PacketSafari

Technical datasheet

Explore PacketSafari support

From protocol decoding to deterministic checks and AI investigation. Browse the complete catalogue below, then expand any entry for the detail.

All support areas are shown by default. Open a group to explore it.

01

Supported protocols

Browse all 3,218 protocol and format entries, alphabetically by their short name. Open a letter to see every entry in that group.

Decoding includes packet fields and message structure where visible. It does not mean every protocol has a dedicated automatic diagnostic. Encrypted content needs suitable decryption material where supported. Private or proprietary protocols can be assessed on request.

0–9 & symbols 1229West · 2dparityfec · 3COMXNS
  • 29West29West Protocol
  • 2dparityfecPro-MPEG Code of Practice #3 release 2 FEC Protocol
  • 3COMXNS3Com XNS Encapsulation
  • 3GPP COMMON3GPP COMMON
  • 3GPP2 A113GPP2 A11
  • 5co-legacyFiveCo's Legacy Register Access Protocol
  • 5co-rapFiveCo RAP Register Access Protocol
  • 6LoWPANIPv6 over Low power Wireless Personal Area Networks
  • 802.11 Radio802.11 radio information
  • 802.11 RadiotapIEEE 802.11 Radiotap Capture header
  • 802.11 RSNA EAPOLIEEE 802.11 RSNA EAPOL key
  • 9PPlan 9
A 150A-bis OML · A21 · A615a
  • A-bis OMLGSM A-bis OML
  • A21A21 Protocol
  • A615aArinc 615a Protocol
  • AAFAVTP Audio Format
  • AAL1ATM AAL1
  • AAL3/4ATM AAL3/4
  • AARPAppletalk Address Resolution Protocol
  • AASPAastra Signalling Protocol
  • AC DRDebug Recording Trace
  • ACAPApplication Configuration Access Protocol
  • Access Network IdentifierMIPv6 Option - Access Network Identifier
  • Access Point NameAccess Point Name
  • Access Technology Type OptionMIPv6 Option - Access Technology Type Option
  • Accurate ECNTCP Option - Accurate ECN
  • ACFACF Message
  • ACNArchitecture for Control Networks
  • ACN/DMPACN Device Management Protocol
  • ACN/SDT_WRAPACN SDT Wrapped Message
  • ACP133ACP133 Attribute Syntaxes
  • ACR 122Advanced Card Systems ACR122
  • ACSEISO 8650-1 OSI Association Control Service
  • ACtraceTrunk Trace
  • ADBAndroid Debug Bridge
  • ADB CSAndroid Debug Bridge Client-Server
  • ADB ServiceAndroid Debug Bridge Service
  • ADDGRPCDSRC Addition Grp C (EU)
  • Address Allocation CauseAddress Allocation Cause
  • Address and Control Field CompressionAddress and Control Field Compression
  • Admin TypeBPv7 Administrative Record Type
  • ADPAruba Discovery Protocol
  • ADSPAppleTalk Data Stream Protocol
  • ADwinADwin communication protocol
  • ADwin-ConfigADwin configuration protocol
  • AeronAeron Protocol
  • AFPApple Filing Protocol
  • AFS (RX)Andrew File System (AFS)
  • AgentXAgentX
  • AHAuthentication Header
  • AIMAOL Instant Messenger
  • AIM AdministrationAIM Administrative
  • AIM AdvertisementsAIM Advertisements
  • AIM BOSAIM Privacy Management Service
  • AIM BuddylistAIM Buddylist Service
  • AIM ChatAIM Chat Service
  • AIM ChatNavAIM Chat Navigation
  • AIM DirectoryAIM Directory Search
  • AIM EmailAIM E-mail
  • AIM GenericAIM Generic Service
  • AIM ICQAIM ICQ
  • AIM InvitationAIM Invitation Service
  • AIM LocationAIM Location
  • AIM MessagingAIM Messaging
  • AIM PopupAIM Popup
  • AIM SignonAIM Signon
  • AIM SSIAIM Server Side Info
  • AIM SSTAIM Server Side Themes
  • AIM StatsAIM Statistics
  • AIM TranslateAIM Translate
  • AIM User LookupAIM User Lookup
  • AINAdvanced Intelligent Network
  • AJP13Apache JServ Protocol v1.3
  • AKPAsymmetric Key Packages
  • ALCAsynchronous Layered Coding
  • ALCAPAAL type 2 signalling protocol (Q.2630)
  • Align-NPDUAlign-NPDU
  • AllJoynAllJoyn Message Protocol
  • AllJoyn ARDPAllJoyn Reliable Datagram Protocol
  • AllJoyn NSAllJoyn Name Service Protocol
  • ALPATSC Link-Layer Protocol
  • AltBeaconAltBeacon
  • Alternate Care-of AddressMIPv6 Option - Alternate Care-of Address
  • Alternate IPv4MIPv6 Option - Alternate IPv4
  • AMFAction Message Format
  • AMPAMP
  • AMQPAdvanced Message Queuing Protocol
  • AMRAdaptive Multi-Rate
  • AMR WBAdaptive Multi-Rate WB
  • AMSAMS
  • AMTAutomatic Multicast Tunneling
  • ANCPAccess Node Control Protocol
  • ANSIntel ANS probe
  • ANSI BSMAPANSI A-I/F BSMAP
  • ANSI DTAPANSI A-I/F DTAP
  • ANSI IS-637-A TeleserviceANSI IS-637-A (SMS) Teleservice Layer
  • ANSI IS-637-A TransportANSI IS-637-A (SMS) Transport Layer
  • ANSI IS-683 (OTA (Mobile))ANSI IS-683 (OTA (Mobile))
  • ANSI IS-801 (Location Services (PLD))ANSI IS-801 (Location Services (PLD))
  • ANSI MAPANSI Mobile Application Part
  • ANSI_TCAPANSI Transaction Capabilities Application Part
  • AODVAd hoc On-demand Distance Vector Routing Protocol
  • AOEATAoverEthernet
  • AOLAmerica Online
  • APN Aggregate Maximum Bit Rate(APN-AMBR)APN Aggregate Maximum Bit Rate(APN-AMBR)
  • AppleMIDIApple Network-MIDI Session Protocol
  • APRSAutomatic Position Reporting System
  • aptXaptX Codec
  • AR DroneAR Drone Packet
  • ARCNETARCNET
  • ArmagetronadThe Armagetron Advanced OpenGL Tron clone
  • ARP/RARPAddress Resolution Protocol
  • Art-NetArt-Net
  • ArtemisArtemis Core Protocol
  • ARUBA ERM AIRMAGNET (Type 2)Aruba Networks encapsulated remote mirroring - AIRMAGNET (Type 2)
  • ARUBA ERM PCAP (Type 0)Aruba Networks encapsulated remote mirroring - PCAP (Type 0)
  • ARUBA ERM PCAP+RADIO (Type 3)Aruba Networks encapsulated remote mirroring - PCAP+RADIO (Type 3)
  • ARUBA ERM PEEK (type 1)Aruba Networks encapsulated remote mirroring - PEEK (Type 1)
  • ARUBA ERM PEEK-NG (type 5)Aruba Networks encapsulated remote mirroring - PEEK (Type 5)
  • ARUBA ERM PPI (Type 4)Aruba Networks encapsulated remote mirroring - PPI (Type 4)
  • ARUBA ERM RADIOTAP (type 6)Aruba Networks encapsulated remote mirroring - RADIOTAP (Type 6)
  • ARUBA_ERMAruba Networks encapsulated remote mirroring
  • aruba_iapAruba Instant AP Protocol
  • ASAM CMPASAM Capture Module Protocol
  • ASAPAggregate Server Access Protocol
  • ASFAlert Standard Forum
  • ASPAppleTalk Session Protocol
  • AsphodelAsphodel
  • ASTERIXASTERIX packet
  • Async Control Character MapAsync Control Character Map
  • ATAT Command
  • AT LDFAllied Telesis Loop Detection
  • AT RLAllied Telesis Resiliency Link
  • ATHApache Tribes Heartbeat Protocol
  • ATMAsynchronous Transfer Mode
  • ATM CellATM Cell
  • ATM LANEATM LAN Emulation
  • ATMARPATM Address Resolution Protocol
  • ATMTCPATM over TCP
  • ATN SLATN Security Label
  • ATN-CMICAO Doc9705 CM
  • ATN-CPDLCICAO Doc9705 CPDLC
  • ATN-ULCSICAO Doc9705 ULCS
  • ATPAppleTalk Transaction Protocol packet
  • ATSVCMicrosoft AT-Scheduler Service
  • Attach TypeAttach Type
  • AUTH-OPTION-TYPEMIPv6 Option - AUTH-OPTION-TYPE
  • Authentication OptionAuthentication Option
  • Authentication ProtocolAuthentication Protocol
  • Authorization DataMIPv6 Option - Authorization Data
  • Auto-RPCisco Auto-RP
  • AUTOSAR I-PduMAUTOSAR I-PDU Multiplexer
  • AUTOSAR NMAUTOSAR Network Management
  • AVS WLANCAPAVS WLAN Capture header
  • AVSPArista Vendor Specific Protocol
  • AWDLApple Wireless Direct Link action frame
  • AWDL dataApple Wireless Direct Link data frame
  • AX.25Amateur Radio AX.25
  • AX.25 KISSAX.25 KISS
  • AX.25 no L3AX.25 no Layer 3
  • AX4000AX/4000 Test Block
  • AYIYAAnything in Anything Protocol
B 757Babel · BACapp · BACnet
  • BabelBabel Routing Protocol
  • BACappBuilding Automation and Control Network APDU
  • BACnetBuilding Automation and Control Network NPDU
  • BACnet MS/TPBACnet MS/TP
  • BananaTwisted Banana
  • Basic Format XIDLogical-Link Control Basic Format XID
  • BATB.A.T.M.A.N. Layer 3 Protocol
  • BAT GWB.A.T.M.A.N. GW
  • BAT VISB.A.T.M.A.N. Vis
  • BATADVB.A.T.M.A.N. Advanced Protocol
  • BazaarBazaar Smart Protocol
  • BBLogBlack Box Log
  • BCTPBCTP Q.1990
  • BEEPBlocks Extensible Exchange Protocol
  • BencodeBencode
  • BERBasic Encoding Rules (ASN.1 X.690)
  • BFCPBinary Floor Control Protocol
  • BFD ControlBidirectional Forwarding Detection Control Message
  • BFD EchoBidirectional Forwarding Detection Echo Packet
  • BGPBorder Gateway Protocol
  • BICCBearer Independent Call Control
  • BICC-MST3GPP BICC MST
  • BIERBit Index Explicit Replication
  • Binary HTTPBinary representation of HTTP Messages
  • Binding Authorization Data for FMIPv6 (BADF)MIPv6 Option - Binding Authorization Data for FMIPv6 (BADF)
  • Binding IdentifierMIPv6 Option - Binding Identifier
  • Binding Refresh AdviceMIPv6 Option - Binding Refresh Advice
  • BIST-OUCHBIST OUCH
  • BIST‑ITCHBIST ITCH
  • BitcoinBitcoin protocol
  • BitTorrentBitTorrent
  • BJNPCanon BJNP
  • BLF-Ethernet-PHY-StateBLF Ethernet PHY State
  • BLF-Ethernet-StatusBLF Ethernet Status
  • BLIPBLIP Couchbase Mobile
  • Block TypeBPv7 Block Type
  • bluecombluecom Protocol
  • BluetoothBluetooth
  • BMCBroadcast/Multicast Control
  • BMPBGP Monitoring Protocol
  • BoardwalkBoardwalk
  • BOFLWellfleet Breath of Life
  • BOOTPARAMSBoot Parameters
  • BOSSVRDCE DFS Basic Overseer Server
  • BPBundle Protocol
  • BPQAmateur Radio BPQ
  • BPSecDTN Bundle Protocol Security
  • BPSec COSEBPSec COSE Context
  • BPSec Default SCBPSec Default Security Contexts
  • BPv7DTN Bundle Protocol Version 7
  • BPv7 AdminBPv7 Administrative Record
  • Bridge Control Packet IndicatorBridge Control Packet Indicator
  • Bridge-IdentificationBridge-Identification
  • Broadcom tagBroadcom tag protocol
  • BROWSERMicrosoft Windows Browser Protocol
  • BRPBRP Protocol
  • BSAPBSAP
  • BSCVLCBACnet Secure Connect Virtual Link Control
  • BSD LZW CompressBSD LZW Compress
  • BSSAPBSSAP
  • BSSAP-LEBSSAP-LE
  • BSSAP2BSSAP2
  • BSSGPBase Station Subsystem GPRS Protocol
  • BSSLAPBSS LCS Assistance Protocol
  • BT 3DSBluetooth 3DS Profile
  • BT A2DPBluetooth A2DP Profile
  • BT A2DP Content Protection Header SCMS-TBluetooth A2DP Content Protection Header SCMS-T
  • BT AMPBluetooth AMP Packet
  • BT ATTBluetooth Attribute Protocol
  • BT AVCTPBluetooth AVCTP Protocol
  • BT AVDTPBluetooth AVDTP Protocol
  • BT AVRCPBluetooth AVRCP Profile
  • BT BIP Application ParametersBluetooth OBEX BIP Application Parameters
  • BT BNEPBluetooth BNEP Protocol
  • BT BPP Application ParametersBluetooth OBEX BPP Application Parameters
  • BT BR/EDR FHSBluetooth BR/EDR FHS
  • BT BR/EDR RFBluetooth Pseudoheader for BR/EDR
  • BT CommonBluetooth Common
  • BT CTN Application ParametersBluetooth OBEX CTN Application Parameters
  • BT DUNBluetooth DUN Packet
  • BT GATTBluetooth GATT Attribute Protocol
  • BT GATT Acceleration - 3D (UUID 0x2c1d)Bluetooth GATT Attribute Acceleration - 3D (UUID 0x2c1d)
  • BT GATT Acceleration (UUID 0x2c06)Bluetooth GATT Attribute Acceleration (UUID 0x2c06)
  • BT GATT Acceleration Detection Status (UUID 0x2c1f)Bluetooth GATT Attribute Acceleration Detection Status (UUID 0x2c1f)
  • BT GATT ACS Control Point (UUID 0x2b33)Bluetooth GATT Attribute ACS Control Point (UUID 0x2b33)
  • BT GATT ACS Data In (UUID 0x2b30)Bluetooth GATT Attribute ACS Data In (UUID 0x2b30)
  • BT GATT ACS Data Out Indicate (UUID 0x2b32)Bluetooth GATT Attribute ACS Data Out Indicate (UUID 0x2b32)
  • BT GATT ACS Data Out Notify (UUID 0x2b31)Bluetooth GATT Attribute ACS Data Out Notify (UUID 0x2b31)
  • BT GATT ACS Status (UUID 0x2b2f)Bluetooth GATT Attribute ACS Status (UUID 0x2b2f)
  • BT GATT Active Preset Index (UUID 0x2bdc)Bluetooth GATT Attribute Active Preset Index (UUID 0x2bdc)
  • BT GATT Activity Goal (UUID 0x2b4e)Bluetooth GATT Attribute Activity Goal (UUID 0x2b4e)
  • BT GATT Advertising Constant Tone Extension Interval (UUID 0x2bb1)Bluetooth GATT Attribute Advertising Constant Tone Extension Interval (UUID 0x2bb1)
  • BT GATT Advertising Constant Tone Extension Minimum Length (UUID 0x2bae)Bluetooth GATT Attribute Advertising Constant Tone Extension Minimum Length (UUID 0x2bae)
  • BT GATT Advertising Constant Tone Extension Minimum Transmit Count (UUID 0x2baf)Bluetooth GATT Attribute Advertising Constant Tone Extension Minimum Transmit Count (UUID 0x2baf)
  • BT GATT Advertising Constant Tone Extension PHY (UUID 0x2bb2)Bluetooth GATT Attribute Advertising Constant Tone Extension PHY (UUID 0x2bb2)
  • BT GATT Advertising Constant Tone Extension Transmit Duration (UUID 0x2bb0)Bluetooth GATT Attribute Advertising Constant Tone Extension Transmit Duration (UUID 0x2bb0)
  • BT GATT Aerobic Heart Rate Lower Limit (UUID 0x2a7e)Bluetooth GATT Attribute Aerobic Heart Rate Lower Limit (UUID 0x2a7e)
  • BT GATT Aerobic Heart Rate Upper Limit (UUID 0x2a84)Bluetooth GATT Attribute Aerobic Heart Rate Upper Limit (UUID 0x2a84)
  • BT GATT Aerobic Threshold (UUID 0x2a7f)Bluetooth GATT Attribute Aerobic Threshold (UUID 0x2a7f)
  • BT GATT Age (UUID 0x2a80)Bluetooth GATT Attribute Age (UUID 0x2a80)
  • BT GATT Aggregate (UUID 0x2a5a)Bluetooth GATT Attribute Aggregate (UUID 0x2a5a)
  • BT GATT Alert Category ID (UUID 0x2a43)Bluetooth GATT Attribute Alert Category ID (UUID 0x2a43)
  • BT GATT Alert Category ID Bit Mask (UUID 0x2a42)Bluetooth GATT Attribute Alert Category ID Bit Mask (UUID 0x2a42)
  • BT GATT Alert Level (UUID 0x2a06)Bluetooth GATT Attribute Alert Level (UUID 0x2a06)
  • BT GATT Alert Notification (UUID 0x1811)Bluetooth GATT Attribute Alert Notification (UUID 0x1811)
  • BT GATT Alert Notification Control Point (UUID 0x2a44)Bluetooth GATT Attribute Alert Notification Control Point (UUID 0x2a44)
  • BT GATT Alert Status (UUID 0x2a3f)Bluetooth GATT Attribute Alert Status (UUID 0x2a3f)
  • BT GATT Altitude (UUID 0x2ab3)Bluetooth GATT Attribute Altitude (UUID 0x2ab3)
  • BT GATT Ammonia Concentration (UUID 0x2bcf)Bluetooth GATT Attribute Ammonia Concentration (UUID 0x2bcf)
  • BT GATT Anaerobic Heart Rate Lower Limit (UUID 0x2a81)Bluetooth GATT Attribute Anaerobic Heart Rate Lower Limit (UUID 0x2a81)
  • BT GATT Anaerobic Heart Rate Upper Limit (UUID 0x2a82)Bluetooth GATT Attribute Anaerobic Heart Rate Upper Limit (UUID 0x2a82)
  • BT GATT Anaerobic Threshold (UUID 0x2a83)Bluetooth GATT Attribute Anaerobic Threshold (UUID 0x2a83)
  • BT GATT Analog (UUID 0x2a58)Bluetooth GATT Attribute Analog (UUID 0x2a58)
  • BT GATT Analog Output (UUID 0x2a59)Bluetooth GATT Attribute Analog Output (UUID 0x2a59)
  • BT GATT AP Sync Key Material (UUID 0x2bf7)Bluetooth GATT Attribute AP Sync Key Material (UUID 0x2bf7)
  • BT GATT Apparent Energy 32 (UUID 0x2b89)Bluetooth GATT Attribute Apparent Energy 32 (UUID 0x2b89)
  • BT GATT Apparent Power (UUID 0x2b8a)Bluetooth GATT Attribute Apparent Power (UUID 0x2b8a)
  • BT GATT Apparent Wind Direction (UUID 0x2a73)Bluetooth GATT Attribute Apparent Wind Direction (UUID 0x2a73)
  • BT GATT Apparent Wind Speed (UUID 0x2a72)Bluetooth GATT Attribute Apparent Wind Speed (UUID 0x2a72)
  • BT GATT Appearance (UUID 0x2a01)Bluetooth GATT Attribute Appearance (UUID 0x2a01)
  • BT GATT ASE Control Point (UUID 0x2bc6)Bluetooth GATT Attribute ASE Control Point (UUID 0x2bc6)
  • BT GATT Audio Input Control (UUID 0x1843)Bluetooth GATT Attribute Audio Input Control (UUID 0x1843)
  • BT GATT Audio Input Control Point (UUID 0x2b7b)Bluetooth GATT Attribute Audio Input Control Point (UUID 0x2b7b)
  • BT GATT Audio Input Description (UUID 0x2b7c)Bluetooth GATT Attribute Audio Input Description (UUID 0x2b7c)
  • BT GATT Audio Input State (UUID 0x2b77)Bluetooth GATT Attribute Audio Input State (UUID 0x2b77)
  • BT GATT Audio Input Status (UUID 0x2b7a)Bluetooth GATT Attribute Audio Input Status (UUID 0x2b7a)
  • BT GATT Audio Input Type (UUID 0x2b79)Bluetooth GATT Attribute Audio Input Type (UUID 0x2b79)
  • BT GATT Audio Location (UUID 0x2b81)Bluetooth GATT Attribute Audio Location (UUID 0x2b81)
  • BT GATT Audio Output Description (UUID 0x2b83)Bluetooth GATT Attribute Audio Output Description (UUID 0x2b83)
  • BT GATT Audio Stream Control (UUID 0x184e)Bluetooth GATT Attribute Audio Stream Control (UUID 0x184e)
  • BT GATT Authorization Control (UUID 0x183d)Bluetooth GATT Attribute Authorization Control (UUID 0x183d)
  • BT GATT Automation IO (UUID 0x1815)Bluetooth GATT Attribute Automation IO (UUID 0x1815)
  • BT GATT Available Audio Contexts (UUID 0x2bcd)Bluetooth GATT Attribute Available Audio Contexts (UUID 0x2bcd)
  • BT GATT Average Current (UUID 0x2ae0)Bluetooth GATT Attribute Average Current (UUID 0x2ae0)
  • BT GATT Average Voltage (UUID 0x2ae1)Bluetooth GATT Attribute Average Voltage (UUID 0x2ae1)
  • BT GATT Barometric Pressure Trend (UUID 0x2aa3)Bluetooth GATT Attribute Barometric Pressure Trend (UUID 0x2aa3)
  • BT GATT Basic Audio Announcement (UUID 0x1851)Bluetooth GATT Attribute Basic Audio Announcement (UUID 0x1851)
  • BT GATT Battery (UUID 0x180f)Bluetooth GATT Attribute Battery (UUID 0x180f)
  • BT GATT Battery Critical Status (UUID 0x2be9)Bluetooth GATT Attribute Battery Critical Status (UUID 0x2be9)
  • BT GATT Battery Energy Status (UUID 0x2bf0)Bluetooth GATT Attribute Battery Energy Status (UUID 0x2bf0)
  • BT GATT Battery Health Information (UUID 0x2beb)Bluetooth GATT Attribute Battery Health Information (UUID 0x2beb)
  • BT GATT Battery Health Status (UUID 0x2bea)Bluetooth GATT Attribute Battery Health Status (UUID 0x2bea)
  • BT GATT Battery Information (UUID 0x2bec)Bluetooth GATT Attribute Battery Information (UUID 0x2bec)
  • BT GATT Battery Level (UUID 0x2a19)Bluetooth GATT Attribute Battery Level (UUID 0x2a19)
  • BT GATT Battery Level State (UUID 0x2a1b)Bluetooth GATT Attribute Battery Level State (UUID 0x2a1b)
  • BT GATT Battery Level Status (UUID 0x2bed)Bluetooth GATT Attribute Battery Level Status (UUID 0x2bed)
  • BT GATT Battery Power State (UUID 0x2a1a)Bluetooth GATT Attribute Battery Power State (UUID 0x2a1a)
  • BT GATT Battery Time Status (UUID 0x2bee)Bluetooth GATT Attribute Battery Time Status (UUID 0x2bee)
  • BT GATT Bearer List Current Calls (UUID 0x2bb9)Bluetooth GATT Attribute Bearer List Current Calls (UUID 0x2bb9)
  • BT GATT Bearer Provider Name (UUID 0x2bb3)Bluetooth GATT Attribute Bearer Provider Name (UUID 0x2bb3)
  • BT GATT Bearer Signal Strength (UUID 0x2bb7)Bluetooth GATT Attribute Bearer Signal Strength (UUID 0x2bb7)
  • BT GATT Bearer Signal Strength Reporting Interval (UUID 0x2bb8)Bluetooth GATT Attribute Bearer Signal Strength Reporting Interval (UUID 0x2bb8)
  • BT GATT Bearer Technology (UUID 0x2bb5)Bluetooth GATT Attribute Bearer Technology (UUID 0x2bb5)
  • BT GATT Bearer UCI (UUID 0x2bb4)Bluetooth GATT Attribute Bearer UCI (UUID 0x2bb4)
  • BT GATT Bearer URI Schemes Supported List (UUID 0x2bb6)Bluetooth GATT Attribute Bearer URI Schemes Supported List (UUID 0x2bb6)
  • BT GATT BGR Features (UUID 0x2c04)Bluetooth GATT Attribute BGR Features (UUID 0x2c04)
  • BT GATT BGS Features (UUID 0x2c03)Bluetooth GATT Attribute BGS Features (UUID 0x2c03)
  • BT GATT Binary Sensor (UUID 0x183b)Bluetooth GATT Attribute Binary Sensor (UUID 0x183b)
  • BT GATT Blood Pressure (UUID 0x1810)Bluetooth GATT Attribute Blood Pressure (UUID 0x1810)
  • BT GATT Blood Pressure Feature (UUID 0x2a49)Bluetooth GATT Attribute Blood Pressure Feature (UUID 0x2a49)
  • BT GATT Blood Pressure Measurement (UUID 0x2a35)Bluetooth GATT Attribute Blood Pressure Measurement (UUID 0x2a35)
  • BT GATT Blood Pressure Record (UUID 0x2b36)Bluetooth GATT Attribute Blood Pressure Record (UUID 0x2b36)
  • BT GATT Bluetooth SIG Data (UUID 0x2b39)Bluetooth GATT Attribute Bluetooth SIG Data (UUID 0x2b39)
  • BT GATT Body Composition (UUID 0x181b)Bluetooth GATT Attribute Body Composition (UUID 0x181b)
  • BT GATT Body Composition Feature (UUID 0x2a9b)Bluetooth GATT Attribute Body Composition Feature (UUID 0x2a9b)
  • BT GATT Body Composition Measurement (UUID 0x2a9c)Bluetooth GATT Attribute Body Composition Measurement (UUID 0x2a9c)
  • BT GATT Body Sensor Location (UUID 0x2a38)Bluetooth GATT Attribute Body Sensor Location (UUID 0x2a38)
  • BT GATT Bond Management (UUID 0x181e)Bluetooth GATT Attribute Bond Management (UUID 0x181e)
  • BT GATT Bond Management Control Point (UUID 0x2aa4)Bluetooth GATT Attribute Bond Management Control Point (UUID 0x2aa4)
  • BT GATT Bond Management Feature (UUID 0x2aa5)Bluetooth GATT Attribute Bond Management Feature (UUID 0x2aa5)
  • BT GATT Boolean (UUID 0x2ae2)Bluetooth GATT Attribute Boolean (UUID 0x2ae2)
  • BT GATT Boot Keyboard Input Report (UUID 0x2a22)Bluetooth GATT Attribute Boot Keyboard Input Report (UUID 0x2a22)
  • BT GATT Boot Keyboard Output Report (UUID 0x2a32)Bluetooth GATT Attribute Boot Keyboard Output Report (UUID 0x2a32)
  • BT GATT Boot Mouse Input Report (UUID 0x2a33)Bluetooth GATT Attribute Boot Mouse Input Report (UUID 0x2a33)
  • BT GATT BR-EDR Handover Data (UUID 0x2b38)Bluetooth GATT Attribute BR-EDR Handover Data (UUID 0x2b38)
  • BT GATT Broadcast Audio Announcement (UUID 0x1852)Bluetooth GATT Attribute Broadcast Audio Announcement (UUID 0x1852)
  • BT GATT Broadcast Audio Scan (UUID 0x184f)Bluetooth GATT Attribute Broadcast Audio Scan (UUID 0x184f)
  • BT GATT Broadcast Audio Scan Control Point (UUID 0x2bc7)Bluetooth GATT Attribute Broadcast Audio Scan Control Point (UUID 0x2bc7)
  • BT GATT Broadcast Receive State (UUID 0x2bc8)Bluetooth GATT Attribute Broadcast Receive State (UUID 0x2bc8)
  • BT GATT BSS Control Point (UUID 0x2b2b)Bluetooth GATT Attribute BSS Control Point (UUID 0x2b2b)
  • BT GATT BSS Response (UUID 0x2b2c)Bluetooth GATT Attribute BSS Response (UUID 0x2b2c)
  • BT GATT Call Control Point (UUID 0x2bbe)Bluetooth GATT Attribute Call Control Point (UUID 0x2bbe)
  • BT GATT Call Control Point Optional Opcodes (UUID 0x2bbf)Bluetooth GATT Attribute Call Control Point Optional Opcodes (UUID 0x2bbf)
  • BT GATT Call Friendly Name (UUID 0x2bc2)Bluetooth GATT Attribute Call Friendly Name (UUID 0x2bc2)
  • BT GATT Call State (UUID 0x2bbd)Bluetooth GATT Attribute Call State (UUID 0x2bbd)
  • BT GATT Caloric Intake (UUID 0x2b50)Bluetooth GATT Attribute Caloric Intake (UUID 0x2b50)
  • BT GATT Carbon Monoxide Concentration (UUID 0x2bd0)Bluetooth GATT Attribute Carbon Monoxide Concentration (UUID 0x2bd0)
  • BT GATT CardioRespiratory Activity Instantaneous Data (UUID 0x2b3e)Bluetooth GATT Attribute CardioRespiratory Activity Instantaneous Data (UUID 0x2b3e)
  • BT GATT CardioRespiratory Activity Summary Data (UUID 0x2b3f)Bluetooth GATT Attribute CardioRespiratory Activity Summary Data (UUID 0x2b3f)
  • BT GATT Central Address Resolution (UUID 0x2aa6)Bluetooth GATT Attribute Central Address Resolution (UUID 0x2aa6)
  • BT GATT CGM Feature (UUID 0x2aa8)Bluetooth GATT Attribute CGM Feature (UUID 0x2aa8)
  • BT GATT CGM Measurement (UUID 0x2aa7)Bluetooth GATT Attribute CGM Measurement (UUID 0x2aa7)
  • BT GATT CGM Session Run Time (UUID 0x2aab)Bluetooth GATT Attribute CGM Session Run Time (UUID 0x2aab)
  • BT GATT CGM Session Start Time (UUID 0x2aaa)Bluetooth GATT Attribute CGM Session Start Time (UUID 0x2aaa)
  • BT GATT CGM Specific Ops Control Point (UUID 0x2aac)Bluetooth GATT Attribute CGM Specific Ops Control Point (UUID 0x2aac)
  • BT GATT CGM Status (UUID 0x2aa9)Bluetooth GATT Attribute CGM Status (UUID 0x2aa9)
  • BT GATT Characteristic (UUID 0x2803)Bluetooth GATT Attribute Characteristic (UUID 0x2803)
  • BT GATT Characteristic Aggregate Format (UUID 0x2905)Bluetooth GATT Attribute Characteristic Aggregate Format (UUID 0x2905)
  • BT GATT Characteristic Extended Properties (UUID 0x2900)Bluetooth GATT Attribute Characteristic Extended Properties (UUID 0x2900)
  • BT GATT Characteristic Presentation Format (UUID 0x2904)Bluetooth GATT Attribute Characteristic Presentation Format (UUID 0x2904)
  • BT GATT Characteristic User Description (UUID 0x2901)Bluetooth GATT Attribute Characteristic User Description (UUID 0x2901)
  • BT GATT Chromatic Distance from Planckian (UUID 0x2ae3)Bluetooth GATT Attribute Chromatic Distance from Planckian (UUID 0x2ae3)
  • BT GATT Chromaticity Coordinate (UUID 0x2b1c)Bluetooth GATT Attribute Chromaticity Coordinate (UUID 0x2b1c)
  • BT GATT Chromaticity Coordinates (UUID 0x2ae4)Bluetooth GATT Attribute Chromaticity Coordinates (UUID 0x2ae4)
  • BT GATT Chromaticity in CCT and Duv Values (UUID 0x2ae5)Bluetooth GATT Attribute Chromaticity in CCT and Duv Values (UUID 0x2ae5)
  • BT GATT Chromaticity Tolerance (UUID 0x2ae6)Bluetooth GATT Attribute Chromaticity Tolerance (UUID 0x2ae6)
