":28,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":970235,"pkt_caplen":159,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":159,"pkt_l4_len":125,"pkt":"EBMx8Tl2ag\/ahpuQCABFAACRtGZAAEAGt63AqAGfCAgEBLusA1UTsXk8DrwNDoAYAW3cwQAAAQEICv\/\/zNB\/X4MzFgMDACUQAAAhIB1NzO65iF1RgzRYUOGwikF2wXKLNJOXWHai+wX\/XmACFAMDAAEBFgMDACgAAAAAAAAAADMYmv1ve8+roAea\/hOyzz8x5G2VCxfbIwWd6P7onSbo"}
00842{"flow_id":3,"flow_packet_id":13,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":29,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":980177,"pkt_caplen":358,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":358,"pkt_l4_len":324,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAFYxe8AAHYGq1kICAgIwKgBnwNV2tjD\/fmjl7AFuIAYAPCVwgAAAQEICmQNynr\/\/8zPFgMDAOwEAADoAAGJwADiARwM3mDSTy2KnFOJMzn7stUI3n9w6Bd7Bo1xVXy+0OXV\/lHT5lA9\/GbuMkzwugBBchLSxvyY0LEl5xIuCp83HBEhH+1MxqmtX4gW4cxNBmD4J7ZB6UV5zmoLDyYH8f06kQ0cbxh\/YLNXHSzVirvfugV3LQBlV+9Bpp0yZSzIkUJLf0qN9Qh8y28fYVh8wrxt\/44w864fkSANzJFhTx0c+Av9PV54L7qn8Ok7eTCjxTG+sTMMtH6DPnvMu7qKQQksevJ9p2LQGHlp\/QGUw6Cs0o62K\/KxYFfLCcXx3OH\/taS5FhQDAwABARYDAwAoAAAAAAAAAAAgilLoAsCqZ+bWS7HX8RV+x6hkiqdBDfE2k1d4jOgLPQ=="}
00840{"flow_id":2,"flow_packet_id":13,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":30,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":982662,"pkt_caplen":358,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":358,"pkt_l4_len":324,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAFYq4MAAHgGx8kICAQEwKgBnwNVu6wOvA0OE7F5mYAYAPCNwQAAAQEICn9fg0z\/\/8zQFgMDAOwEAADoAAGJwADiARwM3mDSTy2KnFOJMzn7si\/DOnq1DGgu8OxQKIPD47uYPnO8xM2aeSK2T\/19bmxIkcfRP00II55x5yfpEv3\/ODq\/7O8EdsmMGI5zxavF7YdVwJUnDAN7hCO7OWFeviLfkGe\/D59YmVRYODja4O49f1v08EKrt6bow4V9ruahBKixKZpY2lFj7FB4DJ6rZKo1+sO8wC8wqe3xvifD7WiW0T1CEOENgeWWMxkeOeSVhfFNemB4dIS4B5xTAU6m1kQcUKSSPB90Glm7Ln3sg+MJf9zxMpTwpOve8EBmeSYyZQBrmRQDAwABARYDAwAoAAAAAAAAAAAt9na1d630FOWMHH\/zJ8SbQeTHoOlsN7C2LFPgeVAqNg=="}
00561{"flow_id":2,"flow_packet_id":14,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":31,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":985074,"pkt_caplen":151,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":151,"pkt_l4_len":117,"pkt":"EBMx8Tl2ag\/ahpuQCABFAACJtGdAAEAGt7TAqAGfCAgEBLusA1UTsXmZDrwOMoAYAXgenwAAAQEICv\/\/zNN\/X4NMFwMDAFAAAAAAAAAAAaI\/1br7qpFCm0iqQN3tCmfEr3xZlO4fCdyKXAN6C7IgYrco8oZs\/+q+UFTPzCFjUkqj0fkGIIXuDIE2GmNUAXJj63zvWrXMLw=="}
00560{"flow_id":3,"flow_packet_id":14,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":32,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552825,"pkt_ts_usec":992866,"pkt_caplen":151,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":151,"pkt_l4_len":117,"pkt":"EBMx8Tl2ag\/ahpuQCABFAACJyAhAAEAGoA\/AqAGfCAgICNrYA1WXsAW4w\/36x4AYAXhpDwAAAQEICv\/\/zNVkDcp6FwMDAFAAAAAAAAAAART8lEX6ZoAkVgX7dDGPPd7aOXVC56IOwlYrJPrXITEl0kw2smePPpFiQ0QHAmpKlI3Welu7CqTq2DaJ2VTWEoUuXYN80BTAqw=="}
00437{"flow_id":2,"flow_packet_id":15,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":33,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":2622,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0q4wAAHgGyOQICAQEwKgBnwNVu6wOvA4yE7F57oAQAPBuVwAAAQEICn9fg2D\/\/8zT"}
00439{"flow_id":3,"flow_packet_id":15,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":34,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":11360,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0xg4AAHYGrF4ICAgIwKgBnwNV2tjD\/frHl7AGDYAQAPBtSAAAAQEICmQNypn\/\/8zV"}
00488{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":42,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":1,"flow_first_seen":1592552826036,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48048,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00451{"flow_id":4,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":42,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":36505,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA80uBAAEAGmYjAqAGfCAgEBLuwA1WtLB4AAAAAAKAC\/\/8imQAAAgQFtAQCCAr\/\/8zgAAAAAAEDAwg="}
00450{"flow_id":4,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":45,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":49329,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA8wHkAAHcGtO8ICAQEwKgBnwNVu7B94BEWrSweAaAS6yCziAAAAgQFZAQCCAq0eUC+\/\/\/M4AEDAwg="}
00438{"flow_id":4,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":46,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":51146,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA00uFAAEAGmY\/AqAGfCAgEBLuwA1WtLB4BfeARF4AQAVfLywAAAQEICv\/\/zOS0eUC+"}
00649{"flow_id":4,"flow_packet_id":4,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":47,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":51495,"pkt_caplen":220,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":220,"pkt_l4_len":186,"pkt":"EBMx8Tl2ag\/ahpuQCABFAADO0uJAAEAGmPTAqAGfCAgEBLuwA1WtLB4BfeARF4AYAVfZbQAAAQEICv\/\/zOS0eUC+FgMBAJUBAACRAwNJCyrg3LiPOkzp25J1tFPL9Xy02QHRBJvQzPxg67QKYwAAHsArwC\/ALMAwzKnMqMAJwBPACsAUAJwAnQAvADUACgEAAEoAAAAPAA0AAApkbnMuZ29vZ2xlABcAAP8BAAEAAAoACAAGAB0AFwAYAAsAAgEAACMAAAANABQAEgQDCAQEAQUDCAUFAQgGBgECAQ=="}
00770{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":47,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":4,"flow_first_seen":1592552826036,"flow_last_seen":1592552826051,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":154,"flow_tot_l4_payload_len":154,"flow_avg_l4_payload_len":38,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48048,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"","unsafe_cipher":0,"cipher":"TLS_NULL_WITH_NULL_NULL"}}
