| .. |
|
1kxun.pcap.out
|
Updated results with numeric IP detection
|
2020-11-01 13:31:00 +01:00 |
|
4in4tunnel.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
4in6tunnel.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
6in4tunnel.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
6in6tunnel.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
443-chrome.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
443-curl.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
443-firefox.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
443-git.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
443-opvn.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
443-safari.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
ajp.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
among_us.pcap.out
|
Renumbered AmongUs protocol
|
2020-11-09 16:23:01 +01:00 |
|
amqp.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
android.pcap.out
|
Reworked MDNS dissector that is not based on the DNS dissector
|
2020-09-17 23:24:02 +02:00 |
|
anyconnect-vpn.pcap.out
|
Updated results with numeric IP detection
|
2020-11-01 13:31:00 +01:00 |
|
anydesk.pcap.out
|
Added risks for checking
|
2020-09-21 19:57:23 +02:00 |
|
bad-dns-traffic.pcap.out
|
Added risks for checking
|
2020-09-21 19:57:23 +02:00 |
|
badpackets.pcap.out
|
Added badpackets.pcap
|
2020-03-23 10:06:16 +01:00 |
|
BGP_Cisco_hdlc_slarp.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
BGP_redist.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
bitcoin.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
bittorrent.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
bittorrent_ip.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
bittorrent_utp.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
bt_search.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
capwap.pcap.out
|
CAPWAP tunnel decoding fix (#1038)
|
2020-10-21 15:07:20 +02:00 |
|
check_mk_new.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
coap_mqtt.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
cpha.pcap.out
|
Added CPHA - CheckPoint High Availability Protocol protocl support
|
2020-10-22 18:39:13 +02:00 |
|
diameter.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
dlt_ppp.pcap.out
|
Fix parsing of DLT_PPP datalink type (#1042)
|
2020-10-21 22:27:42 +02:00 |
|
dnp3.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
dns-tunnel-iodine.pcap.out
|
Added risks for checking
|
2020-09-21 19:57:23 +02:00 |
|
dns_doh.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
dns_dot.pcap.out
|
Tests update
|
2020-10-02 21:35:15 +02:00 |
|
dns_exfiltration.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
dns_long_domainname.pcap.out
|
Added extension to detect nested subdomains as used in Browsertunnel attack tool
|
2020-09-09 23:25:19 +02:00 |
|
dnscrypt-v1-and-resolver-pings.pcap.out
|
Added pcap file which contains dnscrypt-v1 data and resolver update requests/responses (v1/v2).
|
2020-09-07 21:04:23 +02:00 |
|
dnscrypt-v2-doh.pcap.out
|
Added dnscrypt-v2-doh resolver test pcaps.
|
2020-09-07 20:22:52 +02:00 |
|
dos_win98_smb_netbeui.pcap.out
|
Added new risk for NDPI_UNSAFE_PROTOCOL that identifies protocols that are not condidered safe/secure
|
2020-08-30 20:48:58 +02:00 |
|
drda_db2.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
dropbox.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
dtls.pcap.out
|
Added risks for checking
|
2020-09-21 19:57:23 +02:00 |
|
EAQ.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
encrypted_sni.pcap.out
|
Updated ESNI/SNI alarm generation prolicy
|
2020-11-08 10:07:35 +01:00 |
|
ethereum.pcap.out
|
Added new risk for NDPI_UNSAFE_PROTOCOL that identifies protocols that are not condidered safe/secure
|
2020-08-30 20:48:58 +02:00 |
|
exe_download.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
exe_download_as_png.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
facebook.pcap.out
|
Various optimizations to reduce not-necessary calls
|
2020-09-24 23:26:03 +02:00 |
|
fbzero-missing-lengthcheck.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
fix.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
ftp.pcap.out
|
Added new risk for NDPI_UNSAFE_PROTOCOL that identifies protocols that are not condidered safe/secure
|
2020-08-30 20:48:58 +02:00 |
|
ftp_failed.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
fuzz-2006-06-26-2594.pcap.out
|
Reworked MDNS dissector that is not based on the DNS dissector
|
2020-09-17 23:24:02 +02:00 |
|
fuzz-2006-09-29-28586.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
fuzz-2020-02-16-11740.pcap.out
|
Fixed false positive detection for Skype.SkypeCall (affects at least Cisco HSRP and RADIUS).