  • BT GATT CIE 13.3-1995 Color Rendering Index (UUID 0x2ae7)Bluetooth GATT Attribute CIE 13.3-1995 Color Rendering Index (UUID 0x2ae7)
  • BT GATT Client Characteristic Configuration (UUID 0x2902)Bluetooth GATT Attribute Client Characteristic Configuration (UUID 0x2902)
  • BT GATT Client Supported Features (UUID 0x2b29)Bluetooth GATT Attribute Client Supported Features (UUID 0x2b29)
  • BT GATT CO₂ Concentration (UUID 0x2b8c)Bluetooth GATT Attribute CO₂ Concentration (UUID 0x2b8c)
  • BT GATT Coefficient (UUID 0x2ae8)Bluetooth GATT Attribute Coefficient (UUID 0x2ae8)
  • BT GATT Common Audio (UUID 0x1853)Bluetooth GATT Attribute Common Audio (UUID 0x1853)
  • BT GATT Complete BR-EDR Transport Block Data (UUID 0x290f)Bluetooth GATT Attribute Complete BR-EDR Transport Block Data (UUID 0x290f)
  • BT GATT Constant Tone Extension (UUID 0x184a)Bluetooth GATT Attribute Constant Tone Extension (UUID 0x184a)
  • BT GATT Constant Tone Extension Enable (UUID 0x2bad)Bluetooth GATT Attribute Constant Tone Extension Enable (UUID 0x2bad)
  • BT GATT Contact Status 8 (UUID 0x2c22)Bluetooth GATT Attribute Contact Status 8 (UUID 0x2c22)
  • BT GATT Content Control ID (UUID 0x2bba)Bluetooth GATT Attribute Content Control ID (UUID 0x2bba)
  • BT GATT Continuous Glucose Monitoring (UUID 0x181f)Bluetooth GATT Attribute Continuous Glucose Monitoring (UUID 0x181f)
  • BT GATT Cooking Sensor Info (UUID 0x2916)Bluetooth GATT Attribute Cooking Sensor Info (UUID 0x2916)
  • BT GATT Cooking Step Status (UUID 0x2c28)Bluetooth GATT Attribute Cooking Step Status (UUID 0x2c28)
  • BT GATT Cooking Temperature (UUID 0x2c2e)Bluetooth GATT Attribute Cooking Temperature (UUID 0x2c2e)
  • BT GATT Cooking Trigger Setting (UUID 0x2917)Bluetooth GATT Attribute Cooking Trigger Setting (UUID 0x2917)
  • BT GATT Cooking Zone Actual Cooking Conditions (UUID 0x2c2b)Bluetooth GATT Attribute Cooking Zone Actual Cooking Conditions (UUID 0x2c2b)
  • BT GATT Cooking Zone Capabilities (UUID 0x2c29)Bluetooth GATT Attribute Cooking Zone Capabilities (UUID 0x2c29)
  • BT GATT Cooking Zone Desired Cooking Conditions (UUID 0x2c2a)Bluetooth GATT Attribute Cooking Zone Desired Cooking Conditions (UUID 0x2c2a)
  • BT GATT Cooking Zone Perceived Power (UUID 0x2c2f)Bluetooth GATT Attribute Cooking Zone Perceived Power (UUID 0x2c2f)
  • BT GATT Cookware (UUID 0x185d)Bluetooth GATT Attribute Cookware (UUID 0x185d)
  • BT GATT Cookware Description (UUID 0x2c25)Bluetooth GATT Attribute Cookware Description (UUID 0x2c25)
  • BT GATT Cookware Sensor Aggregate (UUID 0x2c2d)Bluetooth GATT Attribute Cookware Sensor Aggregate (UUID 0x2c2d)
  • BT GATT Cookware Sensor Data (UUID 0x2c2c)Bluetooth GATT Attribute Cookware Sensor Data (UUID 0x2c2c)
  • BT GATT Coordinated Set Identification (UUID 0x1846)Bluetooth GATT Attribute Coordinated Set Identification (UUID 0x1846)
  • BT GATT Coordinated Set Name (UUID 0x2c1a)Bluetooth GATT Attribute Coordinated Set Name (UUID 0x2c1a)
  • BT GATT Coordinated Set Size (UUID 0x2b85)Bluetooth GATT Attribute Coordinated Set Size (UUID 0x2b85)
  • BT GATT Correlated Color Temperature (UUID 0x2ae9)Bluetooth GATT Attribute Correlated Color Temperature (UUID 0x2ae9)
  • BT GATT Cosine of the Angle (UUID 0x2b8d)Bluetooth GATT Attribute Cosine of the Angle (UUID 0x2b8d)
  • BT GATT Count 16 (UUID 0x2aea)Bluetooth GATT Attribute Count 16 (UUID 0x2aea)
  • BT GATT Count 24 (UUID 0x2aeb)Bluetooth GATT Attribute Count 24 (UUID 0x2aeb)
  • BT GATT Country Code (UUID 0x2aec)Bluetooth GATT Attribute Country Code (UUID 0x2aec)
  • BT GATT Cross Trainer Data (UUID 0x2ace)Bluetooth GATT Attribute Cross Trainer Data (UUID 0x2ace)
  • BT GATT CSC Feature (UUID 0x2a5c)Bluetooth GATT Attribute CSC Feature (UUID 0x2a5c)
  • BT GATT CSC Measurement (UUID 0x2a5b)Bluetooth GATT Attribute CSC Measurement (UUID 0x2a5b)
  • BT GATT Current Group Object ID (UUID 0x2ba0)Bluetooth GATT Attribute Current Group Object ID (UUID 0x2ba0)
  • BT GATT Current Time (UUID 0x1805)Bluetooth GATT Attribute Current Time (UUID 0x1805)
  • BT GATT Current Time (UUID 0x2a2b)Bluetooth GATT Attribute Current Time (UUID 0x2a2b)
  • BT GATT Current Track Object ID (UUID 0x2b9d)Bluetooth GATT Attribute Current Track Object ID (UUID 0x2b9d)
  • BT GATT Current Track Segments Object ID (UUID 0x2b9c)Bluetooth GATT Attribute Current Track Segments Object ID (UUID 0x2b9c)
  • BT GATT Cycling Power (UUID 0x1818)Bluetooth GATT Attribute Cycling Power (UUID 0x1818)
  • BT GATT Cycling Power Control Point (UUID 0x2a66)Bluetooth GATT Attribute Cycling Power Control Point (UUID 0x2a66)
  • BT GATT Cycling Power Feature (UUID 0x2a65)Bluetooth GATT Attribute Cycling Power Feature (UUID 0x2a65)
  • BT GATT Cycling Power Measurement (UUID 0x2a63)Bluetooth GATT Attribute Cycling Power Measurement (UUID 0x2a63)
  • BT GATT Cycling Power Vector (UUID 0x2a64)Bluetooth GATT Attribute Cycling Power Vector (UUID 0x2a64)
  • BT GATT Cycling Speed and Cadence (UUID 0x1816)Bluetooth GATT Attribute Cycling Speed and Cadence (UUID 0x1816)
  • BT GATT Database Change Increment (UUID 0x2a99)Bluetooth GATT Attribute Database Change Increment (UUID 0x2a99)
  • BT GATT Database Hash (UUID 0x2b2a)Bluetooth GATT Attribute Database Hash (UUID 0x2b2a)
  • BT GATT Date of Birth (UUID 0x2a85)Bluetooth GATT Attribute Date of Birth (UUID 0x2a85)
  • BT GATT Date of Threshold Assessment (UUID 0x2a86)Bluetooth GATT Attribute Date of Threshold Assessment (UUID 0x2a86)
  • BT GATT Date Time (UUID 0x2a08)Bluetooth GATT Attribute Date Time (UUID 0x2a08)
  • BT GATT Date UTC (UUID 0x2aed)Bluetooth GATT Attribute Date UTC (UUID 0x2aed)
  • BT GATT Day Date Time (UUID 0x2a0a)Bluetooth GATT Attribute Day Date Time (UUID 0x2a0a)
  • BT GATT Day of Week (UUID 0x2a09)Bluetooth GATT Attribute Day of Week (UUID 0x2a09)
  • BT GATT Descriptor Value Changed (UUID 0x2a7d)Bluetooth GATT Attribute Descriptor Value Changed (UUID 0x2a7d)
  • BT GATT Device Information (UUID 0x180a)Bluetooth GATT Attribute Device Information (UUID 0x180a)
  • BT GATT Device Name (UUID 0x2a00)Bluetooth GATT Attribute Device Name (UUID 0x2a00)
  • BT GATT Device Time (UUID 0x1847)Bluetooth GATT Attribute Device Time (UUID 0x1847)
  • BT GATT Device Time (UUID 0x2b90)Bluetooth GATT Attribute Device Time (UUID 0x2b90)
  • BT GATT Device Time Control Point (UUID 0x2b91)Bluetooth GATT Attribute Device Time Control Point (UUID 0x2b91)
  • BT GATT Device Time Feature (UUID 0x2b8e)Bluetooth GATT Attribute Device Time Feature (UUID 0x2b8e)
  • BT GATT Device Time Parameters (UUID 0x2b8f)Bluetooth GATT Attribute Device Time Parameters (UUID 0x2b8f)
  • BT GATT Device Wearing Position (UUID 0x2b4b)Bluetooth GATT Attribute Device Wearing Position (UUID 0x2b4b)
  • BT GATT Dew Point (UUID 0x2a7b)Bluetooth GATT Attribute Dew Point (UUID 0x2a7b)
  • BT GATT Digital (UUID 0x2a56)Bluetooth GATT Attribute Digital (UUID 0x2a56)
  • BT GATT Digital Output (UUID 0x2a57)Bluetooth GATT Attribute Digital Output (UUID 0x2a57)
  • BT GATT Directory Listing (UUID 0x2acb)Bluetooth GATT Attribute Directory Listing (UUID 0x2acb)
  • BT GATT Door/Window Status (UUID 0x2c20)Bluetooth GATT Attribute Door/Window Status (UUID 0x2c20)
  • BT GATT DST Offset (UUID 0x2a0d)Bluetooth GATT Attribute DST Offset (UUID 0x2a0d)
  • BT GATT Elapsed Time (UUID 0x183f)Bluetooth GATT Attribute Elapsed Time (UUID 0x183f)
  • BT GATT Elapsed Time (UUID 0x2bf2)Bluetooth GATT Attribute Elapsed Time (UUID 0x2bf2)
  • BT GATT Electric Current (UUID 0x2aee)Bluetooth GATT Attribute Electric Current (UUID 0x2aee)
  • BT GATT Electric Current Range (UUID 0x2aef)Bluetooth GATT Attribute Electric Current Range (UUID 0x2aef)
  • BT GATT Electric Current Specification (UUID 0x2af0)Bluetooth GATT Attribute Electric Current Specification (UUID 0x2af0)
  • BT GATT Electric Current Statistics (UUID 0x2af1)Bluetooth GATT Attribute Electric Current Statistics (UUID 0x2af1)
  • BT GATT Electronic Shelf Label (UUID 0x1857)Bluetooth GATT Attribute Electronic Shelf Label (UUID 0x1857)
  • BT GATT Elevation (UUID 0x2a6c)Bluetooth GATT Attribute Elevation (UUID 0x2a6c)
  • BT GATT Email Address (UUID 0x2a87)Bluetooth GATT Attribute Email Address (UUID 0x2a87)
  • BT GATT Emergency Configuration (UUID 0x183c)Bluetooth GATT Attribute Emergency Configuration (UUID 0x183c)
  • BT GATT Emergency ID (UUID 0x2b2d)Bluetooth GATT Attribute Emergency ID (UUID 0x2b2d)
  • BT GATT Emergency Text (UUID 0x2b2e)Bluetooth GATT Attribute Emergency Text (UUID 0x2b2e)
  • BT GATT Encrypted Data Key Material (UUID 0x2b88)Bluetooth GATT Attribute Encrypted Data Key Material (UUID 0x2b88)
  • BT GATT Energy (UUID 0x2af2)Bluetooth GATT Attribute Energy (UUID 0x2af2)
  • BT GATT Energy 32 (UUID 0x2ba8)Bluetooth GATT Attribute Energy 32 (UUID 0x2ba8)
  • BT GATT Energy in a Period of Day (UUID 0x2af3)Bluetooth GATT Attribute Energy in a Period of Day (UUID 0x2af3)
  • BT GATT Enhanced Blood Pressure Measurement (UUID 0x2b34)Bluetooth GATT Attribute Enhanced Blood Pressure Measurement (UUID 0x2b34)
  • BT GATT Enhanced Intermediate Cuff Pressure (UUID 0x2b35)Bluetooth GATT Attribute Enhanced Intermediate Cuff Pressure (UUID 0x2b35)
  • BT GATT Environmental Sensing (UUID 0x181a)Bluetooth GATT Attribute Environmental Sensing (UUID 0x181a)
  • BT GATT Environmental Sensing Configuration (UUID 0x290b)Bluetooth GATT Attribute Environmental Sensing Configuration (UUID 0x290b)
  • BT GATT Environmental Sensing Measurement (UUID 0x290c)Bluetooth GATT Attribute Environmental Sensing Measurement (UUID 0x290c)
  • BT GATT Environmental Sensing Trigger Setting (UUID 0x290d)Bluetooth GATT Attribute Environmental Sensing Trigger Setting (UUID 0x290d)
  • BT GATT ESL Address (UUID 0x2bf6)Bluetooth GATT Attribute ESL Address (UUID 0x2bf6)
  • BT GATT ESL Control Point (UUID 0x2bfe)Bluetooth GATT Attribute ESL Control Point (UUID 0x2bfe)
  • BT GATT ESL Current Absolute Time (UUID 0x2bf9)Bluetooth GATT Attribute ESL Current Absolute Time (UUID 0x2bf9)
  • BT GATT ESL Display Information (UUID 0x2bfa)Bluetooth GATT Attribute ESL Display Information (UUID 0x2bfa)
  • BT GATT ESL Image Information (UUID 0x2bfb)Bluetooth GATT Attribute ESL Image Information (UUID 0x2bfb)
  • BT GATT ESL LED Information (UUID 0x2bfd)Bluetooth GATT Attribute ESL LED Information (UUID 0x2bfd)
  • BT GATT ESL Response Key Material (UUID 0x2bf8)Bluetooth GATT Attribute ESL Response Key Material (UUID 0x2bf8)
  • BT GATT ESL Sensor Information (UUID 0x2bfc)Bluetooth GATT Attribute ESL Sensor Information (UUID 0x2bfc)
  • BT GATT Estimated Service Date (UUID 0x2bef)Bluetooth GATT Attribute Estimated Service Date (UUID 0x2bef)
  • BT GATT Event Statistics (UUID 0x2af4)Bluetooth GATT Attribute Event Statistics (UUID 0x2af4)
  • BT GATT Exact Time 100 (UUID 0x2a0b)Bluetooth GATT Attribute Exact Time 100 (UUID 0x2a0b)
  • BT GATT Exact Time 256 (UUID 0x2a0c)Bluetooth GATT Attribute Exact Time 256 (UUID 0x2a0c)
  • BT GATT External Report Reference (UUID 0x2907)Bluetooth GATT Attribute External Report Reference (UUID 0x2907)
  • BT GATT Fat Burn Heart Rate Lower Limit (UUID 0x2a88)Bluetooth GATT Attribute Fat Burn Heart Rate Lower Limit (UUID 0x2a88)
  • BT GATT Fat Burn Heart Rate Upper Limit (UUID 0x2a89)Bluetooth GATT Attribute Fat Burn Heart Rate Upper Limit (UUID 0x2a89)
  • BT GATT Firmware Revision String (UUID 0x2a26)Bluetooth GATT Attribute Firmware Revision String (UUID 0x2a26)
  • BT GATT First Name (UUID 0x2a8a)Bluetooth GATT Attribute First Name (UUID 0x2a8a)
  • BT GATT First Use Date (UUID 0x2c0e)Bluetooth GATT Attribute First Use Date (UUID 0x2c0e)
  • BT GATT Fitness Machine (UUID 0x1826)Bluetooth GATT Attribute Fitness Machine (UUID 0x1826)
  • BT GATT Fitness Machine Control Point (UUID 0x2ad9)Bluetooth GATT Attribute Fitness Machine Control Point (UUID 0x2ad9)
  • BT GATT Fitness Machine Feature (UUID 0x2acc)Bluetooth GATT Attribute Fitness Machine Feature (UUID 0x2acc)
  • BT GATT Fitness Machine Status (UUID 0x2ada)Bluetooth GATT Attribute Fitness Machine Status (UUID 0x2ada)
  • BT GATT Five Zone Heart Rate Limits (UUID 0x2a8b)Bluetooth GATT Attribute Five Zone Heart Rate Limits (UUID 0x2a8b)
  • BT GATT Fixed String 16 (UUID 0x2af5)Bluetooth GATT Attribute Fixed String 16 (UUID 0x2af5)
  • BT GATT Fixed String 24 (UUID 0x2af6)Bluetooth GATT Attribute Fixed String 24 (UUID 0x2af6)
  • BT GATT Fixed String 36 (UUID 0x2af7)Bluetooth GATT Attribute Fixed String 36 (UUID 0x2af7)
  • BT GATT Fixed String 64 (UUID 0x2bde)Bluetooth GATT Attribute Fixed String 64 (UUID 0x2bde)
  • BT GATT Fixed String 8 (UUID 0x2af8)Bluetooth GATT Attribute Fixed String 8 (UUID 0x2af8)
  • BT GATT Floor Number (UUID 0x2ab2)Bluetooth GATT Attribute Floor Number (UUID 0x2ab2)
  • BT GATT Force (UUID 0x2c07)Bluetooth GATT Attribute Force (UUID 0x2c07)
  • BT GATT Four Zone Heart Rate Limits (UUID 0x2b4c)Bluetooth GATT Attribute Four Zone Heart Rate Limits (UUID 0x2b4c)
  • BT GATT Gain Settings Attribute (UUID 0x2b78)Bluetooth GATT Attribute Gain Settings Attribute (UUID 0x2b78)
  • BT GATT Gaming Audio (UUID 0x1858)Bluetooth GATT Attribute Gaming Audio (UUID 0x1858)
  • BT GATT GAP (UUID 0x1800)Bluetooth GATT Attribute GAP (UUID 0x1800)
  • BT GATT GATT (UUID 0x1801)Bluetooth GATT Attribute GATT (UUID 0x1801)
  • BT GATT Gender (UUID 0x2a8c)Bluetooth GATT Attribute Gender (UUID 0x2a8c)
  • BT GATT General Activity Instantaneous Data (UUID 0x2b3c)Bluetooth GATT Attribute General Activity Instantaneous Data (UUID 0x2b3c)
  • BT GATT General Activity Summary Data (UUID 0x2b3d)Bluetooth GATT Attribute General Activity Summary Data (UUID 0x2b3d)
  • BT GATT Generic Health Sensor (UUID 0x1840)Bluetooth GATT Attribute Generic Health Sensor (UUID 0x1840)
  • BT GATT Generic Level (UUID 0x2af9)Bluetooth GATT Attribute Generic Level (UUID 0x2af9)
  • BT GATT Generic Media Control (UUID 0x1849)Bluetooth GATT Attribute Generic Media Control (UUID 0x1849)
  • BT GATT Generic Telephone Bearer (UUID 0x184c)Bluetooth GATT Attribute Generic Telephone Bearer (UUID 0x184c)
  • BT GATT Generic Voice Assistant (UUID 0x185f)Bluetooth GATT Attribute Generic Voice Assistant (UUID 0x185f)
  • BT GATT GHS Control Point (UUID 0x2bf4)Bluetooth GATT Attribute GHS Control Point (UUID 0x2bf4)
  • BT GATT Global Trade Item Number (UUID 0x2afa)Bluetooth GATT Attribute Global Trade Item Number (UUID 0x2afa)
  • BT GATT Glucose (UUID 0x1808)Bluetooth GATT Attribute Glucose (UUID 0x1808)
  • BT GATT Glucose Feature (UUID 0x2a51)Bluetooth GATT Attribute Glucose Feature (UUID 0x2a51)
  • BT GATT Glucose Measurement (UUID 0x2a18)Bluetooth GATT Attribute Glucose Measurement (UUID 0x2a18)
  • BT GATT Glucose Measurement Context (UUID 0x2a34)Bluetooth GATT Attribute Glucose Measurement Context (UUID 0x2a34)
  • BT GATT GMAP Role (UUID 0x2c00)Bluetooth GATT Attribute GMAP Role (UUID 0x2c00)
  • BT GATT Group Object Type (UUID 0x2bac)Bluetooth GATT Attribute Group Object Type (UUID 0x2bac)
  • BT GATT Gust Factor (UUID 0x2a74)Bluetooth GATT Attribute Gust Factor (UUID 0x2a74)
  • BT GATT Handedness (UUID 0x2b4a)Bluetooth GATT Attribute Handedness (UUID 0x2b4a)
  • BT GATT Hardware Revision String (UUID 0x2a27)Bluetooth GATT Attribute Hardware Revision String (UUID 0x2a27)
  • BT GATT Health Sensor Features (UUID 0x2bf3)Bluetooth GATT Attribute Health Sensor Features (UUID 0x2bf3)
  • BT GATT Health Thermometer (UUID 0x1809)Bluetooth GATT Attribute Health Thermometer (UUID 0x1809)
  • BT GATT Hearing Access (UUID 0x1854)Bluetooth GATT Attribute Hearing Access (UUID 0x1854)
  • BT GATT Hearing Aid Features (UUID 0x2bda)Bluetooth GATT Attribute Hearing Aid Features (UUID 0x2bda)
  • BT GATT Hearing Aid Preset Control Point (UUID 0x2bdb)Bluetooth GATT Attribute Hearing Aid Preset Control Point (UUID 0x2bdb)
  • BT GATT Heart Rate (UUID 0x180d)Bluetooth GATT Attribute Heart Rate (UUID 0x180d)
  • BT GATT Heart Rate Control Point (UUID 0x2a39)Bluetooth GATT Attribute Heart Rate Control Point (UUID 0x2a39)
  • BT GATT Heart Rate Max (UUID 0x2a8d)Bluetooth GATT Attribute Heart Rate Max (UUID 0x2a8d)
  • BT GATT Heart Rate Measurement (UUID 0x2a37)Bluetooth GATT Attribute Heart Rate Measurement (UUID 0x2a37)
  • BT GATT Heat Index (UUID 0x2a7a)Bluetooth GATT Attribute Heat Index (UUID 0x2a7a)
  • BT GATT Height (UUID 0x2a8e)Bluetooth GATT Attribute Height (UUID 0x2a8e)
  • BT GATT HID Control Point (UUID 0x2a4c)Bluetooth GATT Attribute HID Control Point (UUID 0x2a4c)
  • BT GATT HID Information (UUID 0x2a4a)Bluetooth GATT Attribute HID Information (UUID 0x2a4a)
  • BT GATT HID ISO (UUID 0x185c)Bluetooth GATT Attribute HID ISO (UUID 0x185c)
  • BT GATT HID ISO Properties (UUID 0x2c23)Bluetooth GATT Attribute HID ISO Properties (UUID 0x2c23)
  • BT GATT HID SCI Information (UUID 0x2c3a)Bluetooth GATT Attribute HID SCI Information (UUID 0x2c3a)
  • BT GATT HID SCI Mode (UUID 0x2c39)Bluetooth GATT Attribute HID SCI Mode (UUID 0x2c39)
  • BT GATT High Intensity Exercise Threshold (UUID 0x2b4d)Bluetooth GATT Attribute High Intensity Exercise Threshold (UUID 0x2b4d)
  • BT GATT High Resolution Height (UUID 0x2b47)Bluetooth GATT Attribute High Resolution Height (UUID 0x2b47)
  • BT GATT High Temperature (UUID 0x2bdf)Bluetooth GATT Attribute High Temperature (UUID 0x2bdf)
  • BT GATT High Voltage (UUID 0x2be0)Bluetooth GATT Attribute High Voltage (UUID 0x2be0)
  • BT GATT Hip Circumference (UUID 0x2a8f)Bluetooth GATT Attribute Hip Circumference (UUID 0x2a8f)
  • BT GATT HTTP Control Point (UUID 0x2aba)Bluetooth GATT Attribute HTTP Control Point (UUID 0x2aba)
  • BT GATT HTTP Entity Body (UUID 0x2ab9)Bluetooth GATT Attribute HTTP Entity Body (UUID 0x2ab9)
  • BT GATT HTTP Headers (UUID 0x2ab7)Bluetooth GATT Attribute HTTP Headers (UUID 0x2ab7)
  • BT GATT HTTP Proxy (UUID 0x1823)Bluetooth GATT Attribute HTTP Proxy (UUID 0x1823)
  • BT GATT HTTP Status Code (UUID 0x2ab8)Bluetooth GATT Attribute HTTP Status Code (UUID 0x2ab8)
  • BT GATT HTTPS Security (UUID 0x2abb)Bluetooth GATT Attribute HTTPS Security (UUID 0x2abb)
  • BT GATT Human Interface Device (UUID 0x1812)Bluetooth GATT Attribute Human Interface Device (UUID 0x1812)
  • BT GATT Humidity (UUID 0x2a6f)Bluetooth GATT Attribute Humidity (UUID 0x2a6f)
  • BT GATT Humidity 8 (UUID 0x2c1b)Bluetooth GATT Attribute Humidity 8 (UUID 0x2c1b)
  • BT GATT IDD Annunciation Status (UUID 0x2b22)Bluetooth GATT Attribute IDD Annunciation Status (UUID 0x2b22)
  • BT GATT IDD Command Control Point (UUID 0x2b25)Bluetooth GATT Attribute IDD Command Control Point (UUID 0x2b25)
  • BT GATT IDD Command Data (UUID 0x2b26)Bluetooth GATT Attribute IDD Command Data (UUID 0x2b26)
  • BT GATT IDD Features (UUID 0x2b23)Bluetooth GATT Attribute IDD Features (UUID 0x2b23)
  • BT GATT IDD History Data (UUID 0x2b28)Bluetooth GATT Attribute IDD History Data (UUID 0x2b28)
  • BT GATT IDD Record Access Control Point (UUID 0x2b27)Bluetooth GATT Attribute IDD Record Access Control Point (UUID 0x2b27)
  • BT GATT IDD Status (UUID 0x2b21)Bluetooth GATT Attribute IDD Status (UUID 0x2b21)
  • BT GATT IDD Status Changed (UUID 0x2b20)Bluetooth GATT Attribute IDD Status Changed (UUID 0x2b20)
  • BT GATT IDD Status Reader Control Point (UUID 0x2b24)Bluetooth GATT Attribute IDD Status Reader Control Point (UUID 0x2b24)
  • BT GATT IEEE 11073-20601 Regulatory Certification Data List (UUID 0x2a2a)Bluetooth GATT Attribute IEEE 11073-20601 Regulatory Certification Data List (UUID 0x2a2a)
  • BT GATT Illuminance (UUID 0x2afb)Bluetooth GATT Attribute Illuminance (UUID 0x2afb)
  • BT GATT Illuminance 16 (UUID 0x2c1c)Bluetooth GATT Attribute Illuminance 16 (UUID 0x2c1c)
  • BT GATT IMD Control (UUID 0x2c12)Bluetooth GATT Attribute IMD Control (UUID 0x2c12)
  • BT GATT IMD Historical Data (UUID 0x2c13)Bluetooth GATT Attribute IMD Historical Data (UUID 0x2c13)
  • BT GATT IMD Status (UUID 0x2c0c)Bluetooth GATT Attribute IMD Status (UUID 0x2c0c)
  • BT GATT IMD Trigger Setting (UUID 0x2915)Bluetooth GATT Attribute IMD Trigger Setting (UUID 0x2915)
  • BT GATT IMDS Descriptor Value Changed (UUID 0x2c0d)Bluetooth GATT Attribute IMDS Descriptor Value Changed (UUID 0x2c0d)
  • BT GATT Immediate Alert (UUID 0x1802)Bluetooth GATT Attribute Immediate Alert (UUID 0x1802)
  • BT GATT Include (UUID 0x2802)Bluetooth GATT Attribute Include (UUID 0x2802)
  • BT GATT Incoming Call (UUID 0x2bc1)Bluetooth GATT Attribute Incoming Call (UUID 0x2bc1)
  • BT GATT Incoming Call Target Bearer URI (UUID 0x2bbc)Bluetooth GATT Attribute Incoming Call Target Bearer URI (UUID 0x2bbc)
  • BT GATT Indoor Bike Data (UUID 0x2ad2)Bluetooth GATT Attribute Indoor Bike Data (UUID 0x2ad2)
  • BT GATT Indoor Positioning (UUID 0x1821)Bluetooth GATT Attribute Indoor Positioning (UUID 0x1821)
  • BT GATT Indoor Positioning Configuration (UUID 0x2aad)Bluetooth GATT Attribute Indoor Positioning Configuration (UUID 0x2aad)
  • BT GATT Industrial Measurement Device (UUID 0x185a)Bluetooth GATT Attribute Industrial Measurement Device (UUID 0x185a)
  • BT GATT Installed Location (UUID 0x2c34)Bluetooth GATT Attribute Installed Location (UUID 0x2c34)
  • BT GATT Insulin Delivery (UUID 0x183a)Bluetooth GATT Attribute Insulin Delivery (UUID 0x183a)
  • BT GATT Intermediate Cuff Pressure (UUID 0x2a36)Bluetooth GATT Attribute Intermediate Cuff Pressure (UUID 0x2a36)
  • BT GATT Intermediate Temperature (UUID 0x2a1e)Bluetooth GATT Attribute Intermediate Temperature (UUID 0x2a1e)
  • BT GATT Internet Protocol Support (UUID 0x1820)Bluetooth GATT Attribute Internet Protocol Support (UUID 0x1820)
  • BT GATT Irradiance (UUID 0x2a77)Bluetooth GATT Attribute Irradiance (UUID 0x2a77)
  • BT GATT Kitchen Appliance Airflow (UUID 0x2c30)Bluetooth GATT Attribute Kitchen Appliance Airflow (UUID 0x2c30)
  • BT GATT Language (UUID 0x2aa2)Bluetooth GATT Attribute Language (UUID 0x2aa2)
  • BT GATT Last Name (UUID 0x2a90)Bluetooth GATT Attribute Last Name (UUID 0x2a90)
  • BT GATT Latitude (UUID 0x2aae)Bluetooth GATT Attribute Latitude (UUID 0x2aae)
  • BT GATT LE GATT Security Levels (UUID 0x2bf5)Bluetooth GATT Attribute LE GATT Security Levels (UUID 0x2bf5)
  • BT GATT LE HID Operation Mode (UUID 0x2c24)Bluetooth GATT Attribute LE HID Operation Mode (UUID 0x2c24)
  • BT GATT Length (UUID 0x2c0a)Bluetooth GATT Attribute Length (UUID 0x2c0a)
  • BT GATT Life Cycle Data (UUID 0x2c0f)Bluetooth GATT Attribute Life Cycle Data (UUID 0x2c0f)
  • BT GATT Light Distribution (UUID 0x2be1)Bluetooth GATT Attribute Light Distribution (UUID 0x2be1)
  • BT GATT Light Output (UUID 0x2be2)Bluetooth GATT Attribute Light Output (UUID 0x2be2)
  • BT GATT Light Source Type (UUID 0x2be3)Bluetooth GATT Attribute Light Source Type (UUID 0x2be3)
  • BT GATT Linear Position (UUID 0x2c08)Bluetooth GATT Attribute Linear Position (UUID 0x2c08)
  • BT GATT Link Loss (UUID 0x1803)Bluetooth GATT Attribute Link Loss (UUID 0x1803)
  • BT GATT Live Health Observations (UUID 0x2b8b)Bluetooth GATT Attribute Live Health Observations (UUID 0x2b8b)
  • BT GATT LN Control Point (UUID 0x2a6b)Bluetooth GATT Attribute LN Control Point (UUID 0x2a6b)
  • BT GATT LN Feature (UUID 0x2a6a)Bluetooth GATT Attribute LN Feature (UUID 0x2a6a)
  • BT GATT Local East Coordinate (UUID 0x2ab1)Bluetooth GATT Attribute Local East Coordinate (UUID 0x2ab1)
  • BT GATT Local North Coordinate (UUID 0x2ab0)Bluetooth GATT Attribute Local North Coordinate (UUID 0x2ab0)
  • BT GATT Local Time Information (UUID 0x2a0f)Bluetooth GATT Attribute Local Time Information (UUID 0x2a0f)
  • BT GATT Location and Navigation (UUID 0x1819)Bluetooth GATT Attribute Location and Navigation (UUID 0x1819)
  • BT GATT Location and Speed (UUID 0x2a67)Bluetooth GATT Attribute Location and Speed (UUID 0x2a67)
  • BT GATT Location Name (UUID 0x2ab5)Bluetooth GATT Attribute Location Name (UUID 0x2ab5)
  • BT GATT Longitude (UUID 0x2aaf)Bluetooth GATT Attribute Longitude (UUID 0x2aaf)
  • BT GATT Luminous Efficacy (UUID 0x2afc)Bluetooth GATT Attribute Luminous Efficacy (UUID 0x2afc)
  • BT GATT Luminous Energy (UUID 0x2afd)Bluetooth GATT Attribute Luminous Energy (UUID 0x2afd)