00437{"flow_id":4,"flow_packet_id":5,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":51,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":64156,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0wIMAAHcGtO0ICAQEwKgBnwNVu7B94BEXrSwem4AQAPDLiQAAAQEICrR5QM3\/\/8zk"}
02347{"flow_id":4,"flow_packet_id":6,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":52,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":80321,"pkt_caplen":1484,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1484,"pkt_l4_len":1450,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAW+wIgAAHcGr14ICAQEwKgBnwNVu7B94BEXrSwem4AQAPAKFgAAAQEICrR5QN3\/\/8zkFgMDAD8CAAA7AwNe7G16wqMnCBI7o10QL4Qs2RPVUByrn0FET1dOR1JEAQDALwAAEwAXAAD\/AQABAAALAAIBAAAjAAAWAwMKgAsACnwACnkABiUwggYhMIIFCaADAgECAhAvmt6tSZ\/54QIAAAAAayAjMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNVBAYTAlVTMR4wHAYDVQQKExVHb29nbGUgVHJ1c3QgU2VydmljZXMxEzARBgNVBAMTCkdUUyBDQSAxTzEwHhcNMjAwNTI2MTUyMDAyWhcNMjAwODE4MTUyMDAyWjBkMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNTW91bnRhaW4gVmlldzETMBEGA1UEChMKR29vZ2xlIExMQzETMBEGA1UEAxMKZG5zLmdvb2dsZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOSUeQONctZz3uIqdtC8TGzE8AMaYsmZY88YVzUreJdL\/0dCZYsl1UYc2OvENRHpKfNCZpRv3xMOZvi3kh0QIb5zzddzOkkBUd2hU7s3ZwZK+HaanofZZUCn6DHRVW+tAvbhDsfNhYq7nC6j\/GNW5VGjRotNORp5ATy1MpfZF93XgmaHNixqtpC\/0gM5Gwth6D+1fVJsvBEgZyIPBayP3lOd1yAvzdIkSpwWaZ+TKW+85OK4yyy7S2o1vCDDK3Zq6\/jUumhBP5SJmDA5tr4dukkEoqVyhPnxGcB4hDmwyVDU2U8rmqCGQULfKb12DBmiiJOYbm5pqVj1JBv0+p3j1E0CAwEAAaOCAu8wggLrMA4GA1UdDwEB\/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSFRNGvRXRy0wAb7J2sKkmYhLWe3zAfBgNVHSMEGDAWgBSY0fhuEOvPm+xgnxiQG6DrfQn9KzBoBggrBgEFBQcBAQRcMFowKwYIKwYBBQUHMAGGH2h0dHA6Ly9vY3NwLnBraS5nb29nL2d0czFvMWNvcmUwKwYIKwYBBQUHMAKGH2h0dHA6Ly9wa2kuZ29vZy9nc3IyL0dUUzFPMS5jcnQwgawGA1UdEQSBpDCBoYIKZG5zLmdvb2dsZYIQKi5kbnMuZ29vZ2xlLmNvbYILODg4OC5nb29nbGWCDmRucy5nb29nbGUuY29tghBkbnM2NC5kbnMuZ29vZ2xlhxAgAUhgSGAAAAAAAAAAAABkhxAgAUhgSGAAAAAAAAAAAGRkhxAgAUhgSGAAAAAAAAAAAIhEhxAgAUhgSGAAAAAAAAAAAIiIhwQICAQEhwQICAgIMCEGA1UdIAQaMBgwCAYGZ4EMAQICMAwGCisGAQQB1nkCBQMwMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5wa2kuZ29vZy9HVFMxTzFjb3JlLmNybDCCAQMGCisGAQQB1nkCBAIEgfQEgfEA7wB2AAe3XBvlfWj\/8bDGHSMVx7rmV3xXlLdq7rxhOhpp06IcAAABclHIpS8AAAQDAEcwRQIhAL8PRht0GjLwxvKgvt3ME7Lvn501gSRHUbzJgY3HddfrAiBITPBWXKB\/EsGN\/qthElwjtyifjXyQCtZL82ZOsBNAqgB1AF6nc\/nfVsDntTZIfdBJ4DJ6kZoMhKESEoQYdZaBcUVYAAABclHIo2oAAAQDAEYwRAIgW3oiEOXHmxVJukyPKedbFKLAHU+NWNHGdGVRZy3Vv9QCIBZ565g8plNNkx9OSGvGcmllJquFv0Vpmmf0ZrIkVQCpMA0GCSqGSIb3DQEBCwUAA4IBAQBP8NFNA2o7BvU4C0BZ\/YuA2G4="}
00827{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":52,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":6,"flow_first_seen":1592552826036,"flow_last_seen":1592552826080,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":1572,"flow_avg_l4_payload_len":262,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48048,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"b44baa8a20901c5663b3a9664ba8a767","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"}}
02354{"flow_id":4,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":53,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":81468,"pkt_caplen":1484,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1484,"pkt_l4_len":1450,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAW+wIkAAHcGr10ICAQEwKgBnwNVu7B94BahrSwem4AQAPAopQAAAQEICrR5QN3\/\/8zkBWU\/U1SwWFqB51XKOk\/9gYc9EfnV8DMmwcygUgaToHLYUMwUZiFSJ1LqRJEm3oknKcmGpn6E+8rpojBhPvTewD8kzc3KtWn0xIyDeDz+Z1J8g\/uv+o2If+iKyGWYGf4RT\/KFSb\/lYkCgp373jBd81x2dBToH41zJgQMiTcRji8A4I0eyWkRpuReYMwBKatDuD2J7yUI9b+O06es4KhBC9a+DKwwGcm20clrv8FMBPBA3oxgf2d7Tp3YHw5XBW1+9IPzq88tSTj+WKJs15ATWPHPRFsSXyMFQZgstMB5d3dOB2ANmme6AIIj99uss4gAETjCCBEowggMyoAMCAQICDQHjtJqhjYqpgSVpULgwDQYJKoZIhvcNAQELBQAwTDEgMB4GA1UECxMXR2xvYmFsU2lnbiBSb290IENBIC0gUjIxEzARBgNVBAoTCkdsb2JhbFNpZ24xEzARBgNVBAMTCkdsb2JhbFNpZ24wHhcNMTcwNjE1MDAwMDQyWhcNMjExMjE1MDAwMDQyWjBCMQswCQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMRMwEQYDVQQDEwpHVFMgQ0EgMU8xMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0BjPRdSLzdOc5EDvfrTdaSEbyc88jkx1uQ8xGYQ9njwp71ANEJNvBYCAnyqgvRJLAuE9n1gWJP4wnwt0d1WTHUv3TeGSghD2UawMw7IilA80a5gQSecLnYM53SDGHC3v0RhhZecjgyCoIxL\/0iR\/1C\/nRGpbTddQZrCvnkJjBfvgHMRjYa+fajP\/Ype9SNnTfBRn3HXcLmno+G14adC3EAW48THCOyT9GjN0+CPg7GsZihbG482kzQvbs6RZYDiIO60ducaMp1Mb\/LzZpKu83Txh15MVmO6BvY\/iZEcgQAZO16yX6LnAWRKhSSUj5O1wNCyltGN8+aM9g9HNbSSsBwIDAQABo4IBMzCCAS8wDgYDVR0PAQH\/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH\/AgEAMB0GA1UdDgQWBBSY0fhuEOvPm+xgnxiQG6DrfQn9KzAfBgNVHSMEGDAWgBSb4gdXZxwewGoG3lm0mi3f3BmGLjA1BggrBgEFBQcBAQQpMCcwJQYIKwYBBQUHMAGGGWh0dHA6Ly9vY3NwLnBraS5nb29nL2dzcjIwMgYDVR0fBCswKTAnoCWgI4YhaHR0cDovL2NybC5wa2kuZ29vZy9nc3IyL2dzcjIuY3JsMD8GA1UdIAQ4MDYwNAYGZ4EMAQICMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8vcGtpLmdvb2cvcmVwb3NpdG9yeS8wDQYJKoZIhvcNAQELBQADggEBABqAPjZ5+\/MuqUY3fV5UFjWux04Imf690TRpJlJmBz0KuknLYvTxGo78EU9olkx0K9Nn3rKjqgWNhE1MIGUPpZbaDRb4bDvbbwQjiGs6bMFgvWifcY7uLVg0B\/DVVOmGWf17Xg0hlPWMyaj42PKtzA8a85qnqQQn+aPJsP8CeGthusc1K+hW+k\/DHAzttjy0S+rtzOE87NwNjNY+m8pCWIvMFiEXQLyi1mbv2sQVW82JqpsJJucy0g1uZyACWxCwkAmcDB+erdg76qH8bOgQXAhSGVEqcbuserXdFe0ryQgqLIq0piGrY\/\/XUklQ0Im3rfKv+1CuL+GVDfNGrZ2c9coWAwMBLAwAASgDAB0gQMZqc6gvwDfUHBB\/NhZ917SiHzfCAFxuKLUdjAFRuXsIBAEAkoRtBukMYTri6pWxn5QcneJrzssFHv3z65o="}