|
2020-09-02 07:29:33 +02:00 |
|
git.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
google_ssl.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
googledns_android10.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
gquic.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
h323-overflow.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
hangout.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
http-crash-content-disposition.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
http-lines-split.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
http_ipv6.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
iec60780-5-104.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
imaps.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
instagram.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
iphone.pcap.out
|
Reworked MDNS dissector that is not based on the DNS dissector
|
2020-09-17 23:24:02 +02:00 |
|
ipv6_in_gtp.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
ja3_lots_of_cipher_suites.pcap.out
|
Added risks for checking
|
2020-09-21 19:57:23 +02:00 |
|
ja3_lots_of_cipher_suites_2_anon.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
KakaoTalk_chat.pcap.out
|
Tests update
|
2020-10-02 21:35:15 +02:00 |
|
KakaoTalk_talk.pcap.out
|
Fixes #1033
|
2020-10-21 20:59:02 +02:00 |
|
kerberos.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
malformed_dns.pcap.out
|
Reworked MDNS dissector that is not based on the DNS dissector
|
2020-09-17 23:24:02 +02:00 |
|
malformed_icmp.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
malware.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
modbus.pcap.out
|
Creared IoT-Scada category
|
2020-08-23 13:32:36 +02:00 |
|
monero.pcap.out
|
Added new risk for NDPI_UNSAFE_PROTOCOL that identifies protocols that are not condidered safe/secure
|
2020-08-30 20:48:58 +02:00 |
|
mongodb.pcap.out
|
💡 Add mongodb protocol dissector (#1048)
|
2020-11-03 16:16:02 +01:00 |
|
mpeg.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
mpegts.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
mssql_tds.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
mysql-8.pcap.out
|
MySQL8 update
|
2020-08-21 07:17:34 +02:00 |
|
nats.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
nest_log_sink.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
netbios.pcap.out
|
Added new risk for NDPI_UNSAFE_PROTOCOL that identifies protocols that are not condidered safe/secure
|
2020-08-30 20:48:58 +02:00 |
|
netbios_wildcard_dns_query.pcap.out
|
Added the ability do identigy as DGA those host/domain names with too many consucutive repeated characters
|
2020-08-21 18:41:35 +02:00 |
|
netflix.pcap.out
|
Various optimizations to reduce not-necessary calls
|
2020-09-24 23:26:03 +02:00 |
|
netflow-fritz.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
netflowv9.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
nintendo.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
no_sni.pcap.out
|
Updated ESNI/SNI alarm generation prolicy
|
2020-11-08 10:07:35 +01:00 |
|
NTPv2.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
NTPv3.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
NTPv4.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
ocs.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
ookla.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
openvpn.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
Oscar.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
pps.pcap.out
|
Fixes #1033
|
2020-10-21 20:59:02 +02:00 |
|
ps_vue.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
quic-23.pcap.out
|
Add sub-classification for GQUIC >= Q050 and (IETF-)QUIC
|
2020-08-21 22:04:55 +02:00 |
|
quic-24.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
quic-27.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic-28.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
quic-29.pcap.out
|
QUIC: minor fixes
|
2020-08-24 13:53:36 +02:00 |
|
quic-mvfst-22.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
quic-mvfst-22_decryption_error.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
quic-mvfst-27.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic-mvfst-exp.pcap.out
|
QUIC: add support for MVFST EXPERIMENTAL version
|
2020-09-20 16:38:28 +02:00 |
|
quic.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic046.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic_0RTT.pcap.out
|
QUIC: fix dissection of Initial packets coalesced with 0-RTT one (#1044)
|
2020-11-03 11:35:52 +01:00 |
|
quic_q39.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic_q43.pcap.out
|
Major rework of QUIC dissector
|
2020-08-21 22:04:55 +02:00 |
|
quic_q46.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic_q46_b.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic_q50.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic_t50.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quic_t51.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
quickplay.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
rdp.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
rx.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
s7comm.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
selfsigned.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
signal.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
simple-dnscrypt.pcap.out
|
Added pcap file which contains dnscrypt-v1 data and resolver update requests/responses (v1/v2).