  • BT GATT Luminous Exposure (UUID 0x2afe)Bluetooth GATT Attribute Luminous Exposure (UUID 0x2afe)
  • BT GATT Luminous Flux (UUID 0x2aff)Bluetooth GATT Attribute Luminous Flux (UUID 0x2aff)
  • BT GATT Luminous Flux Range (UUID 0x2b00)Bluetooth GATT Attribute Luminous Flux Range (UUID 0x2b00)
  • BT GATT Luminous Intensity (UUID 0x2b01)Bluetooth GATT Attribute Luminous Intensity (UUID 0x2b01)
  • BT GATT Magnetic Declination (UUID 0x2a2c)Bluetooth GATT Attribute Magnetic Declination (UUID 0x2a2c)
  • BT GATT Magnetic Flux Density - 2D (UUID 0x2aa0)Bluetooth GATT Attribute Magnetic Flux Density - 2D (UUID 0x2aa0)
  • BT GATT Magnetic Flux Density - 3D (UUID 0x2aa1)Bluetooth GATT Attribute Magnetic Flux Density - 3D (UUID 0x2aa1)
  • BT GATT Manufacturer Limits (UUID 0x2913)Bluetooth GATT Attribute Manufacturer Limits (UUID 0x2913)
  • BT GATT Manufacturer Name String (UUID 0x2a29)Bluetooth GATT Attribute Manufacturer Name String (UUID 0x2a29)
  • BT GATT Mass Flow (UUID 0x2b02)Bluetooth GATT Attribute Mass Flow (UUID 0x2b02)
  • BT GATT Maximum Recommended Heart Rate (UUID 0x2a91)Bluetooth GATT Attribute Maximum Recommended Heart Rate (UUID 0x2a91)
  • BT GATT Measurement Description (UUID 0x2912)Bluetooth GATT Attribute Measurement Description (UUID 0x2912)
  • BT GATT Measurement Interval (UUID 0x2a21)Bluetooth GATT Attribute Measurement Interval (UUID 0x2a21)
  • BT GATT Media Control (UUID 0x1848)Bluetooth GATT Attribute Media Control (UUID 0x1848)
  • BT GATT Media Control Point (UUID 0x2ba4)Bluetooth GATT Attribute Media Control Point (UUID 0x2ba4)
  • BT GATT Media Control Point Opcodes Supported (UUID 0x2ba5)Bluetooth GATT Attribute Media Control Point Opcodes Supported (UUID 0x2ba5)
  • BT GATT Media Player Icon Object ID (UUID 0x2b94)Bluetooth GATT Attribute Media Player Icon Object ID (UUID 0x2b94)
  • BT GATT Media Player Icon Object Type (UUID 0x2ba9)Bluetooth GATT Attribute Media Player Icon Object Type (UUID 0x2ba9)
  • BT GATT Media Player Icon URL (UUID 0x2b95)Bluetooth GATT Attribute Media Player Icon URL (UUID 0x2b95)
  • BT GATT Media Player Name (UUID 0x2b93)Bluetooth GATT Attribute Media Player Name (UUID 0x2b93)
  • BT GATT Media State (UUID 0x2ba3)Bluetooth GATT Attribute Media State (UUID 0x2ba3)
  • BT GATT Mesh Provisioning (UUID 0x1827)Bluetooth GATT Attribute Mesh Provisioning (UUID 0x1827)
  • BT GATT Mesh Provisioning Data In (UUID 0x2adb)Bluetooth GATT Attribute Mesh Provisioning Data In (UUID 0x2adb)
  • BT GATT Mesh Provisioning Data Out (UUID 0x2adc)Bluetooth GATT Attribute Mesh Provisioning Data Out (UUID 0x2adc)
  • BT GATT Mesh Proxy (UUID 0x1828)Bluetooth GATT Attribute Mesh Proxy (UUID 0x1828)
  • BT GATT Mesh Proxy Data In (UUID 0x2add)Bluetooth GATT Attribute Mesh Proxy Data In (UUID 0x2add)
  • BT GATT Mesh Proxy Data Out (UUID 0x2ade)Bluetooth GATT Attribute Mesh Proxy Data Out (UUID 0x2ade)
  • BT GATT Mesh Proxy Solicitation (UUID 0x1859)Bluetooth GATT Attribute Mesh Proxy Solicitation (UUID 0x1859)
  • BT GATT Methane Concentration (UUID 0x2bd1)Bluetooth GATT Attribute Methane Concentration (UUID 0x2bd1)
  • BT GATT Microphone Control (UUID 0x184d)Bluetooth GATT Attribute Microphone Control (UUID 0x184d)
  • BT GATT Middle Name (UUID 0x2b48)Bluetooth GATT Attribute Middle Name (UUID 0x2b48)
  • BT GATT Model Number String (UUID 0x2a24)Bluetooth GATT Attribute Model Number String (UUID 0x2a24)
  • BT GATT Mute (UUID 0x2bc3)Bluetooth GATT Attribute Mute (UUID 0x2bc3)
  • BT GATT Navigation (UUID 0x2a68)Bluetooth GATT Attribute Navigation (UUID 0x2a68)
  • BT GATT Network Availability (UUID 0x2a3e)Bluetooth GATT Attribute Network Availability (UUID 0x2a3e)
  • BT GATT New Alert (UUID 0x2a46)Bluetooth GATT Attribute New Alert (UUID 0x2a46)
  • BT GATT Next DST Change (UUID 0x1807)Bluetooth GATT Attribute Next DST Change (UUID 0x1807)
  • BT GATT Next Track Object ID (UUID 0x2b9e)Bluetooth GATT Attribute Next Track Object ID (UUID 0x2b9e)
  • BT GATT Nitrogen Dioxide Concentration (UUID 0x2bd2)Bluetooth GATT Attribute Nitrogen Dioxide Concentration (UUID 0x2bd2)
  • BT GATT Noise (UUID 0x2be4)Bluetooth GATT Attribute Noise (UUID 0x2be4)
  • BT GATT Non-Methane Volatile Organic Compounds Concentration (UUID 0x2bd3)Bluetooth GATT Attribute Non-Methane Volatile Organic Compounds Concentration (UUID 0x2bd3)
  • BT GATT Number of Digitals (UUID 0x2909)Bluetooth GATT Attribute Number of Digitals (UUID 0x2909)
  • BT GATT Object Action Control Point (UUID 0x2ac5)Bluetooth GATT Attribute Object Action Control Point (UUID 0x2ac5)
  • BT GATT Object Changed (UUID 0x2ac8)Bluetooth GATT Attribute Object Changed (UUID 0x2ac8)
  • BT GATT Object First-Created (UUID 0x2ac1)Bluetooth GATT Attribute Object First-Created (UUID 0x2ac1)
  • BT GATT Object ID (UUID 0x2ac3)Bluetooth GATT Attribute Object ID (UUID 0x2ac3)
  • BT GATT Object Last-Modified (UUID 0x2ac2)Bluetooth GATT Attribute Object Last-Modified (UUID 0x2ac2)
  • BT GATT Object List Control Point (UUID 0x2ac6)Bluetooth GATT Attribute Object List Control Point (UUID 0x2ac6)
  • BT GATT Object List Filter (UUID 0x2ac7)Bluetooth GATT Attribute Object List Filter (UUID 0x2ac7)
  • BT GATT Object Name (UUID 0x2abe)Bluetooth GATT Attribute Object Name (UUID 0x2abe)
  • BT GATT Object Properties (UUID 0x2ac4)Bluetooth GATT Attribute Object Properties (UUID 0x2ac4)
  • BT GATT Object Size (UUID 0x2ac0)Bluetooth GATT Attribute Object Size (UUID 0x2ac0)
  • BT GATT Object Transfer (UUID 0x1825)Bluetooth GATT Attribute Object Transfer (UUID 0x1825)
  • BT GATT Object Type (UUID 0x2abf)Bluetooth GATT Attribute Object Type (UUID 0x2abf)
  • BT GATT Observation Schedule (UUID 0x2910)Bluetooth GATT Attribute Observation Schedule (UUID 0x2910)
  • BT GATT Observation Schedule Changed (UUID 0x2bf1)Bluetooth GATT Attribute Observation Schedule Changed (UUID 0x2bf1)
  • BT GATT On-demand Ranging Data (UUID 0x2c16)Bluetooth GATT Attribute On-demand Ranging Data (UUID 0x2c16)
  • BT GATT OTS Feature (UUID 0x2abd)Bluetooth GATT Attribute OTS Feature (UUID 0x2abd)
  • BT GATT Ozone Concentration (UUID 0x2bd4)Bluetooth GATT Attribute Ozone Concentration (UUID 0x2bd4)
  • BT GATT Parent Group Object ID (UUID 0x2b9f)Bluetooth GATT Attribute Parent Group Object ID (UUID 0x2b9f)
  • BT GATT Particulate Matter - PM1 Concentration (UUID 0x2bd5)Bluetooth GATT Attribute Particulate Matter - PM1 Concentration (UUID 0x2bd5)
  • BT GATT Particulate Matter - PM10 Concentration (UUID 0x2bd7)Bluetooth GATT Attribute Particulate Matter - PM10 Concentration (UUID 0x2bd7)
  • BT GATT Particulate Matter - PM2.5 Concentration (UUID 0x2bd6)Bluetooth GATT Attribute Particulate Matter - PM2.5 Concentration (UUID 0x2bd6)
  • BT GATT Perceived Lightness (UUID 0x2b03)Bluetooth GATT Attribute Perceived Lightness (UUID 0x2b03)
  • BT GATT Percentage 8 (UUID 0x2b04)Bluetooth GATT Attribute Percentage 8 (UUID 0x2b04)
  • BT GATT Percentage 8 Steps (UUID 0x2c05)Bluetooth GATT Attribute Percentage 8 Steps (UUID 0x2c05)
  • BT GATT Peripheral Preferred Connection Parameters (UUID 0x2a04)Bluetooth GATT Attribute Peripheral Preferred Connection Parameters (UUID 0x2a04)
  • BT GATT Peripheral Privacy Flag (UUID 0x2a02)Bluetooth GATT Attribute Peripheral Privacy Flag (UUID 0x2a02)
  • BT GATT Phone Alert Status (UUID 0x180e)Bluetooth GATT Attribute Phone Alert Status (UUID 0x180e)
  • BT GATT Physical Activity Current Session (UUID 0x2b44)Bluetooth GATT Attribute Physical Activity Current Session (UUID 0x2b44)
  • BT GATT Physical Activity Monitor (UUID 0x183e)Bluetooth GATT Attribute Physical Activity Monitor (UUID 0x183e)
  • BT GATT Physical Activity Monitor Control Point (UUID 0x2b43)Bluetooth GATT Attribute Physical Activity Monitor Control Point (UUID 0x2b43)
  • BT GATT Physical Activity Monitor Features (UUID 0x2b3b)Bluetooth GATT Attribute Physical Activity Monitor Features (UUID 0x2b3b)
  • BT GATT Physical Activity Session Descriptor (UUID 0x2b45)Bluetooth GATT Attribute Physical Activity Session Descriptor (UUID 0x2b45)
  • BT GATT Playback Speed (UUID 0x2b9a)Bluetooth GATT Attribute Playback Speed (UUID 0x2b9a)
  • BT GATT Playing Order (UUID 0x2ba1)Bluetooth GATT Attribute Playing Order (UUID 0x2ba1)
  • BT GATT Playing Orders Supported (UUID 0x2ba2)Bluetooth GATT Attribute Playing Orders Supported (UUID 0x2ba2)
  • BT GATT PLX Continuous Measurement (UUID 0x2a5f)Bluetooth GATT Attribute PLX Continuous Measurement (UUID 0x2a5f)
  • BT GATT PLX Features (UUID 0x2a60)Bluetooth GATT Attribute PLX Features (UUID 0x2a60)
  • BT GATT PLX Spot-Check Measurement (UUID 0x2a5e)Bluetooth GATT Attribute PLX Spot-Check Measurement (UUID 0x2a5e)
  • BT GATT PnP ID (UUID 0x2a50)Bluetooth GATT Attribute PnP ID (UUID 0x2a50)
  • BT GATT Pollen Concentration (UUID 0x2a75)Bluetooth GATT Attribute Pollen Concentration (UUID 0x2a75)
  • BT GATT Position 2D (UUID 0x2a2f)Bluetooth GATT Attribute Position 2D (UUID 0x2a2f)
  • BT GATT Position 3D (UUID 0x2a30)Bluetooth GATT Attribute Position 3D (UUID 0x2a30)
  • BT GATT Position Quality (UUID 0x2a69)Bluetooth GATT Attribute Position Quality (UUID 0x2a69)
  • BT GATT Power (UUID 0x2b05)Bluetooth GATT Attribute Power (UUID 0x2b05)
  • BT GATT Power Specification (UUID 0x2b06)Bluetooth GATT Attribute Power Specification (UUID 0x2b06)
  • BT GATT Precise Acceleration - 3D (UUID 0x2c1e)Bluetooth GATT Attribute Precise Acceleration - 3D (UUID 0x2c1e)
  • BT GATT Preferred Units (UUID 0x2b46)Bluetooth GATT Attribute Preferred Units (UUID 0x2b46)
  • BT GATT Pressure (UUID 0x2a6d)Bluetooth GATT Attribute Pressure (UUID 0x2a6d)
  • BT GATT Primary Service (UUID 0x2800)Bluetooth GATT Attribute Primary Service (UUID 0x2800)
  • BT GATT Process Tolerances (UUID 0x2914)Bluetooth GATT Attribute Process Tolerances (UUID 0x2914)
  • BT GATT Protocol Mode (UUID 0x2a4e)Bluetooth GATT Attribute Protocol Mode (UUID 0x2a4e)
  • BT GATT Public Broadcast Announcement (UUID 0x1856)Bluetooth GATT Attribute Public Broadcast Announcement (UUID 0x1856)
  • BT GATT Published Audio Capabilities (UUID 0x1850)Bluetooth GATT Attribute Published Audio Capabilities (UUID 0x1850)
  • BT GATT Pulse Oximeter (UUID 0x1822)Bluetooth GATT Attribute Pulse Oximeter (UUID 0x1822)
  • BT GATT Pulse Oximetry Control Point (UUID 0x2a62)Bluetooth GATT Attribute Pulse Oximetry Control Point (UUID 0x2a62)
  • BT GATT Pushbutton Status 8 (UUID 0x2c21)Bluetooth GATT Attribute Pushbutton Status 8 (UUID 0x2c21)
  • BT GATT Rainfall (UUID 0x2a78)Bluetooth GATT Attribute Rainfall (UUID 0x2a78)
  • BT GATT Ranging (UUID 0x185b)Bluetooth GATT Attribute Ranging (UUID 0x185b)
  • BT GATT Ranging Data Overwritten (UUID 0x2c19)Bluetooth GATT Attribute Ranging Data Overwritten (UUID 0x2c19)
  • BT GATT Ranging Data Ready (UUID 0x2c18)Bluetooth GATT Attribute Ranging Data Ready (UUID 0x2c18)
  • BT GATT RAS Control Point (UUID 0x2c17)Bluetooth GATT Attribute RAS Control Point (UUID 0x2c17)
  • BT GATT RAS Features (UUID 0x2c14)Bluetooth GATT Attribute RAS Features (UUID 0x2c14)
  • BT GATT RC Feature (UUID 0x2b1d)Bluetooth GATT Attribute RC Feature (UUID 0x2b1d)
  • BT GATT RC Settings (UUID 0x2b1e)Bluetooth GATT Attribute RC Settings (UUID 0x2b1e)
  • BT GATT Real-time Ranging Data (UUID 0x2c15)Bluetooth GATT Attribute Real-time Ranging Data (UUID 0x2c15)
  • BT GATT Recipe Control (UUID 0x2c26)Bluetooth GATT Attribute Recipe Control (UUID 0x2c26)
  • BT GATT Recipe Parameters (UUID 0x2c27)Bluetooth GATT Attribute Recipe Parameters (UUID 0x2c27)
  • BT GATT Reconnection Address (UUID 0x2a03)Bluetooth GATT Attribute Reconnection Address (UUID 0x2a03)
  • BT GATT Reconnection Configuration (UUID 0x1829)Bluetooth GATT Attribute Reconnection Configuration (UUID 0x1829)
  • BT GATT Reconnection Configuration Control Point (UUID 0x2b1f)Bluetooth GATT Attribute Reconnection Configuration Control Point (UUID 0x2b1f)
  • BT GATT Record Access Control Point (UUID 0x2a52)Bluetooth GATT Attribute Record Access Control Point (UUID 0x2a52)
  • BT GATT Reference Time Information (UUID 0x2a14)Bluetooth GATT Attribute Reference Time Information (UUID 0x2a14)
  • BT GATT Reference Time Update (UUID 0x1806)Bluetooth GATT Attribute Reference Time Update (UUID 0x1806)
  • BT GATT Registered User (UUID 0x2b37)Bluetooth GATT Attribute Registered User (UUID 0x2b37)
  • BT GATT Relative Runtime in a Correlated Color Temperature Range (UUID 0x2be5)Bluetooth GATT Attribute Relative Runtime in a Correlated Color Temperature Range (UUID 0x2be5)
  • BT GATT Relative Runtime in a Current Range (UUID 0x2b07)Bluetooth GATT Attribute Relative Runtime in a Current Range (UUID 0x2b07)
  • BT GATT Relative Runtime in a Generic Level Range (UUID 0x2b08)Bluetooth GATT Attribute Relative Runtime in a Generic Level Range (UUID 0x2b08)
  • BT GATT Relative Value in a Period of Day (UUID 0x2b0b)Bluetooth GATT Attribute Relative Value in a Period of Day (UUID 0x2b0b)
  • BT GATT Relative Value in a Temperature Range (UUID 0x2b0c)Bluetooth GATT Attribute Relative Value in a Temperature Range (UUID 0x2b0c)
  • BT GATT Relative Value in a Voltage Range (UUID 0x2b09)Bluetooth GATT Attribute Relative Value in a Voltage Range (UUID 0x2b09)
  • BT GATT Relative Value in an Illuminance Range (UUID 0x2b0a)Bluetooth GATT Attribute Relative Value in an Illuminance Range (UUID 0x2b0a)
  • BT GATT Removable (UUID 0x2a3a)Bluetooth GATT Attribute Removable (UUID 0x2a3a)
  • BT GATT Report (UUID 0x2a4d)Bluetooth GATT Attribute Report (UUID 0x2a4d)
  • BT GATT Report Map (UUID 0x2a4b)Bluetooth GATT Attribute Report Map (UUID 0x2a4b)
  • BT GATT Report Reference (UUID 0x2908)Bluetooth GATT Attribute Report Reference (UUID 0x2908)
  • BT GATT Resolvable Private Address Only (UUID 0x2ac9)Bluetooth GATT Attribute Resolvable Private Address Only (UUID 0x2ac9)
  • BT GATT Resting Heart Rate (UUID 0x2a92)Bluetooth GATT Attribute Resting Heart Rate (UUID 0x2a92)
  • BT GATT Ringer Control Point (UUID 0x2a40)Bluetooth GATT Attribute Ringer Control Point (UUID 0x2a40)
  • BT GATT Ringer Setting (UUID 0x2a41)Bluetooth GATT Attribute Ringer Setting (UUID 0x2a41)
  • BT GATT Rotational Speed (UUID 0x2c09)Bluetooth GATT Attribute Rotational Speed (UUID 0x2c09)
  • BT GATT Rower Data (UUID 0x2ad1)Bluetooth GATT Attribute Rower Data (UUID 0x2ad1)
  • BT GATT RSC Feature (UUID 0x2a54)Bluetooth GATT Attribute RSC Feature (UUID 0x2a54)
  • BT GATT RSC Measurement (UUID 0x2a53)Bluetooth GATT Attribute RSC Measurement (UUID 0x2a53)
  • BT GATT Running Speed and Cadence (UUID 0x1814)Bluetooth GATT Attribute Running Speed and Cadence (UUID 0x1814)
  • BT GATT SC Control Point (UUID 0x2a55)Bluetooth GATT Attribute SC Control Point (UUID 0x2a55)
  • BT GATT Scan Interval Window (UUID 0x2a4f)Bluetooth GATT Attribute Scan Interval Window (UUID 0x2a4f)
  • BT GATT Scan Parameters (UUID 0x1813)Bluetooth GATT Attribute Scan Parameters (UUID 0x1813)
  • BT GATT Scan Refresh (UUID 0x2a31)Bluetooth GATT Attribute Scan Refresh (UUID 0x2a31)
  • BT GATT Scientific Temperature Celsius (UUID 0x2a3c)Bluetooth GATT Attribute Scientific Temperature Celsius (UUID 0x2a3c)
  • BT GATT Search Control Point (UUID 0x2ba7)Bluetooth GATT Attribute Search Control Point (UUID 0x2ba7)
  • BT GATT Search Results Object ID (UUID 0x2ba6)Bluetooth GATT Attribute Search Results Object ID (UUID 0x2ba6)
  • BT GATT Secondary Service (UUID 0x2801)Bluetooth GATT Attribute Secondary Service (UUID 0x2801)
  • BT GATT Secondary Time Zone (UUID 0x2a10)Bluetooth GATT Attribute Secondary Time Zone (UUID 0x2a10)
  • BT GATT Sedentary Interval Notification (UUID 0x2b4f)Bluetooth GATT Attribute Sedentary Interval Notification (UUID 0x2b4f)
  • BT GATT Seeking Speed (UUID 0x2b9b)Bluetooth GATT Attribute Seeking Speed (UUID 0x2b9b)
  • BT GATT Sensor Location (UUID 0x2a5d)Bluetooth GATT Attribute Sensor Location (UUID 0x2a5d)
  • BT GATT Serial Number String (UUID 0x2a25)Bluetooth GATT Attribute Serial Number String (UUID 0x2a25)
  • BT GATT Server Characteristic Configuration (UUID 0x2903)Bluetooth GATT Attribute Server Characteristic Configuration (UUID 0x2903)
  • BT GATT Server Supported Features (UUID 0x2b3a)Bluetooth GATT Attribute Server Supported Features (UUID 0x2b3a)
  • BT GATT Service Changed (UUID 0x2a05)Bluetooth GATT Attribute Service Changed (UUID 0x2a05)
  • BT GATT Service Cycle Data (UUID 0x2c11)Bluetooth GATT Attribute Service Cycle Data (UUID 0x2c11)
  • BT GATT Service Required (UUID 0x2a3b)Bluetooth GATT Attribute Service Required (UUID 0x2a3b)
  • BT GATT Set Identity Resolving Key (UUID 0x2b84)Bluetooth GATT Attribute Set Identity Resolving Key (UUID 0x2b84)
  • BT GATT Set Member Lock (UUID 0x2b86)Bluetooth GATT Attribute Set Member Lock (UUID 0x2b86)
  • BT GATT Set Member Rank (UUID 0x2b87)Bluetooth GATT Attribute Set Member Rank (UUID 0x2b87)
  • BT GATT Sink ASE (UUID 0x2bc4)Bluetooth GATT Attribute Sink ASE (UUID 0x2bc4)
  • BT GATT Sink Audio Locations (UUID 0x2bca)Bluetooth GATT Attribute Sink Audio Locations (UUID 0x2bca)
  • BT GATT Sink PAC (UUID 0x2bc9)Bluetooth GATT Attribute Sink PAC (UUID 0x2bc9)
  • BT GATT Sleep Activity Instantaneous Data (UUID 0x2b41)Bluetooth GATT Attribute Sleep Activity Instantaneous Data (UUID 0x2b41)
  • BT GATT Sleep Activity Summary Data (UUID 0x2b42)Bluetooth GATT Attribute Sleep Activity Summary Data (UUID 0x2b42)
  • BT GATT Software Revision String (UUID 0x2a28)Bluetooth GATT Attribute Software Revision String (UUID 0x2a28)
  • BT GATT Source ASE (UUID 0x2bc5)Bluetooth GATT Attribute Source ASE (UUID 0x2bc5)
  • BT GATT Source Audio Locations (UUID 0x2bcc)Bluetooth GATT Attribute Source Audio Locations (UUID 0x2bcc)
  • BT GATT Source PAC (UUID 0x2bcb)Bluetooth GATT Attribute Source PAC (UUID 0x2bcb)
  • BT GATT Sport Type for Aerobic and Anaerobic Thresholds (UUID 0x2a93)Bluetooth GATT Attribute Sport Type for Aerobic and Anaerobic Thresholds (UUID 0x2a93)
  • BT GATT Stair Climber Data (UUID 0x2ad0)Bluetooth GATT Attribute Stair Climber Data (UUID 0x2ad0)
  • BT GATT Status Flags (UUID 0x2bbb)Bluetooth GATT Attribute Status Flags (UUID 0x2bbb)
  • BT GATT Step Climber Data (UUID 0x2acf)Bluetooth GATT Attribute Step Climber Data (UUID 0x2acf)
  • BT GATT Step Counter Activity Summary Data (UUID 0x2b40)Bluetooth GATT Attribute Step Counter Activity Summary Data (UUID 0x2b40)
  • BT GATT Stored Health Observations (UUID 0x2bdd)Bluetooth GATT Attribute Stored Health Observations (UUID 0x2bdd)
  • BT GATT Stride Length (UUID 0x2b49)Bluetooth GATT Attribute Stride Length (UUID 0x2b49)
  • BT GATT String (UUID 0x2a3d)Bluetooth GATT Attribute String (UUID 0x2a3d)
  • BT GATT Sulfur Dioxide Concentration (UUID 0x2bd8)Bluetooth GATT Attribute Sulfur Dioxide Concentration (UUID 0x2bd8)
  • BT GATT Sulfur Hexafluoride Concentration (UUID 0x2bd9)Bluetooth GATT Attribute Sulfur Hexafluoride Concentration (UUID 0x2bd9)
  • BT GATT Supported Audio Contexts (UUID 0x2bce)Bluetooth GATT Attribute Supported Audio Contexts (UUID 0x2bce)
  • BT GATT Supported Heart Rate Range (UUID 0x2ad7)Bluetooth GATT Attribute Supported Heart Rate Range (UUID 0x2ad7)
  • BT GATT Supported Inclination Range (UUID 0x2ad5)Bluetooth GATT Attribute Supported Inclination Range (UUID 0x2ad5)
  • BT GATT Supported New Alert Category (UUID 0x2a47)Bluetooth GATT Attribute Supported New Alert Category (UUID 0x2a47)
  • BT GATT Supported Power Range (UUID 0x2ad8)Bluetooth GATT Attribute Supported Power Range (UUID 0x2ad8)
  • BT GATT Supported Resistance Level Range (UUID 0x2ad6)Bluetooth GATT Attribute Supported Resistance Level Range (UUID 0x2ad6)
  • BT GATT Supported Speed Range (UUID 0x2ad4)Bluetooth GATT Attribute Supported Speed Range (UUID 0x2ad4)
  • BT GATT Supported Unread Alert Category (UUID 0x2a48)Bluetooth GATT Attribute Supported Unread Alert Category (UUID 0x2a48)
  • BT GATT System ID (UUID 0x2a23)Bluetooth GATT Attribute System ID (UUID 0x2a23)
  • BT GATT TDS Control Point (UUID 0x2abc)Bluetooth GATT Attribute TDS Control Point (UUID 0x2abc)
  • BT GATT Telephone Bearer (UUID 0x184b)Bluetooth GATT Attribute Telephone Bearer (UUID 0x184b)
  • BT GATT Telephony and Media Audio (UUID 0x1855)Bluetooth GATT Attribute Telephony and Media Audio (UUID 0x1855)
  • BT GATT Temperature (UUID 0x2a6e)Bluetooth GATT Attribute Temperature (UUID 0x2a6e)
  • BT GATT Temperature 8 (UUID 0x2b0d)Bluetooth GATT Attribute Temperature 8 (UUID 0x2b0d)
  • BT GATT Temperature 8 in a Period of Day (UUID 0x2b0e)Bluetooth GATT Attribute Temperature 8 in a Period of Day (UUID 0x2b0e)
  • BT GATT Temperature 8 Statistics (UUID 0x2b0f)Bluetooth GATT Attribute Temperature 8 Statistics (UUID 0x2b0f)
  • BT GATT Temperature Celsius (UUID 0x2a1f)Bluetooth GATT Attribute Temperature Celsius (UUID 0x2a1f)
  • BT GATT Temperature Fahrenheit (UUID 0x2a20)Bluetooth GATT Attribute Temperature Fahrenheit (UUID 0x2a20)
  • BT GATT Temperature Measurement (UUID 0x2a1c)Bluetooth GATT Attribute Temperature Measurement (UUID 0x2a1c)
  • BT GATT Temperature Range (UUID 0x2b10)Bluetooth GATT Attribute Temperature Range (UUID 0x2b10)
  • BT GATT Temperature Statistics (UUID 0x2b11)Bluetooth GATT Attribute Temperature Statistics (UUID 0x2b11)
  • BT GATT Temperature Type (UUID 0x2a1d)Bluetooth GATT Attribute Temperature Type (UUID 0x2a1d)
  • BT GATT Termination Reason (UUID 0x2bc0)Bluetooth GATT Attribute Termination Reason (UUID 0x2bc0)
  • BT GATT Three Zone Heart Rate Limits (UUID 0x2a94)Bluetooth GATT Attribute Three Zone Heart Rate Limits (UUID 0x2a94)
  • BT GATT Time Accuracy (UUID 0x2a12)Bluetooth GATT Attribute Time Accuracy (UUID 0x2a12)
  • BT GATT Time Broadcast (UUID 0x2a15)Bluetooth GATT Attribute Time Broadcast (UUID 0x2a15)
  • BT GATT Time Change Log Data (UUID 0x2b92)Bluetooth GATT Attribute Time Change Log Data (UUID 0x2b92)
  • BT GATT Time Decihour 8 (UUID 0x2b12)Bluetooth GATT Attribute Time Decihour 8 (UUID 0x2b12)
  • BT GATT Time Exponential 8 (UUID 0x2b13)Bluetooth GATT Attribute Time Exponential 8 (UUID 0x2b13)
  • BT GATT Time Hour 24 (UUID 0x2b14)Bluetooth GATT Attribute Time Hour 24 (UUID 0x2b14)
  • BT GATT Time Millisecond 24 (UUID 0x2b15)Bluetooth GATT Attribute Time Millisecond 24 (UUID 0x2b15)
  • BT GATT Time Second 16 (UUID 0x2b16)Bluetooth GATT Attribute Time Second 16 (UUID 0x2b16)
  • BT GATT Time Second 32 (UUID 0x2be6)Bluetooth GATT Attribute Time Second 32 (UUID 0x2be6)
  • BT GATT Time Second 8 (UUID 0x2b17)Bluetooth GATT Attribute Time Second 8 (UUID 0x2b17)
  • BT GATT Time Source (UUID 0x2a13)Bluetooth GATT Attribute Time Source (UUID 0x2a13)
  • BT GATT Time Trigger Setting (UUID 0x290e)Bluetooth GATT Attribute Time Trigger Setting (UUID 0x290e)
  • BT GATT Time Update Control Point (UUID 0x2a16)Bluetooth GATT Attribute Time Update Control Point (UUID 0x2a16)
  • BT GATT Time Update State (UUID 0x2a17)Bluetooth GATT Attribute Time Update State (UUID 0x2a17)
  • BT GATT Time with DST (UUID 0x2a11)Bluetooth GATT Attribute Time with DST (UUID 0x2a11)
  • BT GATT Time Zone (UUID 0x2a0e)Bluetooth GATT Attribute Time Zone (UUID 0x2a0e)
  • BT GATT Tire Acceleration (UUID 0x2c3d)Bluetooth GATT Attribute Tire Acceleration (UUID 0x2c3d)
  • BT GATT Tire Pressure (UUID 0x2c3b)Bluetooth GATT Attribute Tire Pressure (UUID 0x2c3b)
  • BT GATT Tire Pressure Monitoring System (UUID 0x1860)Bluetooth GATT Attribute Tire Pressure Monitoring System (UUID 0x1860)
  • BT GATT Tire Temperature (UUID 0x2c3c)Bluetooth GATT Attribute Tire Temperature (UUID 0x2c3c)
  • BT GATT TMAP Role (UUID 0x2b51)Bluetooth GATT Attribute TMAP Role (UUID 0x2b51)
  • BT GATT Torque (UUID 0x2c0b)Bluetooth GATT Attribute Torque (UUID 0x2c0b)
  • BT GATT TPMS Duty Cycle (UUID 0x2c3f)Bluetooth GATT Attribute TPMS Duty Cycle (UUID 0x2c3f)
  • BT GATT TPMS Position (UUID 0x2c40)Bluetooth GATT Attribute TPMS Position (UUID 0x2c40)
  • BT GATT TPMS Properties (UUID 0x2c3e)Bluetooth GATT Attribute TPMS Properties (UUID 0x2c3e)
  • BT GATT TPMS Signing Key (UUID 0x2c41)Bluetooth GATT Attribute TPMS Signing Key (UUID 0x2c41)
  • BT GATT Track Changed (UUID 0x2b96)Bluetooth GATT Attribute Track Changed (UUID 0x2b96)