01129{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":53,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":7,"flow_first_seen":1592552826036,"flow_last_seen":1592552826081,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":2990,"flow_avg_l4_payload_len":427,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48048,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","server_names":"dns.google,*.dns.google.com,8888.google,dns.google.com,dns64.dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"b44baa8a20901c5663b3a9664ba8a767","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","issuerDN":"C=US, O=Google Trust Services, CN=GTS CA 1O1","issuerDN":"C=US, ST=California, L=Mountain View, O=Google LLC, CN=dns.google","fingerprint":"5B:59:09:FC:7D:50:E6:F7:D1:08:8E:57:42:A2:D8:AE:1F:03:FF:EC"}}
00765{"flow_id":4,"flow_packet_id":8,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":54,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":81567,"pkt_caplen":305,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":305,"pkt_l4_len":271,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAEjwIoAAHcGs\/cICAQEwKgBnwNVu7B94BwrrSwem4AYAPCFQAAAAQEICrR5QN3\/\/8zkFbaAdPgn9Xj8uyFqLPU+JTr6qBW1nG\/d2+KaEzIAXr6bjwYGXTiSp9ZvYPJb0OMzDZ2LBvK5xtDjG9GZOwNAks+89\/1CY78nKowg8GyRuecrOeqGDGQvNOKgdru0Frfgcj0D+HgdCjduRsmDboc4wkUAUeA+P3UBRQrsAr0gqIBmX3YfhA4NCQ4oZ7qnMb90HCJIr9jquCRjaAZTFW514qhB7sAyEoBR2cESB\/AXpCIgC947j6aaut4nYMLpv4jcNBeY3vyfH4oyO8xlKFbmUcH4xaQ7j\/RxMzwjYKkQy6bUBpkzrOwWAwMABA4AAAA="}
00437{"flow_id":4,"flow_packet_id":9,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":55,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":82584,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA00uNAAEAGmY3AqAGfCAgEBLuwA1WtLB6bfeAWoYAQAWLFdQAAAQEICv\/\/zOy0eUDd"}
00439{"flow_id":4,"flow_packet_id":10,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":56,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":83623,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA00uRAAEAGmYzAqAGfCAgEBLuwA1WtLB6bfeAcK4AQAW2\/4AAAAQEICv\/\/zOy0eUDd"}
00438{"flow_id":4,"flow_packet_id":11,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":57,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":84135,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA00uVAAEAGmYvAqAGfCAgEBLuwA1WtLB6bfeAdGoAQAW2+8QAAAQEICv\/\/zOy0eUDd"}
00565{"flow_id":4,"flow_packet_id":12,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":58,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":96652,"pkt_caplen":159,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":159,"pkt_l4_len":125,"pkt":"EBMx8Tl2ag\/ahpuQCABFAACR0uZAAEAGmS3AqAGfCAgEBLuwA1WtLB6bfeAdGoAYAW3zyQAAAQEICv\/\/zO+0eUDdFgMDACUQAAAhIFnfRGROSEcuZEqTogskzo6vAaCrvjhKwzw4GYUFaUR2FAMDAAEBFgMDACgAAAAAAAAAALyUqjC41+IdP9iflwsKIsFu1ccuts39lMpC63Dha1SY"}
00843{"flow_id":4,"flow_packet_id":13,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":59,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":110169,"pkt_caplen":358,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":358,"pkt_l4_len":324,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAFYwJoAAHcGs7IICAQEwKgBnwNVu7B94B0arSwe+IAYAPAmkAAAAQEICrR5QPr\/\/8zvFgMDAOwEAADoAAGJwADiARwM3mDSTy2KnFOJMzn7stzGYyX+ErxweKZvMWA+DHe7GLRnLRUybuHfiV5knTQIjhK\/GK5IIqvLNAmTKNvSo0hv8h0ulRB0aqm8FwgEpkVHHcM6UG5TzNCQ9KdT\/k7UNWuK7swRz9Yvi+k8q96rcEJr\/LXENmBb2UY8tY9l2xJKbBYA9tKwIPIBAerEXFDAPYWZdKDd5Q1S\/gPO223uC0X1er\/jYr9tA39W1m4B\/\/vKp4wt45p5c\/xW9Tg39T7eLvvvPWnCGQRfWtPx5seY9+CMB7cDPpL3T3JV2Fpgho3ydhQDAwABARYDAwAoAAAAAAAAAAD2JH2Q10f36N6vGuWc\/hRIObvPakpcECw6NEiyoMaKGQ=="}
00656{"flow_id":4,"flow_packet_id":14,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":60,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":133510,"pkt_caplen":225,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":225,"pkt_l4_len":191,"pkt":"EBMx8Tl2ag\/ahpuQCABFAADT0udAAEAGmOrAqAGfCAgEBLuwA1WtLB74feAePoAYAXjEgAAAAQEICv\/\/zPi0eUD6FwMDAJoAAAAAAAAAAZU7gg7NoNkCljO87amzN8ZbwElHFFpBRBaS4YZEbG6wHlJJJy4r8Ue3TaR5758jmsQsX31xCOSQ2ljUNCXsQBacf6J3EKnJgTy2WHiwgALMUvuZHgC8vLdpcuMquLezmJNo4BIdDxxNZ+icbjMKG6rBDyR+mI+\/QZALJ7f0bEnGVtYC\/wPeVtPMH75SpiKmQHJv"}
00439{"flow_id":4,"flow_packet_id":15,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":61,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":151385,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0wLYAAHcGtLoICAQEwKgBnwNVu7B94B4+rSwfl4AQAPS89wAAAQEICrR5QST\/\/8z4"}
00438{"flow_id":1,"flow_packet_id":5,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":67,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":207745,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0hqoAAHcG6sIICAgIwKgBnwNV2jAOPHBKaWPSFIARAUTy8AAAAQEIChWqclH\/\/5Cw"}
00420{"flow_id":1,"flow_packet_id":6,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":68,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552826,"pkt_ts_usec":208808,"pkt_caplen":54,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":54,"pkt_l4_len":20,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAAoAABAAEAGaHnAqAGfCAgICNowA1VpY9IUAAAAAFAEAADEiwAA"}
00457{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":81,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":1,"flow_first_seen":1592552827426,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.8.8","l4_proto":"icmp","flow_datalink":1,"flow_max_packets":15}
00480{"flow_id":5,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":81,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552827,"pkt_ts_usec":426405,"pkt_caplen":98,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":98,"pkt_l4_len":64,"pkt":"EBMx8Tl2ag\/ahpuQCABFAABUl9BAAEAB0IHAqAGfCAgICAgA4JUAAgABem3sXgAAAADqxwcAAAAAABAREhMUFRYXGBkaGxwdHh8gISIjJCUmJygpKissLS4vMDEyMzQ1Njc="}