|
2020-09-07 21:04:23 +02:00 |
|
sip.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
skype-conference-call.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
skype.pcap.out
|
Tests update
|
2020-10-02 21:35:15 +02:00 |
|
skype_no_unknown.pcap.out
|
Tests update
|
2020-10-02 21:35:15 +02:00 |
|
skype_udp.pcap.out
|
Improve skype detection (#1039)
|
2020-10-27 08:45:09 +01:00 |
|
smb_deletefile.pcap.out
|
Fixes invalid detection on traffic on non standard ports
|
2020-08-12 11:08:28 +02:00 |
|
smbv1.pcap.out
|
Added new risk for NDPI_UNSAFE_PROTOCOL that identifies protocols that are not condidered safe/secure
|
2020-08-30 20:48:58 +02:00 |
|
smpp_in_general.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
snapchat.pcap.out
|
Added risks for checking
|
2020-09-21 19:57:23 +02:00 |
|
ssdp-m-search.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
ssh.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
starcraft_battle.pcap.out
|
Fixes #1033
|
2020-10-21 20:59:02 +02:00 |
|
steam.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
teams.pcap.out
|
Various optimizations to reduce not-necessary calls
|
2020-09-24 23:26:03 +02:00 |
|
teamspeak3.pcap.out
|
Improved Teamspeak(3) protocol detection.
|
2020-09-09 21:57:31 +02:00 |
|
telegram.pcap.out
|
Updated results
|
2020-09-18 00:17:43 +02:00 |
|
teredo.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
tftp_rrq.pcap.out
|
Various optimizations to reduce not-necessary calls
|
2020-09-24 23:26:03 +02:00 |
|
tinc.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
tls-esni-fuzzed.pcap.out
|
Updated ESNI/SNI alarm generation prolicy
|
2020-11-08 10:07:35 +01:00 |
|
tls-rdn-extract.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
tls_esni_sni_both.pcap.out
|
Suspicious ESNI usage: add a comment and a pcap example
|
2020-08-06 10:29:35 +02:00 |
|
tls_long_cert.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
tls_verylong_certificate.pcap.out
|
Fixed partial TLS dissection
|
2020-07-30 18:30:07 +02:00 |
|
tor.pcap.out
|
Added new risk for NDPI_UNSAFE_PROTOCOL that identifies protocols that are not condidered safe/secure
|
2020-08-30 20:48:58 +02:00 |
|
ubntac2.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
upnp.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
viber.pcap.out
|
Various optimizations to reduce not-necessary calls
|
2020-09-24 23:26:03 +02:00 |
|
vnc.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
wa_video.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
wa_voice.pcap.out
|
Reworked MDNS dissector that is not based on the DNS dissector
|
2020-09-17 23:24:02 +02:00 |
|
waze.pcap.out
|
Fixes #1033
|
2020-10-21 20:59:02 +02:00 |
|
WebattackRCE.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
WebattackSQLinj.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
WebattackXSS.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
webex.pcap.out
|
Tests update
|
2020-10-02 21:35:15 +02:00 |
|
websocket.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
wechat.pcap.out
|
Reworked MDNS dissector that is not based on the DNS dissector
|
2020-09-17 23:24:02 +02:00 |
|
weibo.pcap.out
|
Stddev calculation changes
|
2020-08-30 12:48:32 +02:00 |
|
whatsapp_login_call.pcap.out
|
Various optimizations to reduce not-necessary calls
|
2020-09-24 23:26:03 +02:00 |
|
whatsapp_login_chat.pcap.out
|
Reworked MDNS dissector that is not based on the DNS dissector
|
2020-09-17 23:24:02 +02:00 |
|
whatsapp_voice_and_message.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
whatsappfiles.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
wireguard.pcap.out
|
Fixed false positive in suspicous user agent
|
2020-08-30 12:25:15 +02:00 |
|
youtube_quic.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
youtubeupload.pcap.out
|
QUIC: extract User Agent information
|
2020-09-08 11:03:22 +02:00 |
|
zabbix.pcap.out
|
Changed due to bin size extension
|
2020-07-30 00:06:46 +02:00 |
|
zcash.pcap.out
|
Added new risk for NDPI_UNSAFE_PROTOCOL that identifies protocols that are not condidered safe/secure
|
2020-08-30 20:48:58 +02:00 |
|
zoom.pcap.out
|
Various optimizations to reduce not-necessary calls
|
2020-09-24 23:26:03 +02:00 |