  • BT GATT Track Duration (UUID 0x2b98)Bluetooth GATT Attribute Track Duration (UUID 0x2b98)
  • BT GATT Track Object Type (UUID 0x2bab)Bluetooth GATT Attribute Track Object Type (UUID 0x2bab)
  • BT GATT Track Position (UUID 0x2b99)Bluetooth GATT Attribute Track Position (UUID 0x2b99)
  • BT GATT Track Segments Object Type (UUID 0x2baa)Bluetooth GATT Attribute Track Segments Object Type (UUID 0x2baa)
  • BT GATT Track Title (UUID 0x2b97)Bluetooth GATT Attribute Track Title (UUID 0x2b97)
  • BT GATT Training Status (UUID 0x2ad3)Bluetooth GATT Attribute Training Status (UUID 0x2ad3)
  • BT GATT Transport Discovery (UUID 0x1824)Bluetooth GATT Attribute Transport Discovery (UUID 0x1824)
  • BT GATT Treadmill Data (UUID 0x2acd)Bluetooth GATT Attribute Treadmill Data (UUID 0x2acd)
  • BT GATT True Wind Direction (UUID 0x2a71)Bluetooth GATT Attribute True Wind Direction (UUID 0x2a71)
  • BT GATT True Wind Speed (UUID 0x2a70)Bluetooth GATT Attribute True Wind Speed (UUID 0x2a70)
  • BT GATT Two Zone Heart Rate Limits (UUID 0x2a95)Bluetooth GATT Attribute Two Zone Heart Rate Limits (UUID 0x2a95)
  • BT GATT Tx Power (UUID 0x1804)Bluetooth GATT Attribute Tx Power (UUID 0x1804)
  • BT GATT Tx Power Level (UUID 0x2a07)Bluetooth GATT Attribute Tx Power Level (UUID 0x2a07)
  • BT GATT UDI for Medical Devices (UUID 0x2bff)Bluetooth GATT Attribute UDI for Medical Devices (UUID 0x2bff)
  • BT GATT UGG Features (UUID 0x2c01)Bluetooth GATT Attribute UGG Features (UUID 0x2c01)
  • BT GATT UGT Features (UUID 0x2c02)Bluetooth GATT Attribute UGT Features (UUID 0x2c02)
  • BT GATT Uncertainty (UUID 0x2ab4)Bluetooth GATT Attribute Uncertainty (UUID 0x2ab4)
  • BT GATT Unread Alert Status (UUID 0x2a45)Bluetooth GATT Attribute Unread Alert Status (UUID 0x2a45)
  • BT GATT Unspecified (UUID 0x2aca)Bluetooth GATT Attribute Unspecified (UUID 0x2aca)
  • BT GATT URI (UUID 0x2ab6)Bluetooth GATT Attribute URI (UUID 0x2ab6)
  • BT GATT User Control Point (UUID 0x2a9f)Bluetooth GATT Attribute User Control Point (UUID 0x2a9f)
  • BT GATT User Data (UUID 0x181c)Bluetooth GATT Attribute User Data (UUID 0x181c)
  • BT GATT User Index (UUID 0x2a9a)Bluetooth GATT Attribute User Index (UUID 0x2a9a)
  • BT GATT UV Index (UUID 0x2a76)Bluetooth GATT Attribute UV Index (UUID 0x2a76)
  • BT GATT Valid Range (UUID 0x2906)Bluetooth GATT Attribute Valid Range (UUID 0x2906)
  • BT GATT Valid Range and Accuracy (UUID 0x2911)Bluetooth GATT Attribute Valid Range and Accuracy (UUID 0x2911)
  • BT GATT Value Trigger Setting (UUID 0x290a)Bluetooth GATT Attribute Value Trigger Setting (UUID 0x290a)
  • BT GATT VO2 Max (UUID 0x2a96)Bluetooth GATT Attribute VO2 Max (UUID 0x2a96)
  • BT GATT VOC Concentration (UUID 0x2be7)Bluetooth GATT Attribute VOC Concentration (UUID 0x2be7)
  • BT GATT Voice Assistant (UUID 0x185e)Bluetooth GATT Attribute Voice Assistant (UUID 0x185e)
  • BT GATT Voice Assistant Name (UUID 0x2c31)Bluetooth GATT Attribute Voice Assistant Name (UUID 0x2c31)
  • BT GATT Voice Assistant Service Control Point (UUID 0x2c33)Bluetooth GATT Attribute Voice Assistant Service Control Point (UUID 0x2c33)
  • BT GATT Voice Assistant Session Flag (UUID 0x2c36)Bluetooth GATT Attribute Voice Assistant Session Flag (UUID 0x2c36)
  • BT GATT Voice Assistant Session State (UUID 0x2c35)Bluetooth GATT Attribute Voice Assistant Session State (UUID 0x2c35)
  • BT GATT Voice Assistant Supported Features (UUID 0x2c38)Bluetooth GATT Attribute Voice Assistant Supported Features (UUID 0x2c38)
  • BT GATT Voice Assistant Supported Languages (UUID 0x2c37)Bluetooth GATT Attribute Voice Assistant Supported Languages (UUID 0x2c37)
  • BT GATT Voice Assistant UUID (UUID 0x2c32)Bluetooth GATT Attribute Voice Assistant UUID (UUID 0x2c32)
  • BT GATT Voltage (UUID 0x2b18)Bluetooth GATT Attribute Voltage (UUID 0x2b18)
  • BT GATT Voltage Frequency (UUID 0x2be8)Bluetooth GATT Attribute Voltage Frequency (UUID 0x2be8)
  • BT GATT Voltage Specification (UUID 0x2b19)Bluetooth GATT Attribute Voltage Specification (UUID 0x2b19)
  • BT GATT Voltage Statistics (UUID 0x2b1a)Bluetooth GATT Attribute Voltage Statistics (UUID 0x2b1a)
  • BT GATT Volume Control (UUID 0x1844)Bluetooth GATT Attribute Volume Control (UUID 0x1844)
  • BT GATT Volume Control Point (UUID 0x2b7e)Bluetooth GATT Attribute Volume Control Point (UUID 0x2b7e)
  • BT GATT Volume Flags (UUID 0x2b7f)Bluetooth GATT Attribute Volume Flags (UUID 0x2b7f)
  • BT GATT Volume Flow (UUID 0x2b1b)Bluetooth GATT Attribute Volume Flow (UUID 0x2b1b)
  • BT GATT Volume Offset Control (UUID 0x1845)Bluetooth GATT Attribute Volume Offset Control (UUID 0x1845)
  • BT GATT Volume Offset Control Point (UUID 0x2b82)Bluetooth GATT Attribute Volume Offset Control Point (UUID 0x2b82)
  • BT GATT Volume Offset State (UUID 0x2b80)Bluetooth GATT Attribute Volume Offset State (UUID 0x2b80)
  • BT GATT Volume State (UUID 0x2b7d)Bluetooth GATT Attribute Volume State (UUID 0x2b7d)
  • BT GATT Waist Circumference (UUID 0x2a97)Bluetooth GATT Attribute Waist Circumference (UUID 0x2a97)
  • BT GATT Weight (UUID 0x2a98)Bluetooth GATT Attribute Weight (UUID 0x2a98)
  • BT GATT Weight Measurement (UUID 0x2a9d)Bluetooth GATT Attribute Weight Measurement (UUID 0x2a9d)
  • BT GATT Weight Scale (UUID 0x181d)Bluetooth GATT Attribute Weight Scale (UUID 0x181d)
  • BT GATT Weight Scale Feature (UUID 0x2a9e)Bluetooth GATT Attribute Weight Scale Feature (UUID 0x2a9e)
  • BT GATT Wind Chill (UUID 0x2a79)Bluetooth GATT Attribute Wind Chill (UUID 0x2a79)
  • BT GATT Work Cycle Data (UUID 0x2c10)Bluetooth GATT Attribute Work Cycle Data (UUID 0x2c10)
  • BT GNSSBluetooth GNSS Profile
  • BT GPP Application ParametersBluetooth OBEX GPP Application Parameters
  • BT HCRPBluetooth HCRP Profile
  • BT HFPBluetooth HFP Profile
  • BT HIDBluetooth HID Profile
  • BT HSPBluetooth HSP Profile
  • BT ISO DataBluetooth ISO Data
  • BT L2CAPBluetooth L2CAP Protocol
  • BT LE LLBluetooth Low Energy Link Layer
  • BT LMPBluetooth Link Manager Protocol
  • BT MAP Application ParametersBluetooth OBEX MAP Application Parameters
  • BT MCAPBluetooth MCAP Protocol
  • BT MeshBluetooth Mesh
  • BT Mesh beaconBluetooth Mesh Beacon
  • BT Mesh PB-ADVBluetooth Mesh PB-ADV
  • BT Mesh ProvisioningBluetooth Mesh Provisioning PDU
  • BT Mesh proxyBluetooth Mesh Proxy
  • BT PBAP Application ParametersBluetooth OBEX PBAP Application Parameters
  • BT RFCOMMBluetooth RFCOMM Protocol
  • BT SAPBluetooth SAP Profile
  • BT SDPBluetooth SDP Protocol
  • BT SMPBluetooth Security Manager Protocol
  • BT SPPBluetooth SPP Packet
  • BT VDPBluetooth VDP Profile
  • BT VDP Content Protection Header SCMS-TBluetooth VDP Content Protection Header SCMS-T
  • BT-DHTBitTorrent DHT Protocol
  • BT-TrackerBitTorrent Tracker
  • BT-uTPuTorrent Transport Protocol
  • BTLE RFBluetooth Low Energy RF Info
  • BTPABTP-A
  • BTPBBTP-B
  • BTSNOOPSymbian OS BTSNOOP File Format
  • BUDBDCE/DFS BUDB
  • BusMirroringBus Mirroring Protocol
  • BUTCDCE/RPC BUTC
  • BVLCBACnet Virtual Link Control
C 158C12.22 · C15 · C15.ch
  • C12.22ANSI C12.22
  • C15C15 Call History Protocol
  • C15.chC15 Call History Common Header Protocol
  • C15.INC_GWEC15 Incoming GWE
  • C15.out_gweC15 Outgoing GWE
  • C15.TONEC15 Tone
  • C15HBEATC15 Call History Heartbeat Protocol
  • C2PC2P (Commsignia Capture Protocol)
  • CalcAppProtocolCalculation Application Protocol
  • CALIBRATIONLocamation Interface Module CALIBRATION
  • Call StatusCall Status
  • CallbackCallback
  • Callback to a pre-specified or admin-specified numberCallback to a pre-specified or admin-specified number
  • Callback to a user-specified numberCallback to a user-specified number
  • Callback to any of a list of numbersCallback to any of a list of numbers
  • CAMITS message - CAM
  • CAMELCamel
  • CAMv1ITS message - CAMv1
  • CANController Area Network
  • CAN over AVTPACF CAN
  • CAN-ETHController Area Network over Ethernet
  • CANFDController Area Network FD
  • CANOPENCANopen
  • CANXLController Area Network XL
  • CAPWAP-CONTROLControl And Provisioning of Wireless Access Points - Control
  • CAPWAP-DATAControl And Provisioning of Wireless Access Points - Data
  • Care-of TestMIPv6 Option - Care-of Test
  • Care-of Test InitMIPv6 Option - Care-of Test Init
  • CARPCommon Address Redundancy Protocol
  • CASTCast Client Control Protocol
  • CAT-TPETSI Card Application Toolkit Transport Protocol
  • CBORConcise Binary Object Representation
  • CBRS_OIDSCitizen Broadband Radio Service - Object Identifiers
  • cbsp3GPP/GSM Cell Broadcast Service Protocol
  • CCTCP Option - CC
  • CC.ECHOTCP Option - CC.ECHO
  • CC.NEWTCP Option - CC.NEW
  • CCSDSCCSDS
  • CCSRLH.324/CCSRL
  • CDMA Code AttributeWiMax CDMA Code Attribute
  • CDMA2KCDMA2K
  • CDPCisco Discovery Protocol
  • CDS_CLERKCDS Clerk Server Calls
  • cds_solicitDCE/RPC CDS Solicitation
  • CDTCompressed Data Type
  • celerra_vnxCELERRA_VNX
  • cEMICommon External Message Interface
  • CephCeph
  • CESoETHCircuit Emulation Service over Ethernet
  • CESoPSN basic (no RTP)CESoPSN basic NxDS0 mode (no RTP support)
  • CFDPCFDP
  • CFLOWCisco NetFlow/IPFIX
  • CFMCFM EOAM IEEE 802.1Q/ITU-T Y.1731 Protocol
  • CFPCisco FabricPath
  • CGA ParametersMIPv6 Option - CGA Parameters
  • CGA Parameters RequestMIPv6 Option - CGA Parameters Request
  • CGMPCisco Group Management Protocol
  • ChargenCharacter Generator Protocol
  • ChargingASECharging ASE
  • CHDLCCisco HDLC
  • CIGICommon Image Generator Interface
  • Cilium DSRIP Option - Cilium DSR
  • CIMDComputer Interface to Message Distribution
  • Cimetrics MS/TPCimetrics MS/TP
  • CIPCommon Industrial Protocol
  • CIP Class 1Common Industrial Protocol, I/O Class 1
  • CIP I/OCommon Industrial Protocol, I/O
  • CIP MotionCommon Industrial Protocol, Motion
  • CIP Motion - Rev 3Common Industrial Protocol, Motion - Rev 3
  • CIP SafetyCommon Industrial Protocol, Safety
  • CIP Safety - Base - DataCommon Industrial Protocol, Safety - Base - Data
  • CIP Safety - Base - Time CoordinationCommon Industrial Protocol, Safety - Base - Time Coordination
  • CIP Safety - Extended - DataCommon Industrial Protocol, Safety - Extended - Data
  • CIP Safety - Extended - Time CoordinationCommon Industrial Protocol, Safety - Extended - Time Coordination
  • CIPCCConcurrent Connection Packet
  • CIPCCOCIP Connection Configuration Object
  • CIPCLSCIP Class Generic
  • CIPCMCIP Connection Manager
  • CIPMBCIP Modbus Object
  • CIPPCCCCIP PCCC Object
  • CIPSSupervisorCIP Safety Supervisor
  • CIPSValidatorCIP Safety Validator
  • Cisco MetaDataCisco MetaData
  • Cisco ttagCisco ttag
  • CISCO3 ERSPAN MARKERCISCO ERSPAN3 Marker Packet
  • CITPController Interface Transport Protocol
  • CITP/CAEXCITP Capture Extensions
  • CITP/FINFCITP Fixture Information
  • CITP/FPTCCITP Fixture Patch
  • CITP/FSELCITP Fixture Selection
  • CITP/MSEXCITP Media Server Extensions
  • CITP/PINFCITP Peer Information
  • CITP/SDMXCITP Send DMX
  • CL3CableLabs Layer 3 Protocol
  • cl3dcwCableLabs Dual-Channel Wi-Fi
  • CLACSEISO 10035-1 OSI Connectionless Association Control Service
  • CLASSICSTUNSimple Traversal of UDP Through NAT
  • CLDAPConnectionless Lightweight Directory Access Protocol
  • CLEARCASEClearcase NFS
  • CLIPClassical IP frame
  • cliprdrRDP clipboard redirection channel Protocol
  • Clique-rmClique Reliable Multicast Protocol
  • CLNPISO 8473/X.233 CLNP ConnectionLess Network Protocol
  • CLPRESISO 9576-1 OSI Connectionless Presentation Protocol
  • CLSPISO 9548-1 OSI Connectionless Session Protocol
  • CLTPISO 8602/X.234 CLTP ConnectionLess Transport Protocol
  • CLUSAPIFailover Cluster Management API (clusapi)
  • CMIPX711 CMIP
  • CMPCertificate Management Protocol
  • CMPPChina Mobile Point to Point Protocol
  • CMSCryptographic Message Syntax
  • CN/IPComponent Network over IP
  • CoAPConstrained Application Protocol
  • CoAP-EAPCoAP-EAP
  • CoLA ASICK CoLA A
  • CoLA BSICK CoLA B
  • collectdcollectd network data
  • Commercial SecurityIP Option - Commercial Security
  • CommunityIDCommunity ID Flow Hashing
  • Compact RoutingIPv6 Routing Types - Compact Routing
  • ComponentStatusProtocolComponent Status Protocol
  • Compound Frames (Deprecated)Compound Frames (Deprecated)
  • CONCTRLRDP Conctrl virtual channel Protocol
  • Consistent Overhead Byte Stuffing (COBS)Consistent Overhead Byte Stuffing (COBS)
  • Context RequestMIPv6 Option - Context Request
  • CONVDCE/RPC Conversation Manager
  • COPSCommon Open Policy Service
  • COROSYNC/TOTEMNETTotemnet Layer of Corosync Cluster Engine
  • COROSYNC/TOTEMSRPTotem Single Ring Protocol implemented in Corosync Cluster Engine
  • COSECBOR Object Signing and Encryption
  • COSE Parameter SubdissectorsCOSE Parameter Subdissectors
  • COSEMDLMS/COSEM
  • CoSineCoSine IPNOS L2 debug output
  • COTPISO 8073/X.224 COTP Connection-Oriented Transport Protocol
  • CouchbaseCouchbase Protocol
  • CP2179CP2179 Protocol
  • CPFICross Point Frame Injector
  • CPHACheck Point High Availability Protocol
  • CPMITS message - CPM
  • CPMviITS message - CPMv1
  • cprpc_serverDNS Control Program Server
  • CQLCassandra CQL Protocol
  • CredSSPCredential Security Support Provider
  • CRFClock Reference Format
  • CRMFCertificate Request Message Format
  • CRTPCRTP
  • CRTP (CNTCP)CRTP (CNTCP)
  • CRTP (CS)CRTP (CS)
  • CRTP (CUDP 16)CRTP (CUDP 16)
  • CRTP (CUDP 8)CRTP (CUDP 8)
  • CSM_ENCAPSCSM_ENCAPS
  • CSN1CSN.1
  • CTCPClient To Client Protocol
  • CTDBCluster TDB
  • CUPSCommon Unix Printing System (CUPS) Browsing Protocol
  • CVFAVTP Compressed Video Format
  • cvspserverCVS pserver
  • CWIDSCisco Wireless IDS Captures
D 201D-Bus · DAAP · DAP
  • D-BusD-Bus
  • DAAPDigital Audio Access Protocol
  • DAPX.519 Directory Access Protocol
  • DarwinApple Darwin
  • Darwin-Process-InformationPCAPNG Darwin Process Information Block
  • DataData
  • DAYTIMEDaytime Protocol
  • DB-LSPDropbox LAN sync Protocol
  • DB-LSP-DISCDropbox LAN sync Discovery Protocol
  • dcDublin Core Metadata (DC)
  • dcachedCache
  • DCCDistributed Checksum Clearinghouse protocol
  • DCCPDatagram Congestion Control Protocol
  • DCE IdentifierDCE Identifier
  • dce_updateDCE/RPC UpServer
  • DCERPCDistributed Computing Environment / Remote Procedure Call (DCE/RPC)
  • DCOMDCOM
  • DCP (ETSI)ETSI Distribution & Communication Protocol (for DRM)
  • DCP-AFDCP Application Framing Layer
  • DCP-PFTDCP Protection, Fragmentation & Transport Layer
  • DCP-TPLDCP Tag Packet Layer
  • DCT2000Catapult DCT2000 packet
  • DDPDatagram Delivery Protocol
  • DDTPDynamic DNS Tools Protocol
  • DEC_DNADEC DNA Routing Protocol
  • DEC_STPDEC Spanning Tree Protocol
  • DECTDECT Protocol
  • DECT NR+DECT NR+ (DECT-2020 New Radio)
  • DECT NR+ TAPDECT NR+ TAP header
  • DECT-DLCDECT DLC (LAPC)
  • DECT-MITEL-RFPMitel RFP/OMM TCP communication protocol
  • DECT-NWKDECT NWK
  • Default Protocol IDDefault Protocol ID
  • DeflateDeflate
  • Delegated Mobile Network PrefixMIPv6 Option - Delegated Mobile Network Prefix
  • DENMITS message - DENM
  • DENMv1ITS message - DENMv1
  • DeviceNetDeviceNet Protocol
  • DHCP/BOOTPDynamic Host Configuration Protocol
  • DHCPFODHCP Failover
  • DHCPv6DHCPv6
  • DHCPv6 Bulk LeasequeryDHCPv6 Bulk Leasequery
  • DHCPv6(cablelabs)DHCPv6 Cablelabs
  • DiameterDiameter Protocol
  • Diameter3GPPDiameter 3GPP
  • DICOMDICOM
  • DISDistributed Interactive Simulation
  • DISCARDDiscard Protocol
  • DISPX.519 Directory Information Shadowing Protocol
  • DISTCCDistcc Distributed Compiler
  • DJIUAVDJI UAV Drone Control Protocol
  • DLEPDynamic Link Exchange Protocol
  • DLEP Data ItemDLEP Data Item Dissector
  • DLM3Distributed Lock Manager
  • DLMSDevice Language Message Specification
  • DLRDevice Level Ring
  • DLSwData Link SWitching
  • DLTDiagnostic Log and Trace (DLT)
  • DLT Storage HeaderShortened Diagnostic Log and Trace (DLT) Storage Header
  • DLT_USERDLT User
  • DMPDirect Message Profile
  • DMXDMX
  • DMX ChannelsDMX Channels
  • DMX SIPDMX SIP
  • DMX Test FrameDMX Test Frame
  • DMX Text FrameDMX Text Frame
  • DNP 3.0Distributed Network Protocol 3.0
  • DNSDomain Name System
  • DNS-UPDATE-TYPEMIPv6 Option - DNS-UPDATE-TYPE
  • DNSSERVERDNS Server
  • DO-IRPDigital Object Identifier Resolution Protocol
  • DOCSISDOCSIS
  • DOCSIS B-INT-RNG-REQDOCSIS Bonded Initial Ranging Message
  • DOCSIS BPKM-REQDOCSIS Baseline Privacy Key Management Request
  • DOCSIS BPKM-RSPDOCSIS Baseline Privacy Key Management Response
  • DOCSIS CM-CTRL-REQDOCSIS CM Control Request
  • DOCSIS CM-CTRL-RSPDOCSIS CM Control Response
  • DOCSIS CM-STATUSDOCSIS CM-STATUS Report
  • DOCSIS CM-STATUS-ACKDOCSIS Status Report Acknowledge
  • DOCSIS CWT-REQDOCSIS IG Discovery CW Test Request
  • DOCSIS CWT-RSPDOCSIS IG Discovery CW Test Response
  • DOCSIS DBC-ACKDOCSIS Dynamic Bonding Change Acknowledge
  • DOCSIS DBC-REQDOCSIS Dynamic Bonding Change Request
  • DOCSIS DBC-RSPDOCSIS Dynamic Bonding Change Response
  • DOCSIS DCC-ACKDOCSIS Downstream Channel Change Acknowledge
  • DOCSIS DCC-REQDOCSIS Downstream Channel Change Request
  • DOCSIS DCC-RSPDOCSIS Downstream Channel Change Response
  • DOCSIS DCDDOCSIS Downstream Channel Descriptor
  • DOCSIS DPDDOCSIS Downstream Profile Descriptor
  • DOCSIS DPRDOCSIS Downstream Protection
  • DOCSIS DPV-REQDOCSIS Path Verify Request
  • DOCSIS DPV-RSPDOCSIS Path Verify Response
  • DOCSIS DSA-ACKDOCSIS Dynamic Service Addition Acknowledge
  • DOCSIS DSA-REQDOCSIS Dynamic Service Addition Request
  • DOCSIS DSA-RSPDOCSIS Dynamic Service Addition Response
  • DOCSIS DSC-ACKDOCSIS Dynamic Service Change Acknowledge
  • DOCSIS DSC-REQDOCSIS Dynamic Service Change Request
  • DOCSIS DSC-RSPDOCSIS Dynamic Service Change Response
  • DOCSIS DSD-REQDOCSIS Dynamic Service Delete Request
  • DOCSIS DSD-RSPDOCSIS Dynamic Service Delete Response
  • DOCSIS ECT-REQDOCSIS CM Echo Cancellation Training Request
  • DOCSIS ECT-RSPDOCSIS CM Echo Cancellation Training Response
  • DOCSIS EM-REQDOCSIS Energy Management Request
  • DOCSIS EM-RSPDOCSIS Energy Management Response
  • DOCSIS EXT-RNG-REQDOCSIS Extended Range Request Message
  • DOCSIS INT-RNG-REQDOCSIS Initial Ranging Message
  • DOCSIS MAC MGMTDOCSIS MAC Management
  • DOCSIS MAPDOCSIS Upstream Bandwidth Allocation - version 1
  • DOCSIS MAPDOCSIS Upstream Bandwidth Allocation - version 5
  • DOCSIS MDDDOCSIS MAC Domain Description
  • DOCSIS OCDDOCSIS OFDM Channel Descriptor
  • DOCSIS OPT-ACKOFDM Downstream Profile Test Acknowledge
  • DOCSIS OPT-REQOFDM Downstream Profile Test Request
  • DOCSIS OPT-RSPOFDM Downstream Profile Test Response
  • DOCSIS PLCDOCSIS PHY Link Channel
  • DOCSIS RBADOCSIS Resource Block Assignment Message
  • DOCSIS REG-ACKDOCSIS Registration Acknowledge
  • DOCSIS REG-REQDOCSIS Registration Requests
  • DOCSIS Reg-Req-MpDOCSIS Registration Request Multipart
  • DOCSIS REG-RSPDOCSIS Registration Responses
  • DOCSIS Reg-Rsp-MpDOCSIS Registration Response Multipart
  • DOCSIS RNG-REQDOCSIS Range Request Message
  • DOCSIS RNG-RSPDOCSIS Ranging Response
  • DOCSIS SegmentDOCSIS Segment
  • DOCSIS TLVsDOCSIS Appendix C TLVs
  • DOCSIS type29ucdDOCSIS Upstream Channel Descriptor Type 29
  • DOCSIS type35ucdDOCSIS Upstream Channel Descriptor Type 35
  • DOCSIS type51ucdDOCSIS Upstream Channel Descriptor Type 51
  • DOCSIS UCC-REQDOCSIS Upstream Channel Change Request
  • DOCSIS UCC-RSPDOCSIS Upstream Channel Change Response
  • DOCSIS UCDDOCSIS Upstream Channel Descriptor
  • DOCSIS VSIFDOCSIS Vendor Specific Encodings
  • DOCSIS_INIT_RANGINGDOCSIS_INIT_RANGING
  • DOCSIS_NCPDOCSIS_NCP
  • DOFDOF Protocol Stack
  • DOF-TCPDOF Protocol Stack TCP
  • DOF-UDPDOF Protocol Stack UDP
  • DOF.CCMDOF CCM Security Mode of Operation
  • DOF.CCM.APPDOF CCM Security Mode App
  • DOF.CCM.DSPDOF CCM Security Mode DSP Options
  • DOF.DNP.V1DOF Network Protocol V1
  • DOF.ESPDOF Session Protocol
  • DOF.OAPDOF Object Access Protocol
  • DOF.OAP.DSPDOF Object Access Protocol DSP Options
  • DOF.SGMPDOF Secure Group Management Protocol
  • DOF.TEP1DOF Ticket Exchange Protocol Version 1
  • DOF.TEP1.DSPDOF Ticket Exchange Protocol DSP Options
  • DOF.TRPDOF Ticket Request Protocol
  • DOF.TRP.DSPDOF Ticket Request Protocol DSP Options
  • DoIPDoIP (ISO13400) Protocol
  • DOPX.501 Directory Operational Binding Management Protocol
  • DPAUXDisplayPort AUX-Channel
  • DPAUXMONDPAUXMON DisplayPort AUX channel monitor
  • DPLAYDirectPlay Protocol
  • DPNETDirectPlay 8 protocol
  • DPNSSDigital Private Signalling System No 1
  • DPNSS LinkDigital Private Signalling System No 1 Link Layer
  • DPS.APPDOF Application Protocol
  • DPS.DNPDOF Network Protocol
  • DPS.DNP.V0DOF Network Protocol V0
  • DPS.DPPDOF Presentation Protocol
  • DPS.DPP.V0DOF Presentation Protocol V0
  • DPS.DPP.V2DOF Presentation Protocol V2
  • DPS.DPP.V2SDOF Presentation Protocol V2 Support
  • DPS.OIDDOF Object Identifier
  • DRbDistributed Ruby
  • DRBDDRBD Protocol
  • DRBD lb-tcpDRBD Load-Balanced Protocol
  • DRDADRDA
  • DRDYNVCRDP Dynamic Channel Protocol
  • DRSUAPIActive Directory Replication
  • DSDLUAVCAN DSDL
  • DSIData Stream Interface
  • DSPX.519 Directory System Protocol
  • DSRDynamic Source Routing
  • DSSETUPActive Directory Setup
  • DTCP-IPDigital Transmission Content Protection over IP
  • DTLSDatagram Transport Layer Security
  • DTPDynamic Trunk Protocol
  • DTPSDOF Tunnel Protocol Stack
  • DTPTDeskTop PassThrough Protocol
  • DTSPROVIDERDCE Distributed Time Service Provider
  • DTSSTIME_REQDCE Distributed Time Service Local Server
  • DUADPNSS/DASS2-User Adaptation Layer
  • DVB AITDVB Application Information Table
  • DVB BATDVB Bouquet Association Table
  • DVB EITDVB Event Information Table
  • DVB NITDVB Network Information Table
  • DVB SDTDVB Service Description Table
  • DVB SITDVB Selection Information Table
  • DVB TDTDVB Time and Date Table
  • DVB TOTDVB Time Offset Table
  • DVB-CIDVB Common Interface
  • DVB-DATA MPEDVB-DATA MultiProtocol Encapsulation
  • DVB-S2DVB-S2 Mode Adaptation Header
  • DVB-S2-BBDVB-S2 Baseband Frame
  • DVB-S2-GSEDVB-S2 GSE Packet
  • DVB-S2-TABLEDVB-S2 Signalization Table
  • DVMRPDistance Vector Multicast Routing Protocol
  • DXDX cluster
  • DXLData Exchange Layer
E 114E-LMI · E.164 · E.212
  • E-LMIEthernet Local Management Interface
  • E.164ITU-T E.164 number
  • E.212ITU-T E.212 number
  • E100E100 Encapsulation
  • E1APE1 Application Protocol
  • E2APE2 Application Protocol
  • EAPExtensible Authentication Protocol
  • EAPOL802.1X Authentication
  • EAPOL-MKAMACsec Key Agreement
  • EBHSCREBHSCR Protocol
  • ECATEtherCAT datagram(s)
  • ECAT_MAILBOXEtherCAT Mailbox Protocol
  • EchoTCP Option - Echo
  • ECHOEcho
  • Echo replyTCP Option - Echo reply
  • ECMPECMP
  • ECPECP Protocol
  • ECP21Edge Control Protocol
  • eCPRIevolved Common Public Radio Interface
  • EDHOCEphemeral Diffie-Hellman Over COSE
  • eDonkeyeDonkey Protocol
  • EDPExtreme Discovery Protocol
  • EEROEERO Protocol
  • EFSEFS (pidl)
  • EGDEthernet Global Data
  • EGFXRDP Graphic pipeline channel Protocol
  • EHSEHS
  • EIGRPEnhanced Interior Gateway Routing Protocol
  • ElasticsearchElasticsearch
  • ELCOMELCOM Communication Protocol
  • ELFExecutable and Linkable Format
  • EMSEGNOS Message Server file
  • ENCOpenBSD Encapsulating device
  • End of Option List (EOL)TCP Option - End of Option List (EOL)
  • End of Options List (EOL)IP Option - End of Options List (EOL)
  • Enhanced RTP compression (RFC3545)Enhanced RTP compression (RFC3545)
  • ENIPEtherNet/IP (Industrial Protocol)
  • ENRPEndpoint Handlespace Redundancy Protocol
  • ENTTECENTTEC
  • EOBIEnhanced Order Book Interface 10.0
  • EPLEthernet POWERLINK
  • EPL_V1ETHERNET Powerlink V1.0
  • EPMDCE/RPC Endpoint Mapper
  • EPMDErlang Port Mapper Daemon
  • EPMv4DCE/RPC Endpoint Mapper v4
  • EPONIEEE 802.3 EPON Preamble
  • ERFExtensible Record Format
  • Ericsson GSM A-bis P-GSLGSM A-bis P-GSL
  • Ericsson GSM A-bis TFPGSM A-bis TFP
  • Ericsson HDLC as used in A-bis over IPEricsson HDLC
  • Ericsson OMLEricsson A-bis OML