00498{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":81,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":1,"flow_first_seen":1592552827426,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.8.8","l4_proto":"icmp","ndpi": {"proto":"ICMP.Google","breed":"Tracker\/Ads","category":"Network"}}
00480{"flow_id":5,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":83,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552827,"pkt_ts_usec":440141,"pkt_caplen":98,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":98,"pkt_l4_len":64,"pkt":"ag\/ahpuQEBMx8Tl2CABFoABUAAAAAHEBdrIICAgIwKgBnwAA6JUAAgABem3sXgAAAADqxwcAAAAAABAREhMUFRYXGBkaGxwdHh8gISIjJCUmJygpKissLS4vMDEyMzQ1Njc="}
00481{"flow_id":5,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":87,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552828,"pkt_ts_usec":402579,"pkt_caplen":98,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":98,"pkt_l4_len":64,"pkt":"EBMx8Tl2ag\/ahpuQCABFAABUl\/5AAEAB0FPAqAGfCAgICAgAgPEAAwABe23sXgAAAABJawcAAAAAABAREhMUFRYXGBkaGxwdHh8gISIjJCUmJygpKissLS4vMDEyMzQ1Njc="}
00480{"flow_id":5,"flow_packet_id":4,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":88,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552828,"pkt_ts_usec":415412,"pkt_caplen":98,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":98,"pkt_l4_len":64,"pkt":"ag\/ahpuQEBMx8Tl2CABFoABUAAAAAHEBdrIICAgIwKgBnwAAiPEAAwABe23sXgAAAABJawcAAAAAABAREhMUFRYXGBkaGxwdHh8gISIjJCUmJygpKissLS4vMDEyMzQ1Njc="}
00471{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":150,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":4,"flow_first_seen":1592552827426,"flow_last_seen":1592552828415,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.8.8","l4_proto":"icmp","flow_datalink":1,"flow_max_packets":15}
00489{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":157,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":1,"flow_first_seen":1592552871852,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":1,"l3_proto":"ip4","src_ip":"8.8.4.4","dst_ip":"192.168.1.159","src_port":853,"dst_port":47968,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00440{"flow_id":6,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":157,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552871,"pkt_ts_usec":852324,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0V5sAAHYGHtYICAQEwKgBnwNVu2A7uJADhSLfzIARAX\/+2gAAAQEICuSDFST\/\/78G"}
00422{"flow_id":6,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":158,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552871,"pkt_ts_usec":941265,"pkt_caplen":54,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":54,"pkt_l4_len":20,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAAoAABAAEAGbH3AqAGfCAgEBLtgA1WFIt\/MAAAAAFAEAAC96AAA"}
00489{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":159,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":1,"flow_first_seen":1592552878549,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48098,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00452{"flow_id":7,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":159,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":549677,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA8PO5AAEAGL3vAqAGfCAgEBLviA1WhETzJAAAAAKAC\/\/\/ccgAAAgQFtAQCCAoAAAAnAAAAAAEDAwg="}
00449{"flow_id":7,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":160,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":562423,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA8nAYAAHYG2mIICAQEwKgBnwNVu+J3bBxFoRE8yqAS6yB6VAAAAgQFZAQCCAo7E6h3AAAAJwEDAwg="}
00437{"flow_id":7,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":161,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":563796,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0PO9AAEAGL4LAqAGfCAgEBLviA1WhETzKd2wcRoAQAVeSlgAAAQEICgAAACw7E6h3"}
01142{"flow_id":7,"flow_packet_id":4,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":162,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":564695,"pkt_caplen":583,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":583,"pkt_l4_len":549,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAI5PPBAAEAGLXzAqAGfCAgEBLviA1WhETzKd2wcRoAYAVddrgAAAQEICgAAACw7E6h3FgMBAgABAAH8AwMrWAyrTdDxfgOP+1tzuunb7Cy\/yXCgSWeXoKBkBPrVPyA3JDMO7OphzpU36YzIUm3zGK0YYOmlQM62LkpDm0rDGgAewCvAL8AswDDMqcyowAnAE8AKwBQAnACdAC8ANQAKAQABlQAAAA8ADQAACmRucy5nb29nbGUAFwAA\/wEAAQAACgAIAAYAHQAXABgACwACAQAAIwDiARwM3mDSTy2KnFOJMzn7stzGYyX+ErxweKZvMWA+DHe7GLRnLRUybuHfiV5knTQIjhK\/GK5IIqvLNAmTKNvSo0hv8h0ulRB0aqm8FwgEpkVHHcM6UG5TzNCQ9KdT\/k7UNWuK7swRz9Yvi+k8q96rcEJr\/LXENmBb2UY8tY9l2xJKbBYA9tKwIPIBAerEXFDAPYWZdKDd5Q1S\/gPO223uC0X1er\/jYr9tA39W1m4B\/\/vKp4wt45p5c\/xW9Tg39T7eLvvvPWnCGQRfWtPx5seY9+CMB7cDPpL3T3JV2Fpgho3ydgANABQAEgQDCAQEAQUDCAUFAQgGBgECAQAVAGUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA=="}
00772{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":162,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":4,"flow_first_seen":1592552878549,"flow_last_seen":1592552878564,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":517,"flow_tot_l4_payload_len":517,"flow_avg_l4_payload_len":129,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48098,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"b734f75d22aaff9866fbd5d27eef9106","ja3s":"","unsafe_cipher":0,"cipher":"TLS_NULL_WITH_NULL_NULL"}}
