Reference of Open event subtypes for services that are unexpectedly open or exposed
socks
Traffic related to the SOCKS protocol, often used for proxy servicesproxy
Communication involving proxy servers, intermediaries that facilitate network connectionsrouter
Activity associated with routers, devices directing traffic between networksvpn
Interactions with Virtual Private Network servicesredis
Interactions with Redis, an open-source, in-memory data structure storemongodb
Traffic related to MongoDB, a NoSQL databaseelasticsearch
Activity involving Elasticsearch, a distributed search and analytics enginemssql
Traffic associated with Microsoft SQL Server or MySQL databasesmysql
MySQL database servicespostgresql
Traffic related to PostgreSQL database servicescouchdb
Activities associated with CouchDB, a NoSQL databasedb2
Traffic associated with IBM Db2 database servicesportmapper
Communication with portmapper services, facilitating RPC-based interactionstftp
Traffic related to Trivial File Transfer Protocol, a simple file transfer protocolftp
Communication involving File Transfer Protocol for file exchangesrsync
Traffic related to rsync, a file synchronization toolsmb
Interactions with Server Message Block protocol for file and printer sharingafp
Traffic associated with Apple Filing Protocol, used for Mac file servicesdirectory_listing
Traffic related to directory listing servicesrdp
Activities associated with Remote Desktop Protocol for remote accessvnc
Traffic involving Virtual Network Computing for remote desktop accesstelnet
Communication with Telnet services for remote command-line accessssh
Communication involving Secure Shell protocol for secure accessradmin
Traffic related to Radmin, a remote administration softwarecitrix
Communication with Citrix servers for virtualization and remote accesshttp
Communication involving Hypertext Transfer Protocol for web servicesapache_server
Activities associated with Apache web serversssl
Traffic related to secure communication using SSL/TLS protocolstls
Traffic related to secure communication using SSL/TLS protocolsmail_server
Traffic involving mail servers for email communicationimap
Interactions with IMAP or POP3 protocols for email retrievalpop3
Interactions with IMAP or POP3 protocols for email retrievaldns_resolver
Communication with DNS resolvers for domain name resolutionmdns_resolver
Interactions with mDNS resolvers, facilitating device discoverysnmp
Traffic associated with Simple Network Management Protocol, used for network monitoringipmi
Traffic related to Intelligent Platform Management Interface, used for server managementldap
Interactions with Lightweight Directory Access Protocol servicescwmp
Activities associated with CPE WAN Management Protocol for device managementics
Traffic involving Industrial Control Systems protocolsmodbus
Traffic involving Modbus protocol for industrial communicationbacnet
Traffic related to BACnet protocol for building automation and control networkscoap
Traffic related to Constrained Application Protocol for IoTmqtt
Traffic involving MQTT, a lightweight messaging protocol for IoTntp
Interactions with Network Time Protocol servers, synchronizing system clocksnetbios
Communication with NetBIOS services, often used for file sharingsip
Communication involving Session Initiation Protocol for multimedia sessionsstun
Interactions with Session Traversal Utilities for NAT protocolsamqp
Interactions with Advanced Message Queuing Protocol servicesard
Communication with Apple Remote Desktop servicesipp
Activities involving Internet Printing Protocol for printer communicationxdmcp
Activities related to X Display Manager Control Protocol for remote displayadb
Activities involving Android Debug Bridge for Android device interactionschargen
Traffic related to the Character Generator Protocolmemcached
Interactions with Memcached, an in-memory caching systemnatpmp
Communication with NAT Port Mapping Protocol for network address translationqotd
Traffic related to the Quote of the Day Protocolssdp
Interactions with Simple Service Discovery Protocol for device discoveryisakmp
Activities associated with Internet Security Association and Key Management Protocolhadoop
Communication with Hadoop services for distributed storage and processingcisco_smart_install
Activities related to Cisco Smart Install protocolgrafana
Interactions with Grafana, an open-source analytics and monitoring platformbitbucket
Communication with Bitbucket servers for source code managementgitlab_server
Traffic involving GitLab servers for source code managementubiquiti
Interactions with Ubiquiti network devicessmi
Activities associated with Structure of Management Information protocolbosmon
Traffic related to BosMon, a monitoring system for emergency servicesms_exchange
Communication with Microsoft Exchange servers for email servicesms_sharepoint
Communication with Microsoft SharePoint serversms_rpc
Microsoft RPC servicessecvest_alarm_system
Activities involving Secvest Alarm System protocolskubernetes_api_server
Communication with Kubernetes API serversepmd
Interactions with Erlang Port Mapper Daemon servicesquic
Communication involving QUIC (Quick UDP Internet Connections) protocoldocker
Traffic related to Docker, a containerization platformdvr
Activities related to Digital Video Recorder serviceshp_ilo
Communication with Hewlett Packard Integrated Lights-Out managementsmarter_mail_server
Interactions with SmarterMail servers for email serviceslog4j
Traffic related to Log4j, a Java-based logging utilityzimbra_server
Communication with Zimbra Collaboration Suite serverssap
Activities involving SAP (Systems, Applications, and Products) servicesqnap
Communication with QNAP network-attached storage devicesconfluence
Interactions with Confluence servers for collaboration and documentationsophos
Traffic involving Sophos security solutionsh2_web_console
Communication with H2 Database web consolesfortigate
Interactions with Fortigate, a network security applianceivanti
Activities associated with Ivanti endpoint management solutionsmc_sqlr
Activities associated with Microsoft SQL Server