  • ErlDPErlang Distribution Protocol
  • Error CodeError Code
  • ERSPANEncapsulated Remote Switch Packet ANalysis
  • ESG BootstrapETSI IPDC Bootstrap
  • ESIOSAIA Ether-S-I/O protocol
  • ESISISO 9542 ESIS Routeing Information Exchange Protocol
  • ESLEtherCAT Switch Link
  • ESPEncapsulating Security Payload
  • ESSExtended Security Services
  • ESUNESUN Protocol
  • ETAG802.1BR E-Tag
  • EtchApache Etch Protocol
  • ETHERCATEtherCAT frame header
  • ETHERIPEthernet over IP
  • EthernetEthernet
  • Ethernet PW (CW heuristic)Ethernet PW (CW heuristic)
  • Ethernet PW (no CW)Ethernet PW (no CW)
  • Ethernet PW (with CW)PW Ethernet Control Word
  • EthertypeEthertype
  • ETIEnhanced Trading Interface 10.0
  • ETSI CATCard Application Toolkit ETSI TS 102.223
  • ETV-AM DDBETV-AM DDB Section
  • ETV-AM DIIETV-AM DII Section
  • ETV-AM EISSETV-AM EISS Section
  • ETWEvent Tracing for Windows
  • ETW NdisETW Ndis
  • ETW WFP CaptureETW WFP Capture
  • EVCSNITS message - EVCSN
  • EVENTLOGEvent Logger
  • EVRCEnhanced Variable Rate Codec
  • EVRC (Legacy)Enhanced Variable Rate Codec (Legacy Encapsulation)
  • EVRC-BEnhanced Variable Rate Codec B
  • EVRC-NWEnhanced Variable Rate Codec - Narrowband-Wideband
  • EVRC-NW2KEnhanced Variable Rate Codec - Narrowband-Wideband plus 2kpbs
  • EVRC-WBEnhanced Variable Rate Codec - Wideband
  • EVRSRITS message - EVRSR
  • EVSEnhanced Voice Services
  • ExablazeExablaze trailer
  • EXECRemote Process Execution
  • EXEHEXtreme extra Eth Header
  • ExperimentalMIPv6 Option - Experimental
  • ExperimentalTCP Option - Experimental
  • Exported PDUEXPORTED_PDU
  • Extended SecurityIP Option - Extended Security
  • EXTREME L2UPDExtreme Mesh L2 Update
  • EXTREME MCHExtreme Mesh Control Header
  • EXTREME MESHExtreme Mesh
  • EXTREME PROBEExtreme Mesh Probe Message
  • EXTREME PS AREPExtreme Mesh Path Selection Authorization Reply
  • EXTREME PS AREQExtreme Mesh Path Selection Authorization Request
  • EXTREME PS BANNExtreme Mesh Path Selection Bind Announcement
  • EXTREME PS BREDExtreme Mesh Path Selection Bind Removed
  • EXTREME PS BREPExtreme Mesh Path Selection Bind Reply
  • EXTREME PS BREQExtreme Mesh Path Selection Bind Request
  • EXTREME PS PERRExtreme Mesh Path Selection Path Error
  • EXTREME PS PREMExtreme Mesh Path Selection Proxy Remove
  • EXTREME PS PREPExtreme Mesh Path Selection Path Reply
  • EXTREME PS PREQExtreme Mesh Path Selection Path Request
  • EXTREME PS PRERExtreme Mesh Path Selection Proxy Error
  • EXTREME PS PRSTExtreme Mesh Path Selection Path Reset
  • EXTREME PS SREPExtreme Mesh Path Selection Status Reply
  • EXTREME PS SREQExtreme Mesh Path Selection Status Request
  • EXTREME PS TRACEExtreme Mesh Path Selection Trace Path
F 70F1AP · F5 Ethernet trailer · F5 TLS
  • F1APF1 Application Protocol
  • F5 Ethernet trailerF5 Ethernet Trailer Protocol
  • F5 TLSF5 Ethernet Trailer Protocol - TLS Provider
  • Favored-PeerFavored-Peer
  • FB/IB GDS DBFirebird SQL Database Remote Protocol
  • FBZERO(Facebook) Zero Protocol
  • FCFibre Channel
  • FC ELSFC Extended Link Svc
  • FC FZSFibre Channel Fabric Zone Server
  • FC_CTFibre Channel Common Transport
  • FC-dNSFibre Channel Name Server
  • FC-FCSFC Fabric Configuration Server
  • FC-SB3Fibre Channel Single Byte Command
  • FC-SPFibre Channel Security Protocol
  • FC-SWILSFibre Channel SW_ILS
  • Fc00Fc00 CryptoAuth
  • FCGIFastCGI
  • FCoEFibre Channel over Ethernet
  • FCoIBFibre Channel over Infiniband
  • FCPFibre Channel Protocol for SCSI
  • FCS AlternativesFCS Alternatives
  • FCSoFFibre Channel Delimiters
  • FDDIFiber Distributed Data Interface
  • FDPFoundry Discovery Protocol
  • FEFDFar End Failure Detection
  • FeliCaSony FeliCa
  • FFFOUNDATION Fieldbus
  • Fibre Channel over IPFCIP
  • FileFile
  • File-BLFBLF File Format
  • File-DLTDLT File Format
  • File-PCAPPCAP File Format
  • File-PCAPNGPCAPNG File Format
  • File-TTLTTL File Format
  • FILEEXPDCE DFS File Exporter
  • FILEINFOF5 Capture Information
  • FINDFind Identification of Network Devices
  • FINGERfinger
  • FIPFCoE Initialization Protocol
  • FIXFinancial Information eXchange Protocol
  • FLDBDCE DFS Fileset Location Server
  • FLEXNETFlexNet
  • FLEXRAYFlexRay Protocol
  • FLIPNSN FLIP
  • FMPFile Mapping Protocol
  • FMP/NOTIFYFile Mapping Protocol Notify
  • FMTPFlight Message Transfer Protocol (FMTP)
  • ForCESForwarding and Control Element Separation Protocol
  • fortinet_fgcp_hbFortiGate Cluster Protocol - HeartBeat
  • fortinet_fgcp_sessionFortiGate Cluster Protocol - Session
  • fortinet_ssoFortinet Single Sign On
  • FPFP
  • FP HintFP Hint
  • FP MuxHuawei FP Multiplexing Header
  • FRFrame Relay
  • FractalGeneratorProtocolFractal Generator Protocol
  • FrameFrame
  • Frame Preemption ProtocolIEEE 802.3br Frame Preemption Protocol
  • Frame Relay DLCI PWPW Frame Relay DLCI Control Word
  • FRSAPIMicrosoft File Replication Service API
  • FRSRPCFile Replication Service
  • FRSTRANSFile Replication Service DFS-R
  • FSRVPFile Server Remote VSS Protocol
  • FTAMISO 8571 FTAM
  • FTDI FTFTDI FT USB
  • FTDI MPSSEFTDI Multi-Protocol Synchronous Serial Engine
  • FTPFile Transfer Protocol (FTP)
  • FTP-DATAFTP Data
  • FTSERVERFTServer Operations
  • FW-1Checkpoint FW-1
G 99G.723 · Gadu-Gadu · Galileo I/NAV
  • G.723G.723
  • Gadu-GaduGadu-Gadu Protocol
  • Galileo I/NAVGalileo E1-B I/NAV Navigation Message
  • Gandalf FZAGandalf FZA
  • GBCS GBZGBCS GBZ
  • GBCS MessageGBCS Message
  • GBCS TunnelGBCS Tunnel
  • GCSNAGCSNA
  • GDB remoteGDB Remote Serial Protocol
  • GDTGeneric Data Transfer Protocol
  • GearmanGearman Protocol
  • GED125Cisco GED-125 Protocol
  • GELFGraylog Extended Log Format
  • Generic PW (with CW)PW MPLS Control Word (generic/preferred)
  • GeneveGeneric Network Virtualization Encapsulation
  • genlLinux Generic Netlink protocol
  • GFPGeneric Framing Procedure
  • GIF imageCompuserve GIF
  • giFTgiFT Internet File Transfer
  • GIOPGeneral Inter-ORB Protocol
  • GIOP/COSEVENTCOMMCoseventcomm Dissector Using GIOP API
  • GIOP/COSNAMINGCosnaming Dissector Using GIOP API
  • GIOP/GIASGias Dissector Using GIOP API
  • GIOP/TANGOTango Dissector Using GIOP API
  • GitGit Smart Protocol
  • GLBPGateway Load Balancing Protocol
  • GLOWGlow
  • glusterGLUSTER
  • Gluster CLIGluster CLI
  • Gluster DumpGluster Dump
  • Gluster PortmapGluster Portmap
  • GlusterDGluster Daemon
  • GlusterD BrickGluster Daemon Brick Operations
  • GlusterD FriendGluster Daemon Friend Operations
  • GlusterD ManagementGluster Daemon Management
  • GlusterFSGlusterFS
  • GlusterFS CallbackGlusterFS Callback
  • GlusterFS HandshakeGlusterFS Handshake
  • GMHDRGigamon Header
  • GMR-1 BCCHGEO-Mobile Radio (1) BCCH
  • GMR-1 CCCHGEO-Mobile Radio (1) CCCH
  • GMR-1 CommonGEO-Mobile Radio (1) Common
  • GMR-1 DTAPGEO-Mobile Radio (1) DTAP
  • GMR-1 RACHGEO-Mobile Radio (1) RACH
  • GMR-1 RRGEO-Mobile Radio (1) RR
  • GMRPGARP Multicast Registration Protocol
  • GMTRAILERGigamon Trailer
  • GNUTELLAGnutella Protocol
  • GNWGeoNetworking
  • Google/Apple Exposure NotificationGoogle/Apple Exposure Notification
  • GOOSEGOOSE
  • GopherGopher
  • GPEFGPEF
  • GPRS-LLCLogical Link Control GPRS
  • GPRS-NSGPRS Network Service
  • GPRSCDRGPRS CDR
  • GPS L1GPS L1 Navigation Message
  • GQUICGQUIC (Google Quick UDP Internet Connections)
  • GREGeneric Routing Encapsulation
  • GRE KeyMIPv6 Option - GRE Key
  • GREbondHuawei GRE bonding
  • GRPCGRPC Message
  • GryphonDG Gryphon Protocol
  • GSM BSSMAPGSM A-I/F BSSMAP
  • GSM BSSMAP LELb-I/F BSSMAP LE
  • GSM CBCHGSM Cell Broadcast Channel
  • GSM CCCHGSM CCCH
  • GSM Cell Broadcast ServiceGSM Cell Broadcast Service
  • GSM COMMONGSM A-I/F COMMON
  • GSM DTAPGSM A-I/F DTAP
  • GSM EC-CCCHGSM EC-CCCH
  • GSM ManagementGSM A-I/F GPRS Mobility and Session Management
  • GSM OsmuxGSM multiplexing for AMR
  • GSM over IPGSM over IP protocol as used by ip.access
  • GSM RACHGSM RACH
  • GSM RLC MACRadio Link Control, Medium Access Control, 3GPP TS44.060
  • GSM RPGSM A-I/F RP
  • GSM RRGSM A-I/F Radio Resource Management
  • GSM SACCHGSM SACCH
  • GSM SIMGSM SIM 11.11
  • GSM SMSGSM SMS TPDU (GSM 03.40)
  • GSM SMS UDGSM Short Message Service User Data
  • GSM UmGSM Um Interface
  • GSM_MAPGSM Mobile Application
  • GSM-L2RCOPGSM L2R Character Oriented Protocol (L2RCOP)
  • GSM-RGSM-R User-to-User Signaling
  • GSM-RLPGSM Radio Link Protocol (RLP)
  • GSMTAPGSM Radiotap
  • GSMTAP-LOGGSMTAP libosmocore logging
  • GSS-APIGSS-API Generic Security Service Application Program Interface
  • GSUPOsmocom General Subscriber Update Protocol
  • GTPGPRS Tunneling Protocol
  • GTP (Prime)GPRS Tunneling Protocol Prime
  • GTP Ext HdrGTP Extension Header
  • GTPv2GPRS Tunneling Protocol V2
  • GUEGeneric UDP Encapsulation
  • GVCPGigE Vision Control Protocol
  • GVRPGARP VLAN Registration Protocol
  • GVSPGigE Vision Streaming Protocol
H 79H.223 · H.223 (Bitswapped) · H.224
  • H.223ITU-T Recommendation H.223
  • H.223 (Bitswapped)ITU-T Recommendation H.223 (Bitswapped)
  • H.224H.224
  • H.225 RASH.225 RAS
  • H.225.0H323-MESSAGES
  • H.235H235-SECURITY-MESSAGES
  • H.245MULTIMEDIA-SYSTEM-CONTROL
  • H.248H.248 MEGACO
  • H.261ITU-T Recommendation H.261
  • H.263ITU-T Recommendation H.263
  • H.263 (RFC2190)H.263 RTP Payload header (RFC2190)
  • H.263PITU-T Recommendation H.263 RTP Payload header (RFC4629)
  • H.264H.264
  • H.265H.265
  • H.323H.323
  • H.450H.450 Supplementary Services
  • H.460H.460 Supplementary Services
  • H.501H.501 Mobility
  • H1Sinec H1 Protocol
  • h221nonstdH221NonStandard
  • H248_2H.248.2
  • H2483GPPH.248 3GPP
  • H248ANH.248.7
  • H248CH.248 Annex C
  • H248CHPH.248.10
  • H248EH.248 Annex E
  • H248Q1950H.248 Q.1950 Annex A
  • H450.ROSH.450 Remote Operations Apdus
  • Handoff IndicatorMIPv6 Option - Handoff Indicator
  • HART_IPHART_IP Protocol
  • HAZELCASTHazelcast Wire Protocol
  • HCI ANDROIDBluetooth Android HCI
  • HCI BROADCOMBluetooth Broadcom HCI
  • HCI IntelBluetooth Intel HCI
  • HCI_ACLBluetooth HCI ACL Packet
  • HCI_CMDBluetooth HCI Command
  • HCI_EVTBluetooth HCI Event
  • HCI_H1Bluetooth HCI H1
  • HCI_H4Bluetooth HCI H4
  • HCI_ISOBluetooth HCI ISO Packet
  • HCI_MONBluetooth Linux Monitor Transport
  • HCI_SCOBluetooth HCI SCO Packet
  • HCI_USBBluetooth HCI USB Transport
  • HCLNFSDHummingbird NFS Daemon
  • HCrtHotline Command-Response Transaction protocol
  • HDCPHigh bandwidth Digital Content Protection
  • HDCP2High bandwidth Digital Content Protection version 2
  • HDFSHDFS Protocol
  • HDFSDATAHDFSDATA Protocol
  • HDLC PW with PPP payload (no CW)HDLC-like framing for PPP
  • HDLC PW, FR port mode (no CW)HDLC PW, FR port mode (no CW)
  • HDMIHigh-Definition Multimedia Interface
  • Hewlett-Packard PPCHewlett-Packard PPC
  • HI2OPERATIONSHI2Operations
  • HICPHost IP Configuration Protocol
  • HIPHost Identity Protocol
  • HiPerConTracerHiPerConTracer Trace Service
  • HiQnetHarman HiQnet
  • HiSLIPHigh-Speed LAN Instrument Protocol
  • HL7Health Level Seven
  • HNBAPUTRAN Iuh interface HNBAP signalling
  • Home Network PrefixMIPv6 Option - Home Network Prefix
  • HomePlugHomePlug protocol
  • HomePlug AVHomePlug AV protocol
  • HomePNAHomePNA, wlan link local tunnel
  • HP_ERMHP encapsulated remote mirroring
  • HPEXTHP Extended Local-Link Control
  • HPFEEDSHPFEEDS HoneyPot Feeds Protocol
  • HPSWHP Switch Protocol
  • HPTEAMHP NIC Teaming Heartbeat
  • HSFZHigh Speed Fahrzeugzugang
  • HSMSHigh-speed SECS Message Service Protocol
  • HSRHigh-availability Seamless Redundancy (IEC62439 Part 3 Chapter 5)
  • HSR_PRP_SUPERVISIONHSR/PRP Supervision (IEC62439 Part 3)
  • HSRPCisco Hot Standby Router Protocol
  • HTTPHypertext Transfer Protocol
  • HTTP2HyperText Transfer Protocol 2
  • HTTP3Hypertext Transfer Protocol Version 3
  • HyperSCSIHyperSCSI
I 188I2C · I2C Data · I2C Events
  • I2CInter-Integrated Circuit
  • I2C DataI2C Data
  • I2C EventsI2C Events
  • IAPInformation Access Protocol
  • IAPPInter-Access-Point Protocol
  • IAX2Inter-Asterisk eXchange v2
  • IBInfiniBand
  • iBeaconApple iBeacon
  • iCalliCall Communication Protocol
  • ICAPInternet Content Adaptation Protocol
  • ICBAAccoCBICBAAccoCallback
  • ICBAAccoCB2ICBAAccoCallback2
  • ICBAAccoMgtICBAAccoMgt
  • ICBAAccoMgt2ICBAAccoMgt2
  • ICBAAccoServICBAAccoServer
  • ICBAAccoServ2ICBAAccoServer2
  • ICBAAccoServSRTICBAAccoServerSRT
  • ICBAAccoSyncICBAAccoSync
  • ICBABrowseICBABrowse
  • ICBABrowse2ICBABrowse2
  • ICBAGErrICBAGroupError
  • ICBAGErrEventICBAGroupErrorEvent
  • ICBALDevICBALogicalDevice
  • ICBALDev2ICBALogicalDevice2
  • ICBAPDevICBAPhysicalDevice
  • ICBAPDev2ICBAPhysicalDevice2
  • ICBAPDevPCICBAPhysicalDevicePC
  • ICBAPDevPCEventICBAPhysicalDevicePCEvent
  • ICBAPersistICBAPersist
  • ICBAPersist2ICBAPersist2
  • ICBARTAutoICBARTAuto
  • ICBARTAuto2ICBARTAuto2
  • ICBAStateICBAState
  • ICBAStateEventICBAStateEvent
  • ICBASysPropICBASystemProperties
  • ICBATimeICBATime
  • ICEPInternet Communications Engine Protocol
  • ICL_RPCDCE DFS ICL RPC
  • ICMPInternet Control Message Protocol
  • ICMPv6Internet Control Message Protocol v6
  • ICPInternet Cache Protocol
  • ICQICQ Protocol
  • ID3v2ID3v2
  • IDENTLocamation Interface Module IDENT
  • IDispatchDCOM IDispatch
  • IDMPX.519 Internet Directly Mapped Protocol
  • IDNILDA Digital Network Protocol
  • IDPInternetwork Datagram Protocol
  • IDRPISO/IEC 10747 (1993): Inter Domain Routing Protocol
  • IEC 60870-5-101IEC 60870-5-101
  • IEC 60870-5-101/104 ASDUIEC 60870-5-101/104 ASDU
  • IEC 60870-5-103IEC 60870-5-103
  • IEC 60870-5-104IEC 60870-5-104
  • IEC 61883IEC 61883 Protocol
  • IEEE 802 Tagged FrameIEEE 802 Tagged Frame
  • IEEE 802.11IEEE 802.11 wireless LAN
  • IEEE 802.11 (Centrino)IEEE 802.11 wireless LAN (Centrino)
  • IEEE 802.11 Aggregate DataIEEE 802.11 wireless LAN aggregate frame
  • IEEE 802.11 EXTIEEE 802.11 wireless LAN extension frame
  • IEEE 802.15.4IEEE 802.15.4 Low-Rate Wireless PAN
  • IEEE 802.15.4 non-ASK PHYIEEE 802.15.4 Low-Rate Wireless PAN non-ASK PHY
  • IEEE 802.15.4 TAPIEEE 802.15.4 Low-Rate Wireless PAN TAP
  • IEEE 802.1ADIEEE 802.1ad
  • IEEE 802.1AHIEEE 802.1ah
  • IEEE1609dot2IEEE1609dot2
  • IEEE1722IEEE 1722 Audio Video Transport Protocol (AVTP)
  • IEEE1722.1IEEE 1722.1 Protocol
  • ieee1905IEEE 1905.1a
  • IEEE802aIEEE802a OUI Extended Ethertype
  • iFCPiFCP
  • IGAPInternet Group membership Authentication Protocol
  • IGMPInternet Group Management Protocol
  • IGRPCisco Interior Gateway Routing Protocol
  • IKEInternet Key Exchange
  • ILMIILMI
  • ILNPIdentifier-Locator Network Protocol
  • ILPOMA Internal Location Protocol
  • IMAPInternet Message Access Protocol
  • IMFInternet Message Format
  • IMZMITS message - IMZM
  • INAPIntelligent Network Application Protocol
  • InfiniBand LinkInfiniBand Link
  • Infiniband SDPInfiniband Sockets Direct Protocol
  • Infinity IntercomTelos Infinity Intercom
  • INITSHUTDOWNInit shutdown service
  • Interface IdentifierInterface Identifier
  • InterlinkInterlink Protocol
  • InternationalizationInternationalization
  • IO-RAWTwinCAT IO-RAW
  • IOXIDResolverDCOM OXID Resolver
  • IP AddressIP Address
  • IP Addresses (deprecated)IP Addresses (deprecated)
  • IP Compression ProtocolIP Compression Protocol
  • IP/IEEE1394Apple IP-over-IEEE 1394
  • IPAGSM over IP ip.access CCM sub-protocol
  • IPARSInternational Passenger Airline Reservation System
  • IPCompIP Payload Compression
  • IPDCIP Device Control (SS7 over IP)
  • IPDR/SPIPDR
  • iPerf2iPerf2 Packet Data
  • iPerf3iPerf3 Speed Test
  • IPFCIP Over FC
  • IPMBIntelligent Platform Management Bus
  • IPMIIntelligent Platform Management Interface
  • IPMI SessionIntelligent Platform Management Interface (Session Wrapper)
  • ipmi-traceIPMI Trace Data Collection
  • IPNETSolaris IPNET
  • IPoIBIP over Infiniband
  • IPOSIPOS Kernel Packet Protocol
  • IPPInternet Printing Protocol
  • IPPUSBInternet Printing Protocol Over USB
  • IProvideClassInfoDCOM IProvideClassInfo
  • IPSICTLIPSICTL
  • IPv4Internet Protocol Version 4
  • IPv4 Address AcknowledgementMIPv6 Option - IPv4 Address Acknowledgement
  • IPv4 Care-of AddressMIPv6 Option - IPv4 Care-of Address
  • IPv4 Default Router AddressIPv4 Default Router Address
  • IPv4 Default-Router AddressMIPv6 Option - IPv4 Default-Router Address
  • IPv4 DHCP Support ModeMIPv6 Option - IPv4 DHCP Support Mode
  • IPv4 Home AddressMIPv6 Option - IPv4 Home Address
  • IPv4 Home Address ReplyMIPv6 Option - IPv4 Home Address Reply
  • IPv4 Home Address RequestMIPv6 Option - IPv4 Home Address Request
  • IPv6Internet Protocol Version 6
  • IPv6 compressionIPv6 compression
  • IPv6 DestinationDestination Options for IPv6
  • IPv6 FragmentFragment Header for IPv6
  • IPv6 Hop-by-HopIPv6 Hop-by-Hop Option
  • IPv6 HSGW Link Local Address IIDIPv6 HSGW Link Local Address IID
  • IPv6 RoutingRouting Header for IPv6
  • IPVSIP Virtual Services Sync Daemon
  • IPXInternetwork Packet eXchange
  • IPX MSGIPX Message
  • IPX RIPIPX Routing Information Protocol
  • IPX SAPService Advertisement Protocol
  • IPX WANIPX WAN
  • IRCInternet Relay Chat
  • IrCOMMIrCOMM Protocol
  • iRDMAIBM i RDMA
  • iRDMA-EPIBM i RDMA Endpoint
  • iRDMA-LinkIBM i RDMA Link
  • iRDMA-QPIBM i RDMA QP
  • IREMOTEWINSPOOLIRemoteWinspool SubSystem
  • IRemUnknownIRemUnknown
  • IRemUnknown2IRemUnknown2
  • IrLAPIrDA Link Access Protocol
  • IrLMPIrDA Link Management Protocol
  • iSCSIiSCSI
  • ISDNISDN
  • ISDN_SUPISDN supplementary services
  • iSERiSCSI Extensions for RDMA
  • ISIIntelligent Service Interface
  • ISISISO 10589 ISIS InTRA Domain Routeing Information Exchange Protocol
  • ISIS CSNPISO 10589 ISIS Complete Sequence Numbers Protocol Data Unit
  • ISIS HELLOISIS HELLO
  • ISIS LSPISO 10589 ISIS Link State Protocol Data Unit
  • ISIS PSNPISO 10589 ISIS Partial Sequence Numbers Protocol Data Unit
  • ISLCisco ISL
  • ISMACRYPISMACryp Protocol
  • ISMACRYP 1.1ISMACryp Protocol v1.1
  • ISMACRYP 2.0ISMACryp Protocol v2.0
  • ISMPInterSwitch Message Protocol
  • iSNSiSNS
  • ISO 10681ISO10681 Protocol
  • ISO 14443ISO/IEC 14443
  • ISO 15765ISO15765 Protocol
  • ISO 7816ISO/IEC 7816
  • ISO 7816-3ISO/IEC 7816-3
  • ISO 8583ISO 8583-1
  • ISOBUSISObus
  • ISObus VTISObus Virtual Terminal
  • ISUPISDN User Part
  • ISystemActivatorISystemActivator ISystemActivator Resolver
  • ITDMInternal TDM
  • ITSIntelligent Transport Systems
  • itunesiTunes podCast rss elements
  • ITypeInfoDCOM ITypeInfo
  • IUAISDN Q.921-User Adaptation Layer
  • IuUPIuUP
  • IVIMITS message - IVIM
  • IVIMv1ITS message - IVIMv1
  • IWARP_DDP_RDMAPiWARP Direct Data Placement and Remote Direct Memory Access Protocol
  • IWARP_MPAiWARP Marker Protocol data unit Aligned framing
  • IWBEMLEVEL1LOGINIWBEMLEVEL1LOGIN (pidl)
  • IWBEMLOGINCLIENTIDIWBEMLOGINCLIENTID (pidl)
  • IWBEMLOGINCLIENTIDEXIWBEMLOGINCLIENTIDEX (pidl)
  • IWBEMSERVICESIWBEMSERVICES (pidl)
  • IXIATRAILERIxia Trailer
  • ixveriwaveixveriwave
J 10J1939 · JDWP · JFIF (JPEG) image
  • J1939SAE J1939
  • JDWPJava Debug Wire Protocol
  • JFIF (JPEG) imageJPEG File Interchange Format
  • JmirrorJuniper Packet Mirror
  • JPEGRFC 2435 JPEG
  • JSONJavaScript Object Notation
  • JSON_3GPPJSON 3GPP
  • JuniperJuniper
  • JXTAJXTA P2P
  • JXTA MessageJXTA Message
K 21K12xx · KADM5 · Kafka
  • K12xxK12xx
  • KADM5Kerberos Administration
  • KafkaKafka
  • KCSKeyboard Controller Style Interface
  • KDPKontiki Delivery Protocol
  • KDSPKismet Drone/Server Protocol
  • KIFQNX6 QNET KIF protocol
  • KingfisherKingfisher
  • KINKKerberized Internet Negotiation of Key
  • KismetKismet Client/Server Protocol
  • KLMKernel Lock Manager
  • KNETkNet Protocol
  • knfsd_leKNFSD_LE
  • knfsd_newKNFSD_NEW
  • KNX/IPKNX/IP
  • KpasswdMS Kpasswd
  • KPMv2KPM V2
  • KRB4Kerberos v4
  • KRB5Kerberos
  • KRB5RPCDCE/RPC Kerberos V
  • Kyoto TycoonKyoto Tycoon Protocol
L 98L&G 8979 · L2TP · LACP
  • L&G 8979Landis & Gyr Telegyr 8979
  • L2TPLayer 2 Tunneling Protocol
  • LACPLink Aggregation Control Protocol
  • LAN-Identification (obsoleted)LAN-Identification (obsoleted)
  • LANforgeLANforge Traffic Generator
  • LANMANMicrosoft Windows Lanman Remote API Protocol
  • LAPBLink Access Procedure Balanced (LAPB)
  • LAPBETHERLink Access Procedure Balanced Ethernet (LAPBETHER)
  • LAPDLink Access Procedure, Channel D (LAPD)
  • LAPDmLink Access Procedure, Channel Dm (LAPDm)
  • LaplinkLaplink
  • LAPSatLink Access Procedure, Satellite channel (LAPSat)
  • LATLocal Area Transport
  • Layer 1 EventsLayer 1 Event Messages
  • LBMCLBMC Protocol
  • LBMPDMLBMPDM Protocol
  • LBMPDM-TCPLBMPDM over TCP Protocol
  • LBMRLBM Topic Resolution Protocol
  • LBMSRSLBM Stateful Resolution Service Protocol
  • LBT-RMLBT Reliable Multicast Protocol
  • LBT-RULBT Reliable Unicast Protocol
  • LBT-TCPLBT TCP Protocol
  • LCSAPLCS Application Protocol
  • LCTH.283 Logical Channel Transport
  • LDA_NEO_TRAILERLDA Neo Device trailer
  • LDACLDAC Codec
  • LDAPLightweight Directory Access Protocol
  • LDPLabel Distribution Protocol
  • LDSSLocal Download Sharing Service
  • LGE_MonitorLGE Monitor
  • LI5GLawful Interception 5G
  • LINLIN Protocol
  • LIN over AVTPACF LIN
  • Line-based text dataLine-based text data
  • Line-IdentificationLine-Identification
  • Link DiscriminatorLink Discriminator
  • Link Discriminator for BACPLink Discriminator for BACP
  • Link Quality MonitoringLink Quality Monitoring
  • Link TypeLink Type
  • Link-local AddressMIPv6 Option - Link-local Address
  • LINK16Link 16
  • LINXENEA LINX
  • LINX/TCPENEA LINX over TCP
  • LISP ControlLocator/ID Separation Protocol
  • LISP DataLocator/ID Separation Protocol (Data)
  • LISP Reliable TransportLocator/ID Separation Protocol (Reliable Transport)
  • listEvent Notification for Resource Lists (RFC 4662)
  • Lithionics BMSLithionics Battery Management System
  • LLAPLocalTalk Link Access Protocol
  • llbDCE/RPC NCS 1.5.1 Local Location Broker
  • LLCLogical-Link Control
  • LLCv1LLC V1
  • LLDPLink Layer Discovery Protocol
  • LLMNRLink-local Multicast Name Resolution
  • LLRPLow Level Reader Protocol
  • LLSATSC3 Low Level Signalling
  • LLTVeritas Low Latency Transport (LLT)
  • LLTDLink Layer Topology Discovery
  • LMILocal Management Interface
  • LMPLink Management Protocol (LMP)
  • LNetLustre Network
  • LNPDQPLocal Number Portability Database Query
  • Load InformationMIPv6 Option - Load Information
  • LogLog Message
  • LOG3GPP3GPP log packet
  • LogcatAndroid Logcat
  • Logcat TextAndroid Logcat Text
  • LogotypeCertExtnLogotype Certificate Extensions
  • LONLocal Operating Network
  • LOOPConfiguration Test Protocol (loopback)
  • Loose Source RouteIP Option - Loose Source Route
  • LoRaTapLoRaTap header
  • LoRaWANLoRaWAN Protocol
  • LPDLine Printer Daemon Protocol
  • LPPLTE Positioning Protocol (LPP)
  • LPPaLTE Positioning Protocol A (LPPa)
  • LPPeLTE Positioning Protocol Extensions (LLPe)
  • LRQNX6 QNET LR protocol
  • LSARPCLocal Security Authority
  • LSCPegasus Lightweight Stream Control
  • LSDLocal Service Discovery
  • LSDPLenbrook Service Discovery Protocol
  • LTE RRCLTE Radio Resource Control (RRC) protocol
  • LTPLicklider Transmission Protocol
  • Lucent/AscendLucent/Ascend debug output
  • lustreLustre
  • LW AdvertisementLivewire Source Advertisement
  • LW ClockLivewire Clock
  • LW GPIOLivewire Multicast GPIO
  • LWAPPLWAPP Encapsulated Packet
  • LWAPP-CNTLLWAPP Control Message
  • LWAPP-L3LWAPP Layer 3 Packet
  • LWCPLivewire Control Protocol
  • LWL4QNX6 QNET LWL4 protocol
  • LwM2M-TLVLightweight M2M TLV
  • LwMeshLightweight Mesh (v1.1.1)
  • LWRESLight Weight DNS RESolver (BIND9)
  • LZS-DCPLZS-DCP
M 180M-Module · M2AP · M2M (m2m)
  • M-ModuleM-Module
  • M2APM2 Application Protocol
  • M2M (m2m)WiMax Mac to Mac Packet
  • M2PAMTP2 Peer Adaptation Layer
  • M2TPMTP 2 Transparent Proxy
  • M2UAMTP 2 User Adaptation Layer
  • M3APM3 Application Protocol
  • M3UAMTP 3 User Adaptation Layer
  • MA WFP Capture AUTH v4Message Analyzer WFP Capture AUTH v4