00437{"flow_id":7,"flow_packet_id":5,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":163,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":577342,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0nAgAAHYG2mgICAQEwKgBnwNVu+J3bBxGoRE+z4AQAPCQ6QAAAQEICjsTqIYAAAAs"}
00637{"flow_id":7,"flow_packet_id":6,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":164,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":577421,"pkt_caplen":213,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":213,"pkt_l4_len":179,"pkt":"ag\/ahpuQEBMx8Tl2CABFAADHnAkAAHYG2dQICAQEwKgBnwNVu+J3bBxGoRE+z4AYAPBK3wAAAQEICjsTqIYAAAAsFgMDAFsCAABXAwNe7G2uCykxvbVdBcxAJcwMizMEDI80T9lET1dOR1JEASA3JDMO7OphzpU36YzIUm3zGK0YYOmlQM62LkpDm0rDGsAvAAAPABcAAP8BAAEAAAsAAgEAFAMDAAEBFgMDACgAAAAAAAAAANwZZ3mHbB4\/MCX8h+8kQXM4R1XQtwh2o3bU+qtBI5kE"}
00826{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":164,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":6,"flow_first_seen":1592552878549,"flow_last_seen":1592552878577,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":517,"flow_tot_l4_payload_len":664,"flow_avg_l4_payload_len":110,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48098,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"b734f75d22aaff9866fbd5d27eef9106","ja3s":"1249fb68f48c0444718e4d3b48b27188","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"}}
00437{"flow_id":7,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":165,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":578889,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0PPFAAEAGL4DAqAGfCAgEBLviA1WhET7Pd2wc2YAQAVeP6wAAAQEICgAAADA7E6iG"}
00507{"flow_id":7,"flow_packet_id":8,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":166,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":580026,"pkt_caplen":117,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":117,"pkt_l4_len":83,"pkt":"EBMx8Tl2ag\/ahpuQCABFAABnPPJAAEAGL0zAqAGfCAgEBLviA1WhET7Pd2wc2YAYAVf7KAAAAQEICgAAADA7E6iGFAMDAAEBFgMDACgAAAAAAAAAANm4HIl2OyTAmc5U14SCMz8r4I+dvSSVjJRSzcy89BtT"}
00438{"flow_id":7,"flow_packet_id":9,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":167,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":597024,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0nBIAAHYG2l4ICAQEwKgBnwNVu+J3bBzZoRE\/AoAQAPCQCwAAAQEICjsTqJoAAAAw"}
00661{"flow_id":7,"flow_packet_id":10,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":168,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":599157,"pkt_caplen":225,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":225,"pkt_l4_len":191,"pkt":"EBMx8Tl2ag\/ahpuQCABFAADTPPNAAEAGLt\/AqAGfCAgEBLviA1WhET8Cd2wc2YAYAVckxgAAAQEICgAAADU7E6iaFwMDAJoAAAAAAAAAARFIQabocIgzTFl5FrgaH4UQ6yv8xHxzzwgoRyUK8YU3tm85HeiVNR1\/rSStZV+l\/oMFV1\/vYBOnDvGpptcQB7TAcrGP\/nWBwcXNI5h8Zx92OlkQ\/U2OLAx+B+XV00Vc5MQqiU8VwOPkRKznKnpdyJ+SRWNLk8yol6j\/pb4xJL2fx3Mhlbo\/F2dQCFZT1cMPTQuq"}
00439{"flow_id":7,"flow_packet_id":11,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":169,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":610777,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0nBgAAHYG2lgICAQEwKgBnwNVu+J3bBzZoRE\/oYAQAPSPVQAAAQEICjsTqKgAAAA1"}
01117{"flow_id":7,"flow_packet_id":12,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":170,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":612095,"pkt_caplen":565,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":565,"pkt_l4_len":531,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAInnBkAAHYG2GQICAQEwKgBnwNVu+J3bBzZoRE\/oYAYAPRgcAAAAQEICjsTqKkAAAA1FwMDAe4AAAAAAAAAAbCsNKWdqHLvo7w6PKNe8Qw2dl8x4ZPpA2gWLKg2VCgmdk054diZWv1fE37BzfH5u3Hiql2bDKQCwGgPG6xeMCPwN6MjWoOIiXp\/0s+S9YAZpQBYNo5kyB7H4xsLUX7IshEIF6\/rA00xCnjLY1Nwhp3jnkML83Jh7zyMA5rCwcukD3+9OjpASDj8z2r29+nRv5LatZ1DCuD0JLfR\/YF86X+oHjFHgBUpssLBfN02ywN6\/obgGMuc2JpB3RxuCDuJKwKImwVUA0NKefs3jI4VqypJFbb3Z4LgWwsCSiInFINf3FEW3G3c2Zt3bckH6iES2SrZ\/EaXrIakbofDB39eqZzJBHfNDnb+J3XLEWPOMEFErGEqnP0oKFAkbdkZOGCKaNY8F8S52UOBBjYRwXqDzFWOoInzC3iM4x42raHH8C\/uQ0RxYmhv+GL10UzX2lonuUbmEd\/MTOfhENtL1nIbZuy1+g0HXZe1CtxoHIYne6Jvz8b4cdq+uZV2MUoIeysiWjyL8mbW1wax2J1joPIeSRQW5YOq9CHIkq0ZsEOjoZQfEKDyaQaAtyxYNwYbProS7bZUQETYMbm8H0Jy1FCftGoDNbEf0hRyOw52zPshEqhw6TQjOUeftHx1PExR16awxDJsjyvVVw=="}
00438{"flow_id":7,"flow_packet_id":13,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":171,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552878,"pkt_ts_usec":657604,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0PPRAAEAGL33AqAGfCAgEBLviA1WhET+hd2wezIAQAVuM6wAAAQEICgAAAEQ7E6ip"}
00656{"flow_id":7,"flow_packet_id":14,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":172,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552879,"pkt_ts_usec":308855,"pkt_caplen":225,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":225,"pkt_l4_len":191,"pkt":"EBMx8Tl2ag\/ahpuQCABFAADTPPVAAEAGLt3AqAGfCAgEBLviA1WhET+hd2wezIAYAVtM5AAAAQEICgAAAOQ7E6ipFwMDAJoAAAAAAAAAAmn5\/+4ILFRPfNGt4q8o8vcvtz73sPbtaxwnqGBasfUF\/qq7OLbp\/mKbYQ8PaarzPUpCLTPdQ+sBOAQ4CDaFkM3x8fofwCDGcygT7A1YwRVGQpwHkTJE8vro477jrqvHjodqaSM8V0mWsI3PqlboE3fzxj5T2inAx2gMxkBr2uVksMjgv4tqjDazn6CMgwVEWSW+"}
00438{"flow_id":7,"flow_packet_id":15,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":173,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592552879,"pkt_ts_usec":327056,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0nXkAAHYG2PcICAQEwKgBnwNVu+J3bB7MoRFAQIAQAPiJRQAAAQEICjsTq3MAAADk"}
00540{"flow_event_id":4,"flow_event_name":"guessed","thread_id":0,"packet_id":265,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":6,"flow_first_seen":1592552824409,"flow_last_seen":1592552826208,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":1,"l3_proto":"ip4","src_ip":"8.8.8.8","dst_ip":"192.168.1.159","src_port":853,"dst_port":55856,"l4_proto":"tcp","ndpi": {"proto":"DoH_DoT.Google","breed":"Tracker\/Ads","category":"Web"}}
