Protocols Supported For Inspection and Analysis

Our NDR provides full protocol decoding, anomaly detection, structured logging, and file extraction support for the protocols below.

Detailed Protocol Support Table:

Protocol CategoryProtocolDecodingAnomaly DetectionFile ExtractionLoggingNotes
Link / L2Ethernet / VLAN / QinQYesYesNoYesFull header parsing
NetworkIPv4 / IPv6 / ICMPYesYesNoYesFragment reassembly
TransportTCP / UDPYesYesNoYesStream reassembly
Application (IT)HTTP / HTTP2YesYesYesYesURI, headers, body
Application (IT)TLSYesYesNoYesJA3 / JA4 / certs
Application (IT)DNSYesYesNoYesQuery/response
Application (IT)SMTPYesYesYesYesAttachments
Application (IT)SSHYesYesNoYesVersion / key exchange
Application (IT)SMB (v1–v3)YesYesYesYesFile transfers
Application (IT)FTPYesYesYesYesData channel
Application (IT)RDPYesYesNoYesBasic session
Application (IT)QUICYesYesNoYesJA4 / ALPN
OT / ICSModbusYesYesYesYesIndustrial commands
OT / ICSDNP3YesYesNoYesSCADA
OT / ICSENIP / CIPYesYesYesYesRockwell
OT / ICSS7commYesYesYesYesSiemens
OT / ICSBACnetYesYesNoYesBuilding automation
OT / ICSIEC104YesYesNoYesPower grid
VoIPSIP / SDPYesYesNoYesSession setup
VariableType to search · ESC to discard
GlossaryType to search · ESC to discard
InsertType to search · ESC to discard
No matches