  • MA WFP Capture AUTH v6Message Analyzer WFP Capture AUTH v6
  • MA WFP Capture v4Message Analyzer WFP Capture v4
  • MA WFP Capture v6Message Analyzer WFP Capture v6
  • MA WFP Capture2 v4Message Analyzer WFP Capture2 v4
  • MA WFP Capture2 v6Message Analyzer WFP Capture2 v6
  • MAAPIEEE 1722 MAAP Protocol
  • MACMAC
  • MAC-AddressMAC-Address
  • MAC-LTEMAC-LTE
  • MAC-LTE-FRAMEDmac-lte-framed
  • MAC-NRMAC-NR
  • MAC-NR-FRAMEDmac-nr-framed
  • MAC-SupportMAC-Support
  • MAC-TelnetMikroTik MAC-Telnet Protocol
  • mac80211_hwsimLinux mac80211_hwsim Netlink
  • MACCMAC Control
  • MacIPMacIP
  • MacIP GPMacIP Gateway Protocol
  • MACsec802.1AE Security Tag
  • MAG IPv6 AddressMIPv6 Option - MAG IPv6 Address
  • MAGICMagic Bullet
  • Magic NumberMagic Number
  • Management InlineManagement Inline
  • ManolitoBlubster/Piolet MANOLITO Protocol
  • MAPEMITS message - MAPEM
  • MAPEMv1ITS message - MAPEMv1
  • MAPIMAPI
  • MarkerLink Aggregation Marker Protocol
  • MATEMeta Analysis Tracing Engine
  • MatterMatter
  • Matter Advertising DataMatter Advertising Data
  • MatterBTPMatter Bluetooth Transport Protocol
  • MAUSBMedia Agnostic USB
  • Maximum Receive UnitMaximum Receive Unit
  • Maximum segment sizeTCP Option - Maximum segment size
  • MBIMMobile Broadband Interface Model
  • MC-NMF.NET Message Framing Protocol
  • MCDataMission critical data
  • MCPMiscabling Protocol
  • MCPEMinecraft Pocket Edition
  • MCTPMCTP
  • MCTP-ControlMCTP Control Protocol
  • MCTP-SMBusMCTP over SMBus/I2C
  • MDBMulti-Drop Bus
  • mDNSMulticast Domain Name System
  • MDPMeraki Discovery Protocol
  • MDS HeaderMDS Header
  • MDSSVCSpotlight metadata search service
  • MediaMedia Type
  • MEGACOMEGACO
  • Mellanox EoIBMellanox EoIB Encapsulation Header
  • MEMCACHEMemcache Protocol
  • MESG-ID-OPTION-TYPEMIPv6 Option - MESG-ID-OPTION-TYPE
  • MeshMesh Header
  • message/httpMedia Type: message/http
  • MessengerMicrosoft Messenger Service
  • METAMetadata
  • MetamakoMetamako ethernet trailer
  • MGCPMedia Gateway Control Protocol
  • MGMTDCE/RPC Remote Management
  • MGMT MSGWiMax MAC Management Message
  • Microsoft PPE/PPCMicrosoft PPE/PPC
  • MIDI SysExMIDI System Exclusive
  • MiFareNXP MiFare
  • MIHMedia-Independent Handover
  • MIKEYMultimedia Internet KEYing
  • MIMITS message - MIM
  • MIME multipartMIME Multipart Media Encapsulation
  • MIME_FILEMIME file
  • MINTMedia Independent Network Transport
  • MINT (Data)Media Independent Network Transport Data
  • MIOPUnreliable Multicast Inter-ORB Protocol
  • MIPv6Mobile IPv6
  • MISCMISC (pidl)
  • Mitel-DECToEAastra/Mitel DECT-over-Ethernet
  • MiWi_P2PStarMiWi P2P Star (v6.4)
  • MLEMesh Link Establishment
  • MMSMMS
  • MMSEMMS Message Encapsulation
  • MNDPMikrotik Neighbor Discovery Protocol
  • Mobile IPMobile IP
  • Mobile Network PrefixMIPv6 Option - Mobile Network Prefix
  • Mobile Node Group IdentifierMIPv6 Option - Mobile Node Group Identifier
  • Mobile Node IdentifierMIPv6 Option - Mobile Node Identifier
  • Mobile Node Link-layer IdentifierMIPv6 Option - Mobile Node Link-layer Identifier
  • Mobile Node Link-local Address Interface IdentifierMIPv6 Option - Mobile Node Link-local Address Interface Identifier
  • Mobile Node's Home IP AddressMobile Node's Home IP Address
  • Mobility Header IPv6 Address/PrefixMIPv6 Option - Mobility Header IPv6 Address/Prefix
  • Mobility Header Link-Layer AddressMIPv6 Option - Mobility Header Link-Layer Address
  • ModbusModbus
  • Modbus RTUModbus RTU
  • Modbus/TCPModbus/TCP
  • Modbus/UDPModbus/UDP
  • MojitoMojito DHT
  • MoldUDPMoldUDP
  • MoldUDP64MoldUDP64
  • MoneroMonero protocol
  • MONGOMongo Wire Protocol
  • MOUNTMount Service
  • MP2TISO/IEC 13818-1
  • mp4MP4 / ISOBMFF file format
  • MP4V-ESMP4V-ES
  • MPEGMoving Picture Experts Group
  • MPEG AudioMoving Picture Experts Group Audio
  • MPEG CAMPEG2 Conditional Access Table
  • MPEG DescriptorMPEG2 Descriptors
  • MPEG DSM-CCMPEG DSM-CC
  • MPEG PATMPEG2 Program Association Table
  • MPEG PESPacketized Elementary Stream
  • MPEG PMTMPEG2 Program Map Table
  • MPEG SECTMPEG2 Section
  • MPEG1RFC 2250 MPEG1
  • MPLSMultiProtocol Label Switching Header
  • MPLS Delay Measurement (DM)MPLS Delay Measurement (DM)
  • MPLS Direct Loss and Delay Measurement (DLM+DM)MPLS Direct Loss and Delay Measurement (DLM+DM)
  • MPLS Direct Loss Measurement (DLM)MPLS Direct Loss Measurement (DLM)
  • MPLS EchoMultiprotocol Label Switching Echo
  • MPLS Inferred Loss and Delay Measurement (ILM+DM)MPLS Inferred Loss and Delay Measurement (ILM+DM)
  • MPLS Inferred Loss Measurement (ILM)MPLS Inferred Loss Measurement (ILM)
  • MPLS ITU-T Y.1711 OAMMPLS ITU-T Y.1711 OAM
  • MPLS PW ATM 1:1 / AAL5 PDUMPLS PW ATM One-to-One or AAL5 PDU encapsulation
  • MPLS PW ATM AAL5 SDUMPLS PW ATM AAL5 CPCS-SDU mode encapsulation
  • MPLS PW ATM Cell HeaderMPLS PW ATM Cell Header
  • MPLS PW ATM Control WordMPLS PW ATM Control Word
  • MPLS PW ATM N:1 CWMPLS PW ATM N-to-One encapsulation, with CW
  • MPLS PW ATM N:1 no CWMPLS PW ATM N-to-One encapsulation, no CW
  • MPLS-MACMedia Access Control (MAC) Address Withdrawal over Static Pseudowire
  • MPLS[-TP] Fault-Management Fault-Management (FM) ProtocolMPLS-TP Fault-Management
  • MPLS[-TP] Lock-Instruct Lock-Instruct (LI) ProtocolMPLS-TP Lock-Instruct
  • MPLS[-TP] Protection State Coordination (PSC) ProtocolPSC
  • MPTCPMultipath Transmission Control Protocol
  • MQWebSphere MQ
  • MQ PCFWebSphere MQ Programmable Command Formats
  • MQTTMQ Telemetry Transport Protocol
  • MQTT-SNMQ Telemetry Transport Protocol for Sensor Networks
  • MRCPv2Media Resource Control Protocol Version 2 (MRCPv2)
  • MRDMulticast Router Discovery
  • MRP-MMRPMultiple Mac Registration Protocol
  • MRP-MSRPMultiple Stream Reservation Protocol
  • MRP-MVRPMultiple VLAN Registration Protocol
  • MS NLBMS Network Load Balancing
  • MS ProxyMS Proxy Protocol
  • MS-DOMicrosoft Delivery Optimization
  • MS-NNS.NET NegotiateStream Protocol
  • MS-RTP PSEMicrosoft RTCP Profile Specific Extensions
  • MS-WSPWindows Search Protocol
  • mscmlMedia Server Control Markup Language - draft 07
  • MSDPMulticast Source Discovery Protocol
  • MsgPackMessage Pack
  • MSMMSMicrosoft Media Server
  • MSNIPMSNIP: Multicast Source Notification of Interest Protocol
  • MSNMSMSN Messenger Service
  • MSRCPMSRCP Protocol
  • MSRPMessage Session Relay Protocol
  • MTP over NW UDPNexusWare C7 MTP
  • MTP2Message Transfer Part Level 2
  • MTP3Message Transfer Part Level 3
  • MTP3MGMessage Transfer Part Level 3 Management
  • MTU ProbeIP Option - MTU Probe
  • MTU ReplyIP Option - MTU Reply
  • MUDURLMUDURL
  • Multi Link Plus ProcedureMulti Link Plus Procedure
  • Multilink Endpoint DiscriminatorMultilink Endpoint Discriminator
  • Multilink header formatMultilink header format
  • Multilink MRRUMultilink MRRU
  • Multilink Short Sequence Number HeaderMultilink Short Sequence Number Header
  • MUX27010MUX27010 Protocol
  • MVMITS message - MVM
  • MVRCA (Magnalink)MVRCA (Magnalink)
  • MySQLMySQL Protocol
  • MySQLXMySQL X Protocol
N 112Nano · NAS-5GS · NAS-EPS
  • NanoNano Cryptocurrency Protocol
  • NAS-5GSNon-Access-Stratum 5GS (NAS)PDU
  • NAS-EPSNon-Access-Stratum (NAS)PDU
  • NASDAQ-ITCHNasdaq TotalView-ITCH
  • NASDAQ-SOUPNasdaq-SoupTCP version 2.0
  • NAT DetectionMIPv6 Option - NAT Detection
  • NAT-PMPNAT Port Mapping Protocol
  • NATSNATS
  • NavitrolNavitec Systems Navitrol
  • NB_RTPMUX3GPP Nb Interface RTP Multiplex
  • NBAPUTRAN Iub interface NBAP signalling
  • NBDNetwork Block Device
  • NBDSNetBIOS Datagram Service
  • NBIFOMNetwork-Based IP Flow Mobility
  • NBIPXNetBIOS over IPX
  • NBNSNetBIOS Name Service
  • NBPName Binding Protocol
  • NBSSNetBIOS Session Service
  • NCPNetWare Core Protocol
  • NCSNovell Cluster Services
  • NCSINCSI
  • NDMPNetwork Data Management Protocol
  • NDPNortel Discovery Protocol
  • NDPSNovell Distributed Print System
  • NEGOEXSPNEGO Extended Negotiation Security Mechanism
  • Negotiating header compression (RFC3545)Negotiating header compression (RFC3545)
  • net_dmLinux net_dm (network drop monitor) protocol
  • NET/ROMAmateur Radio NET/ROM
  • netANALYZERnetANALYZER
  • NetBIOSNetBIOS
  • NETDFSSettings for Microsoft Distributed File System
  • NetdumpNetdump Protocol
  • netfilterLinux netlink netfilter protocol
  • NETLINKLinux netlink protocol
  • NetMon 802.11NetMon 802.11 capture header
  • NetMon EventNetwork Monitor Event
  • NetMon FilterNetwork Monitor Filter
  • NetMon HeaderNetwork Monitor Header
  • NetMon Network InfoNetwork Monitor Network Info
  • NetMon ProcessNetwork Monitor Process
  • NetMon System ConfigNetwork Monitor System Config
  • NetMon System TraceNetwork Monitor System Trace
  • NetPerfMeterNetPerfMeter Protocol
  • NetrixNetrix Communication Protocol
  • NetScaler HANetScaler HA Protocol
  • NetScaler MEPNetScaler Metric Exchange Protocol
  • NetScaler RPCNetScaler RPC Protocol
  • NetsyncMonotone Netsync
  • nettlHP-UX Network Tracing and Logging
  • NEWMAILMicrosoft Exchange New Mail Notification
  • NFAPINfapi
  • NFLOGLinux Netfilter NFLOG
  • NFSNetwork File System
  • NFS CBNetwork File System CB
  • nfs_unknownUnknown NFS
  • NFSACLNFSACL
  • NFSAUTHNFSAUTH
  • nfsd_leNFSD_LE
  • NFSv4Network File System v4
  • NGAPNG Application Protocol
  • NGENetgear Ensemble Protocol
  • NHRPNBMA Next Hop Resolution Protocol
  • NIS+NIS+
  • NIS+ CBNIS+ Callback
  • NIST_CSORNIST_CSOR
  • NJACK3com Network Jack
  • nl80211Linux 802.11 Netlink
  • NLMNetwork Lock Manager Protocol
  • NLSPNetWare Link Services Protocol
  • NMASNovell Modular Authentication Service
  • NMEA 0183NMEA 0183 protocol
  • NMEA 0183 BINNMEA 0183 binary protocol
  • nmea2000NMEA 2000
  • NMFNMF (.NET Message Framing Protocol)
  • NMPIName Management Protocol over IPX
  • NNTPNetwork News Transfer Protocol
  • No callbackNo callback
  • No Operation (NOP)IP Option - No-Operation (NOP)
  • No Phone Number NeededNo Phone Number Needed
  • No-Operation (NOP)TCP Option - No-Operation (NOP)
  • NOENOE Protocol
  • NoiseF5 Ethernet trailer provider - Noise
  • Nominal Data Encapsulation (Deprecated)Nominal Data Encapsulation (Deprecated)
  • Nonce IndicesMIPv6 Option - Nonce Indices
  • NORDIC_BLEnRF Sniffer for Bluetooth LE
  • NORMNegative-acknowledgment Oriented Reliable Multicast
  • novell_pkisNovell PKIS ASN.1 type
  • NRQNX6 QNET Network Resolver protocol
  • NR RRCNR Radio Resource Control (RRC) protocol
  • NRPPaNR Positioning Protocol A (NRPPa)
  • NRUPNRUP
  • NS TraceNetScaler Trace
  • NS_CERT_EXTSNetScape Certificate Extensions
  • NSHNetwork Service Header
  • NSPIExchange 5.5 Name Service Provider
  • NSRPJuniper Netscreen Redundant Protocol
  • NTLMSSPNTLM Secure Service Provider
  • NTPNetwork Time Protocol
  • NTS-KENTS Key Establishment Protocol
  • NTSCFNon-Time-Synchronous Control Format
  • NullNull/Loopback
  • Numbered ModeNumbered Mode
  • nvmeNVM Express
  • NVMe Fabrics RDMANVM Express Fabrics RDMA
  • NVMe-MINVMe-MI
  • NVMe-MI AdminNVMe-MI Admin Command
  • NVMe-MI ControlNVMe-MI Control Primitive
  • NVMe-MI MINVMe-MI MI Command
  • NVMe/TCPNVM Express Fabrics TCP
  • NW_SERIALNetWare Serialization Protocol
  • NWPNeighborhood Watch Protocol
  • NXP 802154 SnifferNXP 802.15.4 Sniffer Protocol
O 52O-RAN FH CUS · OAM AAL · OAMPDU
  • O-RAN FH CUSO-RAN Fronthaul CUS
  • OAM AALATM OAM AAL
  • OAMPDUEthernet OAM PDU
  • OBD-IIOBD-II PID
  • OBEXOBEX Protocol
  • OCFS2OCFS2 Networking
  • OCP.1Open Control Protocol (OCP.1/AES70)
  • OCSPOnline Certificate Status Protocol
  • OEROctet Encoding Rules (ASN.1)
  • OICQOICQ - IM software, popular in China
  • OIPF CI+Open IPTV Forum CSPG-CI+
  • OLSROptimized Link State Routing Protocol
  • OMAPIISC Object Management API
  • OMRON FINSOMRON FINS Protocol
  • ontap_gx_v3ONTAP_GX_V3
  • ontap_v3ONTAP_V3
  • ontap_v4ONTAP_V4
  • OPAIntel Omni-Path
  • OPA FEIntel Omni-Path FE Header - Omni-Path Fabric Executive Header
  • OPA MADIntel Omni-Path MAD
  • OPA SnCIntel Omni-Path SnC - Omni-Path Snoop and Capture MetaData Header
  • OpcUaOpcUa Binary Protocol
  • OpenFlowOpenFlow
  • openflow_v1OpenFlow 1.0
  • openflow_v4OpenFlow 1.3
  • openflow_v5OpenFlow 1.4
  • openflow_v6OpenFlow 1.5
  • openSAFETYopenSAFETY
  • openSAFETY ov. UDPopenSAFETY over UDP
  • OpenThreadOpenThread
  • OpenVPNOpenVPN Protocol
  • OpenWireOpenWire
  • OPSIOpen Policy Service Interface
  • OptoMMPOptoMMP
  • OPUSOpus Interactive Audio Codec
  • OSCOpen Sound Control Encoding
  • OSCOREObject Security for Constrained RESTful Environments
  • OSIOSI
  • OsmoTRXCOsmoTRX Control / Clock Protocol
  • OsmoTRXDOsmoTRX Data Protocol
  • OSPFOpen Shortest Path First
  • OSSPOrganization Specific Slow Protocol
  • OTPObject Transform Protocol
  • OUCHOUCH
  • OUIOUI
  • ovs_ct_limitLinux ovs_ct_limit (Open vSwitch CT Limit) protocol
  • ovs_datapathLinux ovs_datapath (Open vSwitch Datapath) protocol
  • ovs_flowLinux ovs_flow (Open vSwitch Flow) protocol
  • ovs_meterLinux ovs_meter (Open vSwitch Meter) protocol
  • ovs_packetLinux ovs_packet (Open vSwitch Packet) protocol
  • ovs_vportLinux ovs_vport (Open vSwitch Vport) protocol
  • OWAMP-TestOne-way Active Measurement Protocol
P 156P_MUL · P1 · P22
  • P_MULP_Mul (ACP142)
  • P1X.411 Message Transfer Service
  • P22X.420 Information Object
  • P3X.411 Message Access Service
  • P4RPCP4RPC (Perforce Protocol)
  • P7X.413 Message Store Service
  • P772STANAG 4406 Message
  • PA-HB-BakPalo Alto Heartbeat Backup
  • PacketBBPacketBB Protocol
  • PACKETCABLEPacketCable AVPs
  • Pad1MIPv6 Option - Pad1
  • PadNMIPv6 Option - PadN
  • PAGPPort Aggregation Protocol
  • PaltalkPaltalk Messenger Protocol
  • PANAProtocol for carrying Authentication for Network Access
  • PAPIAruba PAPI
  • PathportPathport Protocol
  • PCAPUTRAN Iupc interface Positioning Calculation Application Part (PCAP)
  • pcap_pktdatapcap/pcapng packet data
  • pcaplogpcaplog
  • PCAPNGPcapng block
  • PCEPPath Computation Element communication Protocol
  • PCLIPacket Cable Lawful Intercept
  • PCLI12 (timestamp)Packet Cable Lawful Intercept (timestamp)
  • PCLI20 (timestamp, case ID)Packet Cable Lawful Intercept (timestamp, case ID)
  • PCLI8 (8 byte CCCID)Packet Cable Lawful Intercept (8 byte CCCID)
  • PCNFSDPC NFS
  • PCOM ASCIIPCOM ASCII
  • PCOM BINARYPCOM BINARY
  • PCOM/TCPPCOM/TCP
  • PCPPerformance Co-Pilot
  • pdPrimary_Data
  • PDCPDC Protocol
  • PDCP-LTEPDCP-LTE
  • PDCP-NRPDCP-NR
  • PDN AddressPDN Address
  • PDN IdentifierPDN Identifier
  • PDN TypePDN Type
  • PDU TransportPDU Transport Protocol
  • PEAPProtected Extensible Authentication Protocol
  • PEEKREMOTEAiroPeek/OmniPeek encapsulated IEEE 802.11
  • PERPacked Encoding Rules (ASN.1 X.691)
  • Permanent Home Keygen TokenMIPv6 Option - Permanent Home Keygen Token
  • PFCPPacket Forwarding Control Protocol
  • PFLOGOpenBSD Packet Filter log file
  • PFLOG-OLDOpenBSD Packet Filter log file, pre 3.4
  • PGMPragmatic General Multicast
  • PGSQLPostgreSQL
  • Phone DeltaPhone Delta
  • PIMITS message - PIM
  • PIMProtocol Independent Multicast
  • PingPongProtocolPing Pong Protocol
  • PKCS10PKCS10 Certification Request
  • PKCS12PKCS#12: Personal Information Exchange
  • PKInitPKINIT
  • PKIX CertificatePKIX CERT File Format
  • PKIX1EXPLICITPKIX1Explicit
  • PKIX1IMPLICITPKIX1Implicit
  • PKIXACPKIX Attribute Certificate
  • PKIXALGSPKIX Algorithms
  • PKIXPROXYPKIXProxy (RFC3820)
  • PKIXQUALIFIEDPKIX Qualified
  • PKIXTSPPKIX Time Stamp Protocol
  • PKT CCCPacketCable Call Content Connection
  • Pkt_CommentPacket comments
  • PKTAPPKTAP packet header
  • PKTCPacketCable
  • PKTC MTA FQDNPacketCable MTA FQDN
  • PKTGENLinux Kernel Packet Generator
  • PKTLOGPacketLogger
  • PLDMPLDM Protocol
  • PLEPrivate Line Emulation
  • PMPROXYPerformance Co-Pilot Proxy
  • PN-DCPPROFINET DCP
  • PN-MRPPROFINET MRP
  • PN-MRRTPROFINET MRRT
  • PN-PTCPPROFINET PTCP
  • PN-RSIPROFINET RSI
  • PN-RTPROFINET Real-Time Protocol
  • PN-SXPPROFINET SXP
  • PN532NXP PN532
  • PN532_HCINXP PN532 HCI
  • PNGPortable Network Graphics
  • PNIOPROFINET IO
  • PNIO (Apdu Status)PROFINET IO (Apdu Status)
  • PNIO (Controller Interface)PROFINET IO (Controller)
  • PNIO (Device Interface)PROFINET IO (Device)
  • PNIO (Implicit Ar)PROFINET IO (Implicit Ar)
  • PNIO (Parameter Server Interface)PROFINET IO (Parameter Server)
  • PNIO (Supervisor Interface)PROFINET IO (Supervisor)
  • PNIO (Time Aware Status)PROFINET IO (Time Aware Status)
  • PNPMicrosoft Plug and Play service
  • PNRPPeer Name Resolution Protocol
  • poc-settingspoc-settings XML doc (RFC 4354)
  • POPPost Office Protocol
  • Port ControlPort Control Protocol
  • PortmapPortmap
  • PPCAPProprietary PCAP
  • PPIPPI Packet Header
  • PPI antenna DecoderPPI antenna decoder
  • PPI GPS DecoderPPI Geotagging GPS tag decoder
  • PPI sensor DecoderPPI sensor decoder
  • PPI vector DecoderPPI vector decoder
  • PPPPoint-to-Point Protocol
  • PPP BACPPPP Bandwidth Allocation Control Protocol
  • PPP BAPPPP Bandwidth Allocation Protocol
  • PPP BCP BPDUPPP Bridging Control Protocol Bridged PDU
  • PPP BCP NCPPPP Bridging Control Protocol Network Control Protocol
  • PPP CBCPPPP Callback Control Protocol
  • PPP CCPPPP Compression Control Protocol
  • PPP CDPCPPPP CDP Control Protocol
  • PPP CHAPPPP Challenge Handshake Authentication Protocol
  • PPP CompPPP Compressed Datagram
  • PPP for Data Compression in Data Circuit-Terminating Equipment (DCE)PPP for Data Compression in Data Circuit-Terminating Equipment (DCE)
  • PPP IPCPPPP IP Control Protocol
  • PPP IPV6CPPPP IPv6 Control Protocol
  • PPP LCPPPP Link Control Protocol
  • PPP MPPPP Multilink Protocol
  • PPP MPLSCPPPP MPLS Control Protocol
  • PPP OSINLCPPPP OSI Network Layer Control Protocol
  • PPP PAPPPP Password Authentication Protocol
  • PPP PPPMuxPPP Multiplexing
  • PPP PPPMuxCPPPPMux Control Protocol
  • PPP VSNPVendor Specific Network Protocol
  • PPP-HDLCPPP In HDLC-Like Framing
  • PPPoEPPP-over-Ethernet
  • PPPoEDPPP-over-Ethernet Discovery
  • PPPoESPPP-over-Ethernet Session
  • PPTPPoint-to-Point Tunnelling Protocol
  • PrAPPrinter Access Protocol
  • Predictor type 1Predictor type 1
  • Predictor type 2Predictor type 2
  • Prefix ElisionPrefix Elision
  • PRESISO 8823 OSI Presentation Protocol
  • presencepresence XML doc (RFC 3863)
  • Primary DNS Server IP AddressPrimary DNS Server IP Address
  • Primary NBNS Server IP AddressPrimary NBNS Server IP Address
  • PrismPrism capture header
  • Profiles (RFC3241)Profiles (RFC3241)
  • ProtoBufProtocol Buffers
  • ProtoBuf_JSONProtocol Buffers (as JSON Mapping View)
  • Protocol Configuration OptionsProtocol Configuration Options
  • Protocol Field CompressionProtocol Field Compression
  • PROXYPROXY Protocol
  • PRPParallel Redundancy Protocol (IEC62439 Part 3)
  • psampleLinux psample protocol
  • PSNPosiStageNet
  • PTPPrecision Time Protocol (IEEE1588)
  • PTP/IPPicture Transfer Protocol Over IP
  • Puddle JumperPuddle Jumper
  • PULSEPULSE protocol for Linux Virtual Server redundancy
  • PVFSParallel Virtual File System
  • PW Associated ChannelPW Associated Channel Header
  • PW Associated Management Communication ChannelManagement Communication Channel (MCC)
  • PW PaddingPseudowire Padding
  • PW-OAM Pseudo-Wire OAM ProtocolPseudo-Wire OAM
Q 19Q.2931 · Q.708 · Q.931
  • Q.2931Q.2931
  • Q.708ITU-T Q.708 ISPC Analysis
  • Q.931Q.931
  • Q.933Q.933
  • Q932Q.932
  • Q932.ROSQ.932 Operations Service Element
  • QCDIAGQualcomm Diagnostic
  • QCDIAG LOGQualcomm Diagnostic Log
  • QLLCQualified Logical Link Control
  • QOSQNX6 QNET QOS protocol
  • QSIGQSIG
  • QUAKEQuake Network Protocol
  • QUAKE2Quake II Network Protocol
  • QUAKE3Quake III Arena Network Protocol
  • QUAKEWORLDQuakeWorld Network Protocol
  • Quality ProtocolQuality Protocol
  • QUICQUIC IETF
  • Quick-StartIP Option - Quick-Start
  • Quick-StartTCP Option - Quick-Start
R 155R-GOOSE · R-STP · R-Tag
  • R-GOOSER-GOOSE
  • R-STPRetix Spanning Tree Protocol
  • R-Tag802.1CB Redundancy Tag
  • R-TAG802.1cb R-TAG
  • R09R09.x
  • R3Assa Abloy R3
  • RAD (RFC2198)RTP Payload for Redundant Audio Data (RFC 2198)
  • RADIUSRADIUS Protocol
  • RAILRDP Program virtual channel Protocol
  • RakNetRakNet game networking protocol
  • RANAPRadio Access Network Application Part
  • RawRaw packet data
  • Raw Application ParametersOBEX Raw Application Parameters
  • Raw_SigCompDecompressed SigComp message as raw text
  • Raw_SIPSession Initiation Protocol (SIP as raw text)
  • RbmRuby Marshal Object
  • RCGRCG (pidl)
  • RCv3RC V3
  • rdaclifDCE/RPC Directory Acl Interface
  • RDCH.282 Remote Device Control
  • RDMRemote Device Management
  • RDM-ETCETC RDM Extensions
  • RDMnetRDMnet
  • RDPRemote Desktop Protocol
  • RDPDRRDP disk redirection virtual channel Protocol
  • rdpearRDP authentication redirection virtual channel Protocol
  • RDPECAMRDP Video Capture Virtual Channel Extension
  • RDPMTRemote Desktop Protocol Multi-transport
  • rdpsndRDP audio output virtual channel Protocol
  • RDPUDPUDP Remote Desktop Protocol
  • RDTReal Data Transport
  • RealtekRealtek Layer 2 Protocols
  • ReasonReason
  • Record RouteIP Option - Record Route
  • RedbackRedback
  • RedbackLIRedback Lawful Intercept
  • RedirectMIPv6 Option - Redirect
  • Redirect-CapabilityMIPv6 Option - Redirect-Capability
  • reginfoReginfo XML doc (RFC 3680)
  • RELOADREsource LOcation And Discovery
  • RELOAD FRAMINGREsource LOcation And Discovery Framing
  • REMACTDCOM IRemoteActivation
  • REPRealtek Echo Protocol
  • REP_PROCDCE DFS Replication Server
  • RESPREdis Serialization Protocol
  • Restart CounterMIPv6 Option - Restart Counter
  • RF4CERF4CE Network Layer
  • RF4CE ProfileRF4CE Profile
  • rfc7468RFC 7468 file format
  • RFRExchange 2003 Directory Request For Response
  • RFtapRFtap Protocol
  • RGMPRouter-port Group Management Protocol
  • RiemannRiemann
  • RIFFResource Interchange File Format
  • RIPRouting Information Protocol
  • RIPngRIPng
  • Riverbed ProbeTCP Option - Riverbed Probe
  • Riverbed TransparencyTCP Option - Riverbed Transparency
  • RK512SICK RK512
  • RLCRadio Link Control
  • RLC-LTERLC-LTE
  • RLC-NRRLC-NR
  • RLDPRealtek Loop Detection Protocol
  • RLMRedundant Link Management Protocol
  • RloginRlogin Protocol
  • RMCPRemote Management Control Protocol
  • RMIJava RMI
  • RMPHP Remote Maintenance Protocol
  • RMT-FECForward Error Correction (FEC)
  • RMT-LCTLayered Coding Transport
  • RNSAPUTRAN Iur interface Radio Network Subsystem Application Part
  • ROHCRObust Header Compression (ROHC)
  • RoMONMikrotik RoMON
  • RoofnetRoofnet Protocol
  • RoonDiscoRoon Discovery
  • ROSX.880 OSI Remote Operations Service
  • RoughtimeRoughtime
  • Router AlertIP Option - Router Alert
  • roverrideRemote Override interface
  • RPCRemote Procedure Call
  • RPC_BROWSERRPC Browser
  • RPC_NETLOGONMicrosoft Network Logon
  • RPCAPRemote Packet Capture
  • RPCoRDMARPC over RDMA
  • RPKI-Router ProtocolRPKI-Router Protocol
  • RPLRemote Program Load
  • RPL Source RouteIPv6 Routing Type - RPL Source Route
  • rprivPrivilege Server operations
  • RQUOTARemote Quota
  • RRASMicrosoft Routing and Remote Access Service
  • RRCRadio Resource Control (RRC) protocol
  • RRCPRealtek Remote Control Protocol
  • RRLPRadio Resource LCS Protocol (RRLP)
  • RS_ACCTDCE/RPC RS_ACCT
  • RS_ATTRRegistry Server Attributes Manipulation Interface
  • rs_attr_schemaDCE/RPC Registry Server Attributes Schema
  • RS_BINDDCE/RPC RS_BIND
  • rs_miscDCE/RPC RS_MISC
  • RS_PGODCE Name Service
  • RS_PLCYRS Interface properties
  • rs_prop_acctDCE/RPC RS_PROP_ACCT
  • rs_prop_aclDCE/RPC Registry server propagation interface - ACLs
  • rs_prop_attrDCE/RPC Prop Attr
  • rs_prop_pgoDCE/RPC Registry server propagation interface - PGO items
  • rs_prop_plcyDCE/RPC Registry server propagation interface - properties and policies
  • rs_pwd_mgmtDCE/RPC Registry Password Management
  • RS_REPADMRegistry server administration operations.
  • RS_REPLISTDCE/RPC Repserver Calls