00501{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":265,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":6,"flow_first_seen":1592552824409,"flow_last_seen":1592552826208,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":1,"l3_proto":"ip4","src_ip":"8.8.8.8","dst_ip":"192.168.1.159","src_port":853,"dst_port":55856,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00510{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":265,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":21,"flow_first_seen":1592552825913,"flow_last_seen":1592552826054,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":3843,"flow_avg_l4_payload_len":183,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.8.8","src_port":56024,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00510{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":265,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":21,"flow_first_seen":1592552825913,"flow_last_seen":1592552826030,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":3843,"flow_avg_l4_payload_len":183,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48044,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00512{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":285,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":104,"flow_first_seen":1592552826036,"flow_last_seen":1592552867048,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":21215,"flow_avg_l4_payload_len":203,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48048,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00540{"flow_event_id":4,"flow_event_name":"guessed","thread_id":0,"packet_id":292,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":2,"flow_first_seen":1592552871852,"flow_last_seen":1592552871941,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":1,"l3_proto":"ip4","src_ip":"8.8.4.4","dst_ip":"192.168.1.159","src_port":853,"dst_port":47968,"l4_proto":"tcp","ndpi": {"proto":"DoH_DoT.Google","breed":"Tracker\/Ads","category":"Web"}}
00501{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":292,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":2,"flow_first_seen":1592552871852,"flow_last_seen":1592552871941,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":1,"l3_proto":"ip4","src_ip":"8.8.4.4","dst_ip":"192.168.1.159","src_port":853,"dst_port":47968,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00489{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":292,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":1,"flow_first_seen":1592553007037,"flow_last_seen":0,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":0,"flow_tot_l4_payload_len":0,"flow_avg_l4_payload_len":0,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48210,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00451{"flow_id":8,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":292,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":37028,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA8FgpAAEAGVl\/AqAGfCAgEBLxSA1VGZWurAAAAAKAC\/\/+KUgAAAgQFtAQCCAoAAH2hAAAAAAEDAwg="}
00450{"flow_id":8,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":293,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":51414,"pkt_caplen":74,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":74,"pkt_l4_len":40,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA8ScwAAHYGLJ0ICAQEwKgBnwNVvFKvdpW\/RmVrrKAS6yB4FwAAAgQFZAQCCAp\/c2KvAAB9oQEDAwg="}
00437{"flow_id":8,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":294,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":78898,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0FgtAAEAGVmbAqAGfCAgEBLxSA1VGZWusr3aVwIAQAVeQUgAAAQEICgAAfa1\/c2Kv"}
00652{"flow_id":8,"flow_packet_id":4,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":295,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":88078,"pkt_caplen":220,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":220,"pkt_l4_len":186,"pkt":"EBMx8Tl2ag\/ahpuQCABFAADOFgxAAEAGVcvAqAGfCAgEBLxSA1VGZWusr3aVwIAYAVd\/mgAAAQEICgAAfa9\/c2KvFgMBAJUBAACRAwNWAMlRN\/y9+y5bn87kl8S7SwnuvLXD9du+\/Dt1fS20NAAAHsArwC\/ALMAwzKnMqMAJwBPACsAUAJwAnQAvADUACgEAAEoAAAAPAA0AAApkbnMuZ29vZ2xlABcAAP8BAAEAAAoACAAGAB0AFwAYAAsAAgEAACMAAAANABQAEgQDCAQEAQUDCAUFAQgGBgECAQ=="}
00771{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":295,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":4,"flow_first_seen":1592553007037,"flow_last_seen":1592553007088,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":154,"flow_tot_l4_payload_len":154,"flow_avg_l4_payload_len":38,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48210,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"","unsafe_cipher":0,"cipher":"TLS_NULL_WITH_NULL_NULL"}}
00437{"flow_id":8,"flow_packet_id":5,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":296,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":101326,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0SeYAAHYGLIsICAQEwKgBnwNVvFKvdpXARmVsRoAQAPCP6wAAAQEICn9zYuEAAH2v"}
02347{"flow_id":8,"flow_packet_id":6,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":297,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":118877,"pkt_caplen":1484,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1484,"pkt_l4_len":1450,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAW+SfAAAHYGJvcICAQEwKgBnwNVvFKvdpXARmVsRoAQAPAH2gAAAQEICn9zYvIAAH2vFgMDAD8CAAA7AwNe7G4vYWtcBNfat74UY6eggZEkCjQVV0VET1dOR1JEAQDALwAAEwAXAAD\/AQABAAALAAIBAAAjAAAWAwMKgAsACnwACnkABiUwggYhMIIFCaADAgECAhAvmt6tSZ\/54QIAAAAAayAjMA0GCSqGSIb3DQEBCwUAMEIxCzAJBgNVBAYTAlVTMR4wHAYDVQQKExVHb29nbGUgVHJ1c3QgU2VydmljZXMxEzARBgNVBAMTCkdUUyBDQSAxTzEwHhcNMjAwNTI2MTUyMDAyWhcNMjAwODE4MTUyMDAyWjBkMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNTW91bnRhaW4gVmlldzETMBEGA1UEChMKR29vZ2xlIExMQzETMBEGA1UEAxMKZG5zLmdvb2dsZTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAOSUeQONctZz3uIqdtC8TGzE8AMaYsmZY88YVzUreJdL\/0dCZYsl1UYc2OvENRHpKfNCZpRv3xMOZvi3kh0QIb5zzddzOkkBUd2hU7s3ZwZK+HaanofZZUCn6DHRVW+tAvbhDsfNhYq7nC6j\/GNW5VGjRotNORp5ATy1MpfZF93XgmaHNixqtpC\/0gM5Gwth6D+1fVJsvBEgZyIPBayP3lOd1yAvzdIkSpwWaZ+TKW+85OK4yyy7S2o1vCDDK3Zq6\/jUumhBP5SJmDA5tr4dukkEoqVyhPnxGcB4hDmwyVDU2U8rmqCGQULfKb12DBmiiJOYbm5pqVj1JBv0+p3j1E0CAwEAAaOCAu8wggLrMA4GA1UdDwEB\/wQEAwIFoDATBgNVHSUEDDAKBggrBgEFBQcDATAMBgNVHRMBAf8EAjAAMB0GA1UdDgQWBBSFRNGvRXRy0wAb7J2sKkmYhLWe3zAfBgNVHSMEGDAWgBSY0fhuEOvPm+xgnxiQG6DrfQn9KzBoBggrBgEFBQcBAQRcMFowKwYIKwYBBQUHMAGGH2h0dHA6Ly9vY3NwLnBraS5nb29nL2d0czFvMWNvcmUwKwYIKwYBBQUHMAKGH2h0dHA6Ly9wa2kuZ29vZy9nc3IyL0dUUzFPMS5jcnQwgawGA1UdEQSBpDCBoYIKZG5zLmdvb2dsZYIQKi5kbnMuZ29vZ2xlLmNvbYILODg4OC5nb29nbGWCDmRucy5nb29nbGUuY29tghBkbnM2NC5kbnMuZ29vZ2xlhxAgAUhgSGAAAAAAAAAAAABkhxAgAUhgSGAAAAAAAAAAAGRkhxAgAUhgSGAAAAAAAAAAAIhEhxAgAUhgSGAAAAAAAAAAAIiIhwQICAQEhwQICAgIMCEGA1UdIAQaMBgwCAYGZ4EMAQICMAwGCisGAQQB1nkCBQMwMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5wa2kuZ29vZy9HVFMxTzFjb3JlLmNybDCCAQMGCisGAQQB1nkCBAIEgfQEgfEA7wB2AAe3XBvlfWj\/8bDGHSMVx7rmV3xXlLdq7rxhOhpp06IcAAABclHIpS8AAAQDAEcwRQIhAL8PRht0GjLwxvKgvt3ME7Lvn501gSRHUbzJgY3HddfrAiBITPBWXKB\/EsGN\/qthElwjtyifjXyQCtZL82ZOsBNAqgB1AF6nc\/nfVsDntTZIfdBJ4DJ6kZoMhKESEoQYdZaBcUVYAAABclHIo2oAAAQDAEYwRAIgW3oiEOXHmxVJukyPKedbFKLAHU+NWNHGdGVRZy3Vv9QCIBZ565g8plNNkx9OSGvGcmllJquFv0Vpmmf0ZrIkVQCpMA0GCSqGSIb3DQEBCwUAA4IBAQBP8NFNA2o7BvU4C0BZ\/YuA2G4="}
00828{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":297,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":6,"flow_first_seen":1592553007037,"flow_last_seen":1592553007118,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":1572,"flow_avg_l4_payload_len":262,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48210,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"b44baa8a20901c5663b3a9664ba8a767","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256"}}
02353{"flow_id":8,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":298,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":118996,"pkt_caplen":1484,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":1484,"pkt_l4_len":1450,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAW+SfEAAHYGJvYICAQEwKgBnwNVvFKvdptKRmVsRoAQAPBRqwAAAQEICn9zYvIAAH2vBWU\/U1SwWFqB51XKOk\/9gYc9EfnV8DMmwcygUgaToHLYUMwUZiFSJ1LqRJEm3oknKcmGpn6E+8rpojBhPvTewD8kzc3KtWn0xIyDeDz+Z1J8g\/uv+o2If+iKyGWYGf4RT\/KFSb\/lYkCgp373jBd81x2dBToH41zJgQMiTcRji8A4I0eyWkRpuReYMwBKatDuD2J7yUI9b+O06es4KhBC9a+DKwwGcm20clrv8FMBPBA3oxgf2d7Tp3YHw5XBW1+9IPzq88tSTj+WKJs15ATWPHPRFsSXyMFQZgstMB5d3dOB2ANmme6AIIj99uss4gAETjCCBEowggMyoAMCAQICDQHjtJqhjYqpgSVpULgwDQYJKoZIhvcNAQELBQAwTDEgMB4GA1UECxMXR2xvYmFsU2lnbiBSb290IENBIC0gUjIxEzARBgNVBAoTCkdsb2JhbFNpZ24xEzARBgNVBAMTCkdsb2JhbFNpZ24wHhcNMTcwNjE1MDAwMDQyWhcNMjExMjE1MDAwMDQyWjBCMQswCQYDVQQGEwJVUzEeMBwGA1UEChMVR29vZ2xlIFRydXN0IFNlcnZpY2VzMRMwEQYDVQQDEwpHVFMgQ0EgMU8xMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA0BjPRdSLzdOc5EDvfrTdaSEbyc88jkx1uQ8xGYQ9njwp71ANEJNvBYCAnyqgvRJLAuE9n1gWJP4wnwt0d1WTHUv3TeGSghD2UawMw7IilA80a5gQSecLnYM53SDGHC3v0RhhZecjgyCoIxL\/0iR\/1C\/nRGpbTddQZrCvnkJjBfvgHMRjYa+fajP\/Ype9SNnTfBRn3HXcLmno+G14adC3EAW48THCOyT9GjN0+CPg7GsZihbG482kzQvbs6RZYDiIO60ducaMp1Mb\/LzZpKu83Txh15MVmO6BvY\/iZEcgQAZO16yX6LnAWRKhSSUj5O1wNCyltGN8+aM9g9HNbSSsBwIDAQABo4IBMzCCAS8wDgYDVR0PAQH\/BAQDAgGGMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjASBgNVHRMBAf8ECDAGAQH\/AgEAMB0GA1UdDgQWBBSY0fhuEOvPm+xgnxiQG6DrfQn9KzAfBgNVHSMEGDAWgBSb4gdXZxwewGoG3lm0mi3f3BmGLjA1BggrBgEFBQcBAQQpMCcwJQYIKwYBBQUHMAGGGWh0dHA6Ly9vY3NwLnBraS5nb29nL2dzcjIwMgYDVR0fBCswKTAnoCWgI4YhaHR0cDovL2NybC5wa2kuZ29vZy9nc3IyL2dzcjIuY3JsMD8GA1UdIAQ4MDYwNAYGZ4EMAQICMCowKAYIKwYBBQUHAgEWHGh0dHBzOi8vcGtpLmdvb2cvcmVwb3NpdG9yeS8wDQYJKoZIhvcNAQELBQADggEBABqAPjZ5+\/MuqUY3fV5UFjWux04Imf690TRpJlJmBz0KuknLYvTxGo78EU9olkx0K9Nn3rKjqgWNhE1MIGUPpZbaDRb4bDvbbwQjiGs6bMFgvWifcY7uLVg0B\/DVVOmGWf17Xg0hlPWMyaj42PKtzA8a85qnqQQn+aPJsP8CeGthusc1K+hW+k\/DHAzttjy0S+rtzOE87NwNjNY+m8pCWIvMFiEXQLyi1mbv2sQVW82JqpsJJucy0g1uZyACWxCwkAmcDB+erdg76qH8bOgQXAhSGVEqcbuserXdFe0ryQgqLIq0piGrY\/\/XUklQ0Im3rfKv+1CuL+GVDfNGrZ2c9coWAwMBLAwAASgDAB0ggCn9KJ2XCNb7ry8hpgGU6pw393hGZZvmzoFNvymkWmgIBAEAjiA8lA1oBI8a8vFGt+VqaY1Oxe5ryAh45uc="}
01130{"flow_event_id":6,"flow_event_name":"detection-update","thread_id":0,"packet_id":298,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":7,"flow_first_seen":1592553007037,"flow_last_seen":1592553007118,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":2990,"flow_avg_l4_payload_len":427,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48210,"dst_port":853,"l4_proto":"tcp","ndpi": {"flow_risk": {"15":"TLS (probably) not carrying HTTPS"},"proto":"TLS.DoH_DoT","breed":"Fun","category":"Network"},"tls": {"version":"TLSv1.2","client_requested_server_name":"dns.google","server_names":"dns.google,*.dns.google.com,8888.google,dns.google.com,dns64.dns.google","ja3":"2c776785ee603cc85d37df996bb90cc8","ja3s":"b44baa8a20901c5663b3a9664ba8a767","unsafe_cipher":0,"cipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","issuerDN":"C=US, O=Google Trust Services, CN=GTS CA 1O1","issuerDN":"C=US, ST=California, L=Mountain View, O=Google LLC, CN=dns.google","fingerprint":"5B:59:09:FC:7D:50:E6:F7:D1:08:8E:57:42:A2:D8:AE:1F:03:FF:EC"}}