  • rs_repmgrDCE/RPC Operations between registry server replicas
  • RS_UNIXDCE/RPC RS_UNIX
  • rsec_loginRemote sec_login preauth interface.
  • RSHRemote Shell
  • RSIPRealm Specific IP Protocol
  • RSLRadio Signalling Link (RSL)
  • RSPRMCP Security-extensions Protocol
  • rssrss
  • RSTATRSTAT
  • RSVDRemote Shared Virtual Disk
  • RSVPResource ReserVation Protocol (RSVP)
  • RSVP-E2EIResource ReserVation Protocol (RSVP-E2EI)
  • RSYNCRSYNC File Synchroniser
  • RTAC SerialRTAC Serial
  • RTCDCWebRTC Datachannel Protocol
  • RTcfgRTcfg
  • RTCMEMITS message - RTCMEM
  • RTCMEMv1ITS message - RTCMEMv1
  • RTCPReal-time Transport Control Protocol
  • RTCP CCFBRTP Congestion Control Feedback (CCFB)
  • RTCP NACKGeneric negative acknowledgement (NACK)
  • RTCP TMMBNTemporary Maximum Media Stream Bit Rate Notification (TMMBN)
  • RTCP TMMBRTemporary Maximum Media Stream Bit Rate Request (TMMBR)
  • RTCP Transport-CCTransport-wide Congestion Control (Transport-cc)
  • RTITCPRTI TCP Transport Protocol
  • RTLSReal Time Location System
  • RTmacReal-Time Media Access Control
  • RTMPRouting Table Maintenance Protocol
  • RTMPTReal Time Messaging Protocol
  • rtnetlinkLinux rtnetlink (route netlink) protocol
  • RTPReal-Time Transport Protocol
  • RTP compression (RFC2508)RTP compression (RFC2508)
  • RTP EventRFC 2833 RTP Event
  • RTP-ED137Real-Time Transport Protocol ED137 Extensions
  • RTP-MIDIRFC 4695/6295 RTP-MIDI
  • rtpdumpRTPDump file format
  • RTPproxySippy RTPproxy Protocol
  • RTPSReal-Time Publish-Subscribe Wire Protocol
  • RTPS-PROCReal-Time Publish-Subscribe Wire Protocol (processed)
  • RTPS-VTReal-Time Publish-Subscribe Virtual Transport
  • RTSEX.228 OSI Reliable Transfer Service
  • RTSPReal Time Streaming Protocol
  • RTTrPReal-Time Tracking Protocol
  • RUAUTRAN Iuh interface RUA signalling
  • RUDPReliable UDP
  • RWALLRemote Wall protocol
  • RXRX Protocol
S 182S101 · S1AP · S7COMM
  • S101S101
  • S1APS1 Application Protocol
  • S7COMMS7 Communication
  • SABPUTRAN IuBC interface SABP signaling
  • SACKTCP Option - SACK
  • SACK permittedTCP Option - SACK permitted
  • SADMINDSADMIND
  • SAMETIMESametime Protocol
  • SAMIS-TYPE-1 RecordSAMIS-TYPE-1 Record
  • SAMPLES - IM1Locamation Interface Module SAMPLES - IM1
  • SAMPLES - IM2R0Locamation Interface Module SAMPLES - IM2R0
  • SAMRSAMR (pidl)
  • SANEScanner Access Now Easy
  • SAPSession Announcement Protocol
  • SAPDIAGSAP Diag Protocol
  • SAPENQUEUESAP Enqueue Protocol
  • SAPHDBSAP HANA SQL Command Network Protocol
  • SAPIGSSAP Internet Graphic Server
  • SAPMSSAP Message Server Protocol
  • SAPNISAP NI Protocol
  • SAPRFCSAP RFC Protocol
  • SAPROUTERSAP Router Protocol
  • SAPSNCSAP SNC Protocol
  • SASPServer/Application State Protocol
  • SAToPSAToP
  • SBAS L1SBAS L1 Navigation Message
  • SBAS L5SBAS L5 Navigation Message
  • SBCBluetooth SBC Codec
  • SBcAPSBc Application Part
  • SBUSSAIA S-Bus
  • SCARD_PACKSCARD_PACK (pidl)
  • SCCPSignalling Connection Control Part
  • SCCPMGSignalling Connection Control Part Management
  • SCoPZigBee SCoP
  • SCPS capabilitiesTCP Option - SCPS capabilities
  • SCPS corruption experiencedTCP Option - SCPS corruption experienced
  • SCPS record boundaryTCP Option - SCPS record boundary
  • SCSISCSI
  • SCSI_MMCSCSI_MMC
  • SCSI_OSDSCSI_OSD
  • SCSI_SBCSCSI_SBC
  • SCSI_SMCSCSI_SMC
  • SCSI_SSCSCSI_SSC
  • SCTE 35SCTE-35 Splice Information
  • SCTE35 PCSCTE-35 Private Command
  • SCTE35 SISCTE-35 Splice Insert
  • SCTE35 SSSCTE-35 Splice Schedule
  • SCTE35 TSSCTE-35 Time Signal
  • SCTPStream Control Transmission Protocol
  • ScyllaScylla RPC protocol
  • SDAPSDAP
  • SDHSDH/SONET Protocol
  • SDLCSynchronous Data Link Control (SDLC)
  • SDPSession Description Protocol
  • SEBEKSEBEK - Kernel Data Capture
  • SECIDMAPDCE Security ID Mapper
  • Secondary DNS Server IP AddressSecondary DNS Server IP Address
  • Secondary NBNS Server IP AddressSecondary NBNS Server IP Address
  • SecurityIP Option - Security
  • Segment RoutingIPv6 Routing Types - Segment Routing
  • SEL ProtocolSEL Protocol
  • Selective Directed BroadcastIP Option - Selective Directed Broadcast
  • Selective Negative AcknowledgmentTCP Option - Selective Negative Acknowledgment
  • Self Describing PadSelf Describing Pad
  • SERCOS III V1.1SERCOS III V1.1
  • SerializationJava Serialization
  • Service SelectionMIPv6 Option - Service Selection
  • SESISO 8327-1 OSI Session Protocol
  • sFlowInMon sFlow
  • SFTPSSH File Transfer Protocol
  • SGI MOUNTSGI Mount Service
  • SGP.22SGP.22 GSMA Remote SIM Provisioning (RSP)
  • SGP.32SGP.32 GSMA Remote SIM Provisioning (RSP)
  • SGSAPSGs Application Part (SGsAP)
  • SHICPSecure Host IP Configuration Protocol
  • Shim6Shim6 Protocol
  • SIGCOMPSignaling Compression
  • Signal PDUSignal PDU
  • SignatureMIPv6 Option - Signature
  • Silabs DCHSilabs Debug Channel
  • SIMPLEStandard Interface for Multiple Platform Link Evaluation
  • Simple Data Link on SONET/SDHSimple Data Link on SONET/SDH
  • SIMULCRYPTSIMULCRYPT Protocol
  • SINEC APSINEC AP Telegram
  • SIPSession Initiation Protocol
  • SIPFRAGSipfrag
  • SIRSerial Infrared
  • SITASociete Internationale de Telecommunications Aeronautiques
  • SKINNYSkinny Client Control Protocol
  • SKYPESKYPE
  • SLARPCisco SLARP
  • SliMP3SliMP3 Communication Protocol
  • SLLLinux cooked-mode capture
  • Slow Protocols802.3 Slow protocols
  • SMCisco Session Management
  • SMBSMB (Server Message Block Protocol)
  • SMB MailslotSMB MailSlot Protocol
  • SMB PipeSMB Pipe Protocol
  • SMB_NETLOGONMicrosoft Windows Logon Protocol (Old)
  • SMB2SMB2 (Server Message Block Protocol version 2)
  • SMBDirectSMB-Direct (SMB RDMA Transport)
  • SMCShared Memory Communications
  • smilSynchronized Multimedia Integration Language
  • SMLSmart Message Language
  • SMPSession Multiplex Protocol
  • SMPPShort Message Peer to Peer
  • SMRSEShort Message Relaying Service
  • SMTPSimple Mail Transfer Protocol
  • SMUXSNMP Multiplex Protocol
  • SNASystems Network Architecture
  • SNA XIDSystems Network Architecture XID
  • SNAETHSNA-over-Ethernet
  • SNDCPSubnetwork Dependent Convergence Protocol
  • SNDCP XIDSubnetwork Dependent Convergence Protocol XID
  • SNMPSimple Network Management Protocol
  • SnortSnort Alerts
  • sock_diagLinux netlink sock diag protocol
  • SocksSocks Protocol
  • SolarEdgeSolarEdge monitoring protocol
  • SOME/IPSOME/IP Protocol
  • SOME/IP-SDSOME/IP Service Discovery Protocol
  • SoulSeekSoulSeek Protocol
  • SoupBinTCPSoupBinTCP
  • Source RouteIPv6 Routing Type - Source Route
  • Spanning-Tree-Protocol (old formatted)Spanning-Tree-Protocol (old formatted)
  • SparkplugBSparkplugB
  • SPATEMITS message - SPATEM
  • SPATEMv1ITS message - SPATEMv1
  • SPDYSPDY
  • SpiceSpice protocol
  • SPNEGOSimple Protected Negotiation
  • SPNEGO-KRB5SPNEGO-KRB5
  • SPOOLSSMicrosoft Spool Subsystem
  • SPPSequenced Packet Protocol
  • SPRAYSPRAY
  • SPRTSimple Packet Relay Transport
  • SPXSequenced Packet eXchange
  • SREMITS message - SREM
  • SRPH.324/SRP
  • SRTSRT Protocol
  • SRTCPSecure Real-time Transport Control Protocol
  • SRVLOCService Location Protocol
  • SRVSVCServer Service
  • SSCF-NNISSCF-NNI
  • SSCOPSSCOP
  • SSDPSimple Service Discovery Protocol
  • SSEMITS message - SSEM
  • SSHSSH Protocol
  • SSPScripting Service Protocol
  • SSSNovell SecretStore Services
  • SSTPSecure Socket Tunneling Protocol
  • SSyncPState Synchronization Protocol
  • ST2110-20SMPTE ST2110-20 (Uncompressed Active Video)
  • Stac Electronics LZSStac Electronics LZS
  • Stac Electronics LZS (Ascend Proprietary version)Stac Electronics LZS (Ascend Proprietary version)
  • STANAG 4607STANAG 4607 (GMTI Format)
  • STANAG 5066 DTSSTANAG 5066(DTS layer)
  • STANAG 5066 SISSTANAG 5066 (SIS layer)
  • StarTeamStarTeam
  • STATNetwork Status Monitor Protocol
  • STAT-CBNetwork Status Monitor CallBack Protocol
  • STCSIGSpirent Test Center Signature
  • Steam IHS DiscoverySteam In-Home Streaming Discovery Protocol
  • STPSpanning Tree Protocol
  • Stream IDIP Option - Stream ID
  • Strict Source RouteIP Option - Strict Source Route
  • STTStateless Transport Tunneling
  • STUNSession Traversal Utilities for NAT
  • SUASS7 SCCP-User Adaptation Layer
  • SVIEC61850 Sampled Values
  • svc_paramsSVC params
  • SVCCTLService Control
  • svr4SVR4
  • swIPeswIPe IP Security Protocol
  • SymantecSymantec Enterprise Firewall
  • SYNCMBMS synchronisation protocol
  • SYNC MessageDOCSIS Synchronisation Message
  • SYNCHROPHASORIEEE C37.118 Synchrophasor Protocol
  • SynergySynergy
  • SyscallSystem Call
  • SysEx DigiTechMIDI System Exclusive DigiTech
  • SyslogSyslog Message
T 94T.124 · T.125 · T.30
  • T.124GENERIC-CONFERENCE-CONTROL T.124
  • T.125MULTIPOINT-COMMUNICATION-SERVICE T.125
  • T.30T.30
  • T.38T.38
  • TACACSTACACS
  • TACACS+TACACS+
  • TALITransport Adapter Layer Interface v1.0, RFC 3094
  • TAPATrapeze Access Point Access Protocol
  • TAPIMicrosoft Telephony API Service
  • TaskSchedulerServiceMicrosoft Task Scheduler Service
  • TC-NVTwinCAT NV
  • TCAPTransaction Capabilities Application Part
  • TCG_CP_OIDSTCG_CP_OIDS
  • TCPTransmission Control Protocol
  • TCP AOTCP Option - TCP AO
  • TCP Fast OpenTCP Option - TCP Fast Open
  • TCP MD5 signatureTCP Option - TCP MD5 signature
  • TCPCLDTN TCP Convergence Layer Protocol
  • TCPCL Extension SubdissectorsTCPCL Extension Subdissectors
  • TCPENCAPTCP Encapsulation of IPsec Packets
  • TCPROSTCP based Robot Operating System protocol (TCPROS)
  • TDMATDMA RTmac Discipline
  • TDMoEDigium TDMoE Protocol
  • TDMoPTDMoP protocol
  • TDSTabular Data Stream
  • TeamSpeak2Teamspeak2 Protocol
  • TEAPTunnel Extensible Authentication Protocol
  • TECMPTechnically Enhanced Capture Module Protocol
  • TECMP PayloadTechnically Enhanced Capture Module Protocol Payload
  • TEI_MANAGEMENTTEI Management Procedure, Channel D (LAPD)
  • TEKLINKTEKLINK
  • TELKONETTelkonet powerline
  • TELNETTelnet
  • TeredoTeredo IPv6 over UDP tunneling
  • TETRATETRA Protocol
  • TFPTinkerforge Protocol
  • TFTPTrivial File Transfer Protocol
  • ThreadThread
  • Thread AddressThread Address
  • Thread Backbone LinkThread Backbone Link
  • Thread BeaconThread Beacon
  • Thread CoAPThread CoAP
  • Thread DiagnosticsThread Diagnostics
  • Thread MeshCoPThread MeshCoP
  • Thread Network ManagementThread Network Management
  • Thread NWDThread Network Data
  • ThriftThrift Protocol
  • TibiaTibia Protocol
  • TIFF imageTagged Image File Format
  • TIMETime Protocol
  • Time StampIP Option - Time Stamp
  • TimestampMIPv6 Option - Timestamp
  • TimestampsTCP Option - Timestamps
  • Tinygram-CompressionTinygram-Compression
  • TIPCTransparent Inter Process Communication(TIPC)
  • TISTPGITS message - TISTPG
  • TiVoConnectTiVoConnect Discovery Protocol
  • TKN4IntDCE DFS Token Server
  • TLSTransport Layer Security
  • TModeSerial Terminal Mode Interface
  • TN3270TN3270 Protocol
  • TN5250TN5250 Protocol
  • TNEFTransport-Neutral Encapsulation Format
  • TNSTransparent Network Substrate Protocol
  • Token-RingToken-Ring
  • TPCPAlteon - Transparent Proxy Cache Protocol
  • TPKTTPKT - ISO on TCP - RFC1006
  • TPKT Heuristic (for RDP)TPKT Heuristic (for RDP)
  • TPLINK-SMARTHOMETP-Link Smart Home Protocol
  • TPM2.0TPM2.0 Protocol
  • TPNCPTPNCP (TrunkPack Network Control Protocol)
  • TR MACToken-Ring Media Access Control
  • TracerouteIP Option - Traceroute
  • TRANSUMTRANSUM RTE Data
  • TRDPTrain Real Time Data Protocol
  • TRELTREL Protocol
  • TRILLTRILL
  • TRKSVRMicrosoft Distributed Link Tracking Server Service
  • TrueConfTrueConf Protocol
  • TSCFTime-Synchronous Control Format
  • TSDNSTeamSpeak3 DNS
  • TSPTime Synchronization Protocol
  • TTETTEthernet
  • TTE PCFTTEthernet Protocol Control Frame
  • TTLTTL Format
  • TTPTiny Transport Protocol
  • TurbocellTurbocell Header
  • Turbocell Aggregate DataTurbocell Aggregate Data
  • TURNCHANNELTURN Channel
  • TUXEDOBEA Tuxedo
  • TWAMP-ControlTwoWay Active Measurement Control Protocol
  • TWAMP-TestTwoWay Active Measurement Test Protocol
  • Type 2IPv6 Routing Type - Type 2
  • TZSPTazmen Sniffer Protocol
U 53U3V · UA · UA3G
  • U3VUSB 3 Vision
  • UAUniversal Alcatel Protocol
  • UA3GUA3G Message
  • UASIPUA/SIP Protocol
  • UASPUSB Attached SCSI
  • UAUDPUA/UDP Encapsulation Protocol
  • UAVCAN/CANUAVCAN/CAN
  • UBDPUbiquiti Discovery Protocol
  • UBERTOOTHUbertooth
  • UBIKDISKDCE DFS FLDB UBIK TRANSFER
  • UBIKVOTEDCE DFS FLDB UBIKVOTE
  • UBTAruba UBT
  • UBXUBX Protocol
  • UCIUWB UCI Protocol
  • UCPUniversal Computer Protocol
  • UDLDUnidirectional Link Detection
  • UDPUser Datagram Protocol
  • UDP-LiteLightweight User Datagram Protocol
  • UDPCPUDPCP
  • UDPENCAPUDP Encapsulation of IPsec Packets
  • UDSUnified Diagnostic Services
  • UDTUDT Protocol
  • UDXUDX Protocol
  • UETUltra Ethernet Transport
  • UFTPUDP based FTP w/ multicast
  • UFTP4UDP based FTP w/ multicast V4
  • UFTP5UDP based FTP w/ multicast V5
  • UHDUHD
  • ULPOMA UserPlane Location Protocol
  • UMAUnlicensed Mobile Access
  • Undecoded FCIUndecoded FCI
  • UNISTIMUNISTIM Protocol
  • UnknownTCP Option - Unknown
  • Unknown RPCUnknown RPC protocol
  • URL Encoded Form DataHTML Form URL Encoded
  • USBUSB
  • USB DFUUSB Device Firmware Upgrade
  • USB-PTPUSB Picture Transfer Protocol
  • USBAUDIOUSB Audio
  • USBCCIDUSB CCID
  • USBCOMUSB Communications and CDC Control
  • USBHIDUSB HID
  • USBHUBUSB HUB
  • USBIPUSBIP Protocol
  • USBLLUSB Link Layer
  • USBMSUSB Mass Storage
  • USBMSClassUSB Mass Storage Class
  • USBPortUSBPort
  • USBPRINTERUSB Printer
  • USBVIDEOUSB Video
  • User TimeoutTCP Option - User Timeout
  • UserLogUserLog Protocol
  • UTSUnisys Transmittal System
V 56V.120 · V.150.1 SSE · V.42bis compression
  • V.120Async data over ISDN (V.120)
  • V.150.1 SSEV.150.1 State Signaling Event
  • V.42bis compressionV.42bis compression
  • V.44/LZJH compressionV.44/LZJH compression
  • V5.2V5.2
  • V5DLV5 Data Link Layer
  • v5efV5 Envelope Function (v5ef)
  • V5UAV5.2-User Adaptation Layer
  • VAMITS message - VAM
  • VCDUVCDU
  • VDP21VSI protocol
  • Vendor SpecificMIPv6 Option - Vendor Specific
  • Vendor SpecificVendor Specific
  • Version 0.10AMQP Version 0.10
  • Version 0.9AMQP Version 0.9
  • Version 1.0AMQP Version 1.0
  • VICPLeCroy VICP
  • VINESVINES
  • Vines ARPBanyan Vines ARP
  • Vines EchoBanyan Vines Echo
  • Vines FRPBanyan Vines Fragmentation Protocol
  • Vines ICPBanyan Vines ICP
  • Vines IPBanyan Vines IP
  • Vines IPCBanyan Vines IPC
  • Vines LLCBanyan Vines LLC
  • Vines RTPBanyan Vines RTP
  • Vines SPPBanyan Vines SPP
  • VITA 49VITA 49 radio transport protocol
  • VJCVan Jacobson PPP compression
  • VLAN802.1Q Virtual LAN
  • VLP-16 DataVLP-16 Data Protocol
  • VLP-16 PositionVLP-16 Position Protocol
  • VMLABVMware Lab Manager
  • vmware_hbVMware - HeartBeat
  • VNCVirtual Network Computing
  • VNTAGVN-Tag
  • VP8VP8
  • VP9VP9
  • VPPVPP Dispatch Trace
  • VPP-MetadataVPP Buffer Metadata
  • VPP-OpaqueVPP Buffer Opaque
  • VPP-Opaque2VPP Buffer Opaque2
  • VPP-TraceVPP Buffer Trace
  • VRRPVirtual Router Redundancy Protocol
  • VSIPVideo Services over IP
  • VSNCPVendor Specific Control Protocol
  • vsockvSocket
  • vSomeIPvSomeIP
  • VSS MonitoringVSS Monitoring Ethernet trailer
  • VTPVLAN Trunking Protocol
  • Vuze-DHTVuze DHT Protocol
  • VXI-11 AsyncVXI-11 Asynchronous Abort
  • VXI-11 CoreVXI-11 Core Protocol
  • VXI-11 IntrVXI-11 Interrupt
  • VXLANVirtual eXtensible Local Area Network
  • VXLAN (GPE)Virtual eXtensible Local Area Network (GPE)
W 70WAI · WAP SIR · WASSP
  • WAIWAI Protocol
  • WAP SIRWAP Session Initiation Request
  • WASSPWireless Access Station Session Protocol
  • watcherinfowatcherinfo XML doc (RFC 3858)
  • waveagentWaveAgent
  • WBXMLWAP Binary XML
  • WCCPWeb Cache Communication Protocol
  • WCPWellfleet Compression
  • WebSocketWebSocket
  • WFDWi-Fi Display
  • WHDLCWellfleet HDLC
  • WHOWho
  • WHOISwhois
  • Wi-Fi DPPWi-Fi Device Provisioning Protocol
  • Wi-Fi NANWi-Fi Neighbor Awareness Networking (NAN)
  • Wi-Fi P2PWi-Fi Peer-to-Peer
  • Wi-SUNWi-SUN Field Area Network
  • Wi-SUN EAPOL RelayWi-SUN FAN EAPOL Relay
  • Wi-SUN Netricity SegmentWi-SUN Netricity Segment
  • Wi-SUN WM-SECWi-SUN FAN Security Extension
  • WiMax (wmx)WiMax Protocol
  • WiMax AAS-BEAMWiMax AAS-BEAM Messages
  • WiMax AAS-FEEDBACK (aas)WiMax AAS-FEEDBACK Messages
  • WiMax ARQ Feedback/Discard/Reset (arq)WiMax ARQ Feedback/Discard/Reset Messages
  • WiMAX ASN CPWiMAX ASN Control Plane Protocol
  • WiMax CLK-CMP (clk)WiMax CLK-CMP Message
  • WiMax DCDWiMax DCD Messages
  • WiMax DLMAPWiMax DLMAP Messages
  • WiMax DREG-CMDWiMax DREG-CMD Messages
  • WiMax DREG-REQWiMax DREG-REQ Messages
  • WiMax DSAWiMax DSA Messages
  • WiMax DSCWiMax DSC Messages
  • WiMax DSDWiMax DSD Messages
  • WiMax DSX-RVD (dsx_rvd)WiMax DSX-RVD Message
  • WiMax FPC (fpc)WiMax FPC Message
  • WiMax Generic/Type1/Type2 MAC Header (hdr)WiMax Generic/Type1/Type2 MAC Header Messages
  • WiMAX MAC-PHYWiMAX MAC-PHY over Ethernet
  • WiMax PKM-REQ/RSP (pkm)WiMax PKM-REQ/RSP Messages
  • WiMax PMC-REQWiMax PMC-REQ Messages
  • WiMax PMC-RSPWiMax PMC-RSP Messages
  • WiMax PRC-LT-CTRL (prc)WiMax PRC-LT-CTRL Message
  • WiMax REG-REQWiMax REG-REQ Messages
  • WiMax REG-RSPWiMax REG-RSP Messages
  • WiMax REP-REQ/RSP (rep)WiMax REP-REQ/RSP Messages
  • WiMax RES-CMD (res)WiMax RES-CMD Message
  • WiMax RNG-REQWiMax RNG-REQ Messages
  • WiMax RNG-RSPWiMax RNG-RSP Messages
  • WiMax SBC-REQ/RSP (sbc)WiMax SBC-REQ/RSP Messages
  • WiMax Sub-TLV (sub)WiMax Sub-TLV Messages
  • WiMax UCDWiMax UCD Messages
  • WiMax ULMAPWiMax ULMAP Messages
  • Window scaleTCP Option - Window scale
  • WINREGRemote Registry Service
  • WINS-ReplicationWINS (Windows Internet Name Service) Replication
  • WireGuardWireGuard Protocol
  • WITNESSSMB Witness Service
  • WKSSVCWorkstation Service
  • WLANCERTEXTNWlan Certificate Extension
  • WLCCPCisco Wireless LAN Context Control Protocol
  • WMIOWMIO
  • WOLWake On LAN
  • WOWWorld of Warcraft
  • WOWWWorld of Warcraft World
  • WPSWifi Protected Setup
  • WRETHWSE remote ethernet
  • WSMPWave Short Message Protocol(IEEE P1609.3)
  • WSPWireless Session Protocol
  • WTLSWireless Transport Layer Security
  • WTPWireless Transaction Protocol
  • WZCSVCWireless Configuration Service
X 28X-Rite i1 Display Pro · X.25 · X.29
  • X-Rite i1 Display ProX-Rite i1 Display Pro (and derivatives) USB protocol
  • X.25X.25
  • X.29X.29
  • X.75Async data over ISDN (X.75)
  • X11X11
  • X2APEUTRAN X2 Application Protocol (X2AP)
  • X509AFX.509 Authentication Framework
  • X509CEX.509 Certificate Extensions
  • X509IFX.509 Information Framework
  • X509SATX.509 Selected Attribute Types
  • xcap-capsXML Configuration Access Protocol Server Capabilities
  • xcap-errorXCAP Error XML doc (RFC 4825)
  • XCPUniversal Measurement and Calibration Protocol (XCP)
  • XCSLCall Specification Language (Xcsl)
  • XDMCPX Display Manager Control Protocol
  • XGTXGT FEnet Protocol
  • XIPeXpressive Internet Protocol
  • XIP ServalXIP Serval
  • xIRIX2 xIRI payload
  • XMCPeXtensible Messaging Client Protocol
  • XMLeXtensible Markup Language
  • XMPPXMPP Protocol
  • XnAPNG-RAN Xn Application Protocol (XnAP)
  • XOTX.25 over TCP
  • XRAExcentis XRA Header
  • XTIEnhanced Cash Trading Interface 10.0
  • XTPXpress Transport Protocol
  • XYPLEXXyplex
Y 7YAMI · YHOO · YMSG
  • YAMIYAMI Protocol
  • YHOOYahoo Messenger Protocol
  • YMSGYahoo YMSG Messenger Protocol
  • YPBINDYellow Pages Bind
  • YPPASSWDYellow Pages Passwd
  • YPSERVYellow Pages Service
  • YPXFRYellow Pages Transfer
Z 97Z21 · Z39.50 · Zabbix
  • Z21Z21 LAN Protocol
  • Z39.50Z39.50 Protocol
  • ZabbixZabbix Protocol
  • ZB NCPZBOSS Network Coprocessor product
  • ZB TLVZigbee TLV
  • ZBDZigBee Direct
  • ZBOSS dumpZBOSS IEEE 802.15.4 dump
  • ZCL AlarmsZigBee ZCL Alarms
  • ZCL Analog Input BasicZigBee ZCL Analog Input Basic
  • ZCL Analog Output BasicZigBee ZCL Analog Output Basic
  • ZCL Analog Value BasicZigBee ZCL Analog Value Basic
  • ZCL Appliance ControlZigBee ZCL Appliance Control
  • ZCL Appliance Events & AlertZigBee ZCL Appliance Events & Alert
  • ZCL Appliance IdentificationZigBee ZCL Appliance Identification
  • ZCL Appliance StatisticsZigBee ZCL Appliance Statistics
  • ZCL Ballast ConfigurationZigBee ZCL Ballast Configuration
  • ZCL BasicZigBee ZCL Basic
  • ZCL Binary Input BasicZigBee ZCL Binary Input Basic
  • ZCL Binary Output BasicZigBee ZCL Binary Output Basic
  • ZCL Binary Value BasicZigBee ZCL Binary Value Basic
  • ZCL CalendarZigBee ZCL Calendar
  • ZCL Color ControlZigBee ZCL Color Control
  • ZCL CommissioningZigBee ZCL Commissioning
  • ZCL Daily ScheduleZigBee ZCL Daily Schedule
  • ZCL Dehumidification ControlZigBee ZCL Dehumidification Control
  • ZCL Device ManagementZigBee ZCL Device Management
  • ZCL Device Temperature ConfigurationZigBee ZCL Device Temperature Configuration
  • ZCL DiagnosticsZigBee ZCL Diagnostics
  • ZCL DLRCZigBee ZCL DLRC
  • ZCL Door LockZigBee ZCL Door Lock
  • ZCL Electrical MeasurementZigBee ZCL Electrical Measurement
  • ZCL Energy ManagementZigBee ZCL Energy Management
  • ZCL EventsZigBee ZCL Events
  • ZCL Fan ControlZigBee ZCL Fan Control
  • ZCL Flow Meas.ZigBee ZCL Flow Meas.
  • ZCL Generic TunnelZigBee ZCL Generic Tunnel
  • ZCL Green PowerZigBee ZCL Green Power
  • ZCL GroupsZigBee ZCL Groups
  • ZCL IAS ACEZigBee ZCL IAS ACE
  • ZCL IAS WDZigBee ZCL IAS WD
  • ZCL IAS ZoneZigBee ZCL IAS Zone
  • ZCL IdentifyZigBee ZCL Identify
  • ZCL Illuminance Level SensingZigBee ZCL Illuminance Level Sensing
  • ZCL Illuminance Meas.ZigBee ZCL Illuminance Meas.
  • ZCL Keep-AliveZigBee ZCL Keep-Alive
  • ZCL Key EstablishmentZigBee ZCL Key Establishment
  • ZCL Level ControlZigBee ZCL Level Control
  • ZCL MDU PairingZigBee ZCL MDU Pairing
  • ZCL MessagingZigBee ZCL Messaging
  • ZCL Meter IdentificationZigBee ZCL Meter Identification
  • ZCL MeteringZigBee ZCL Metering
  • ZCL Multistate Input BasicZigBee ZCL Multistate Input Basic
  • ZCL Multistate Output BasicZigBee ZCL Multistate Output Basic
  • ZCL Multistate Value BasicZigBee ZCL Multistate Value Basic
  • ZCL Occupancy SensingZigBee ZCL Occupancy Sensing
  • ZCL OnOffZigBee ZCL OnOff
  • ZCL OnOff Switch ConfigurationZigBee ZCL OnOff Switch Configuration
  • ZCL OTAZigBee ZCL OTA
  • ZCL PartitionZigBee ZCL Partition
  • ZCL Poll ControlZigBee ZCL Poll Control
  • ZCL Power ConfigurationZigBee ZCL Power Configuration
  • ZCL Power ProfileZigBee ZCL Power Profile
  • ZCL PrepaymentZigBee ZCL Prepayment
  • ZCL Pressure Meas.ZigBee ZCL Pressure Meas.
  • ZCL PriceZigBee ZCL Price
  • ZCL Pump Configuration and ControlZigBee ZCL Pump Configuration and Control
  • ZCL Relative Humidity Meas.ZigBee ZCL Rel. Humidity Meas.
  • ZCL RSSI LocationZigBee ZCL RSSI Location
  • ZCL ScenesZigBee ZCL Scenes
  • ZCL Shade ConfigurationZigBee ZCL Shade Configuration
  • ZCL Sub-GhzZigBee ZCL Sub-Ghz
  • ZCL Temperature Meas.ZigBee ZCL Temperature Meas.
  • ZCL ThermostatZigBee ZCL Thermostat
  • ZCL Thermostat User Interface ConfigurationZigBee ZCL Thermostat User Interface Configuration
  • ZCL TimeZigBee ZCL Time
  • ZCL TouchlinkZigBee ZCL Touchlink
  • ZCL TunnelingZigBee ZCL Tunneling
  • ZCL Window CoveringZigBee ZCL Window Covering
  • ZCL ZBD ConfigurationZigBee ZCL ZBD Configuration
  • ZEBRAZebra Protocol
  • ZenohEclipse Zenoh Protocol
  • ZEPZigBee Encapsulation Protocol
  • ZigBeeZigBee Network Layer
  • ZigBee APFZigBee Application Framework
  • ZigBee APSZigBee Application Support Layer
  • ZigBee BeaconZigBee Beacon
  • ZigBee Green PowerZigBee Green Power Profile
  • ZigBee IEZigBee IE
  • ZigBee IP BeaconZigBee IP Beacon
  • ZigBee ZCLZigBee Cluster Library
  • ZigBee ZDPZigBee Device Profile
  • ZIOPZipped Inter-ORB Protocol
  • ZIPZone Information Protocol
  • ZIP_FILEZIP File Format
  • ZMTPZeroMQ Message Transport Protocol
  • ZRTPZRTP
  • ZVTZVT Kassenschnittstelle
02