00767{"flow_id":8,"flow_packet_id":8,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":299,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":119074,"pkt_caplen":305,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":305,"pkt_l4_len":271,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAEjSfIAAHYGK5AICAQEwKgBnwNVvFKvdqDURmVsRoAYAPBSpwAAAQEICn9zYvIAAH2vpuPGZP4JgUyAM7wCOdE4Fc16QU9KxcfuTIhOOPUog3Y3FGW+vpnz9jN1jLRfVrzUArxGxWLXFvRtjHjwsl6SCEkYsNE5RY4uTRDpU9uWBYz91xhpepEE0Quki2+5+Ao69X+zNarzIcksJTy7VNGA9mPObcF2ja\/A0h9v3eN06YBN5Gx+VkaA9eKqoP2Ok\/RNdhaTA3wp4woECZFYPCqog7eqqe\/\/eYo2V4kaFBuDro79ZWnsfyPD\/hfrPae1LgaUONOZb\/c2utzv2C7AVX5Zi9BG0\/aEPCZmoDR5UwzEKpJQ2FHTtCsWAwMABA4AAAA="}
00438{"flow_id":8,"flow_packet_id":9,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":300,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":120580,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0Fg1AAEAGVmTAqAGfCAgEBLxSA1VGZWxGr3abSoAQAWKJ1gAAAQEICgAAfbd\/c2Ly"}
00439{"flow_id":8,"flow_packet_id":10,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":301,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":121115,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0Fg5AAEAGVmPAqAGfCAgEBLxSA1VGZWxGr3ag1IAQAW2EQQAAAQEICgAAfbd\/c2Ly"}
00439{"flow_id":8,"flow_packet_id":11,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":302,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":121218,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"EBMx8Tl2ag\/ahpuQCABFAAA0Fg9AAEAGVmLAqAGfCAgEBLxSA1VGZWxGr3ahw4AQAW2DUgAAAQEICgAAfbd\/c2Ly"}
00569{"flow_id":8,"flow_packet_id":12,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":303,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":136587,"pkt_caplen":159,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":159,"pkt_l4_len":125,"pkt":"EBMx8Tl2ag\/ahpuQCABFAACRFhBAAEAGVgTAqAGfCAgEBLxSA1VGZWxGr3ahw4AYAW2vzgAAAQEICgAAfbt\/c2LyFgMDACUQAAAhIJkSTnDpQIa7DpGzu\/G1gW3LnyV4nS87HvRg7yx7Wl4YFAMDAAEBFgMDACgAAAAAAAAAAFEEa\/B2Ai\/upGK9I+N5Kptl6u7fR82l17fMpb3KE015"}
00843{"flow_id":8,"flow_packet_id":13,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":304,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":149896,"pkt_caplen":358,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":358,"pkt_l4_len":324,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAFYSgMAAHYGK0oICAQEwKgBnwNVvFKvdqHDRmVso4AYAPBy2wAAAQEICn9zYxIAAH27FgMDAOwEAADoAAGJwADiARwM3mDSTy2KnFOJMzn7skYIQXN0\/2tY\/9Yy+gWv+Ue7CvPIHCD5aJ5WQlCE11QpsnW60kjdl4gNz\/wsv9vCMdmQOOU3d\/dW+j4lHIFbnJmU3tTSxA9x+upSkAMJac8C8bp+qBGFGUs2U4s0Ko+QjjDu9HQyL1\/X\/Gd7VX4r+Vhti3LccpMwsHpiZ0o4JwPuthPI0LbcWoWxWnr4g0fil3IGw6UPbuA\/anPZyjKokO1FvKa0\/kNP2xizN8lpRdvl72lnswNXvfpKBnlVuksDYmrDKAks1HH63C83hGox2x+qiRQDAwABARYDAwAoAAAAAAAAAAA1U+0e0zdH7jZ6YkApz\/r+7sqkbi97MpL\/Yw+KPaFP5w=="}
00657{"flow_id":8,"flow_packet_id":14,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":305,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":152248,"pkt_caplen":225,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":225,"pkt_l4_len":191,"pkt":"EBMx8Tl2ag\/ahpuQCABFAADTFhFAAEAGVcHAqAGfCAgEBLxSA1VGZWyjr3ai54AYAXiZ1AAAAQEICgAAfb9\/c2MSFwMDAJoAAAAAAAAAASvU9Egx87RbkmJ13pZK7LHbvoZqJEW+LMQCXUVUsYXXYOT0A07A9oBhbd3xAqGLJVjanY8YjA+PchbEeksYAxBUebXNWt3CLGgqUZ1zZL2W9RktPfe\/xpJ61Di5ER1tDbATkasN2MFVlbRIP0cM9hu\/oS8YMUya1uNp3pnEVI9bPChlf\/XPzz7so24uZvPXyyE2"}
00439{"flow_id":8,"flow_packet_id":15,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":306,"source":"googledns_android10.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1592553007,"pkt_ts_usec":169844,"pkt_caplen":66,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":66,"pkt_l4_len":32,"pkt":"ag\/ahpuQEBMx8Tl2CABFAAA0ShMAAHYGLF4ICAQEwKgBnwNVvFKvdqLnRmVtQoAQAPSBbwAAAQEICn9zYyYAAH2\/"}
00511{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":532,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":133,"flow_first_seen":1592552878549,"flow_last_seen":1592552996502,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":517,"flow_tot_l4_payload_len":19828,"flow_avg_l4_payload_len":149,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48098,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00513{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":532,"source":"googledns_android10.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":241,"flow_first_seen":1592553007037,"flow_last_seen":1592553079303,"flow_min_l4_payload_len":0,"flow_max_l4_payload_len":1418,"flow_tot_l4_payload_len":48857,"flow_avg_l4_payload_len":202,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.159","dst_ip":"8.8.4.4","src_port":48210,"dst_port":853,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00140{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":532,"source":"googledns_android10.pcap","alias":"nDPId-test"}
~~~~~~~~~~~~~~~~~~~~ SUMMARY ~~~~~~~~~~~~~~~~~~~~
~~ packets captured/processed: 532/532
~~ skipped flows.............: 0
~~ total layer4 data length..: 114806 bytes
~~ total detected protocols..: 6
~~ total active/idle flows...: 8/8
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~ total memory allocated....: 4880159 bytes
~~ total memory freed........: 4880159 bytes
~~ total allocations/frees...: 58948/58948
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~