Triage Insights

Explore every Triage processor, the checks it performs and the evidence it produces.

Selection, configuration and packet visibility determine what is evaluated in a particular run. A rule match is an observation, not automatically a diagnosis or confirmed attack.

Processors 45

Every registered processor, grouped by purpose. All processor names are visible below. One qualification-only entry is clearly marked.

Addressing & network control 3

ARP spoofing & address conflicts

Stateful ARP poisoning, IP/MAC conflicts and local-path changes.

Correlates competing MAC claims for an IP address. Detects local and gateway path-flip evidence associated with ARP poisoning. Retains duplicate-address, gratuitous-ARP spoofing, storm and malformed-ARP signals.

An address conflict alone does not prove spoofing. Attribution depends on captured state and path-change evidence.

DHCP conflicts & competing servers

Lease churn and inconsistent address-configuration authorities.

Checks duplicate lease churn. Compares gateway and DNS options. Correlates competing DHCP authority evidence.

Requires visible DHCP exchanges; does not inspect an external IPAM database.

Spanning-tree topology correlation

Bridge/root changes correlated with transport disruption.

Groups STP bridge and root events. Correlates topology-event windows with TCP loss and retransmission signals.

Requires both control-plane and affected traffic visibility; correlation alone does not establish causality.

DNS & encrypted services 5

DNS resolver health

Resolution failures and resolver failover instability.

Detects NXDOMAIN and SERVFAIL spikes. Evaluates resolver failover instability using shared DNS transaction summaries.

Requires complete-capture coverage; encrypted DNS payloads are not automatically visible.

DNS privacy posture

Plaintext DNS, encrypted-DNS indicators and fallback behavior.

Summarizes visible plaintext and encrypted-DNS posture. Correlates bounded same-client privacy-fallback observations.

Traffic observations do not establish organizational policy compliance or reveal encrypted query content.

TLS handshake failures

Incomplete handshakes, fatal alerts and early closure.

ClientHello without an observed ServerHello. Fatal alerts and certificate-related alerts. Early connection closure around the handshake.

Needs complete flow visibility. A missing response can also reflect capture loss or a one-sided capture.

TLS certificate lifecycle

Certificate lifecycle, transparency and revocation signals.

Examines visible certificate lifecycle information. Evaluates SCT/certificate-transparency and OCSP revocation evidence. Correlates interception-risk indicators.

Requires visible certificate/status material; encrypted handshakes can limit coverage. Risk indicators are not proof of interception.

Post-quantum cryptographic posture

Observed key-establishment posture across encrypted protocols.

Summarizes visible key-establishment evidence. Reports protocol-specific visibility limits alongside posture.

A capture-based posture assessment is not a cryptographic certification or a complete endpoint configuration audit.

Transport & application performance 7

TCP connection dossier anomalies

Additional anomaly checks on top-ranked TCP connections.

Evaluates retained connection dossiers for top-ranked TCP connections.

Bounded to selected top-ranked connections with complete flow coverage; not every connection receives dossier analysis.

TCP connection quality

Retransmission burden and lossy, low-throughput connections.

Evaluates retransmission ratios. Identifies connections combining loss indicators and low throughput.

Needs complete flow coverage. Capture loss, asymmetry and endpoint offload affect interpretation.

TCP segment size & offload caveats

Observed segment sizes compared with negotiated MSS.

Compares observed TCP payload length with negotiated maximum segment size. Adds offload caveats to oversized-segment observations.

Large captured segments can be offload artifacts; they do not by themselves prove an on-wire MTU fault.

HTTP/2 & gRPC degradation

Reset storms, retries and latency degradation.

Correlates reset storms and retry behavior. Evaluates latency-collapse signals.

Requires decoded HTTP/2 or gRPC evidence and complete flows; encryption can hide application messages.

QUIC & HTTP/3 path degradation

Handshake retry and fallback instability.

Evaluates handshake retry behavior. Correlates path/fallback instability signals.

Requires complete flow evidence; does not imply access to encrypted HTTP/3 content.

Traffic burst concentration

Concentrated activity across connection sessions.

Groups TCP/UDP activity into bounded sessions. Identifies concentrated bursts in the capture.

Requires complete-capture coverage; a burst does not independently prove congestion or an attack.

Citrix transport quality

Session transport stalls, resets and path changes.

Detects bounded stalls and transport path changes. Identifies resets and refused-listener evidence.

Requires complete flow coverage; transport observations do not expose all desktop or application behavior.

Telecom, VoIP & media 10

DNS / SIP correlation

SIP-related names viewed alongside DNS transactions.

Provides a SIP-name view over the shared DNS transaction summary.

Requires both DNS and SIP with complete flow coverage; optional correlation view.

TLS / SIP correlation

SIP-related transport setup and TLS handshakes.

Provides a SIP-TLS view over shared TLS handshakes and connection summaries.

Requires both TLS and SIP evidence with complete flows; does not decrypt SIP automatically.

SIP signaling state

Call setup failures and transaction/dialog anomalies.

Authentication loops and failure bursts. Missing ACK after a successful INVITE response. INVITE without a response and heavy retransmission.

Requires decoded signaling and complete flows. A partial capture can omit expected responses.

RTP media state

Sequence gaps, timing spikes and one-way media indicators.

Sequence gaps and interarrival-delta spikes. Suspected one-way RTP. SSRC churn within observed media relationships.

Requires complete flow visibility. One-way capture visibility does not prove one-way audio at the endpoint.

VoIP connection quality

Media loss, jitter and directional quality correlation.

RTP jitter, loss and sequence quality. RTCP cumulative-loss observations. One-way media and directional imbalance, correlated with VoIP signals.

Requires complete flows and available media/control observations; does not measure the listener’s subjective audio experience.

VoIP NAT & session path

Negotiated media compared with observed media paths.

Correlates SIP dialogs, SDP media and RTP stream summaries. Adds STUN error signals to session-path findings.

Single-vantage attribution limits are explicit; a capture does not reveal every NAT translation or remote leg.

VoIP full-stack correlation

Voice signaling, media and underlying tunnel/control-plane risks.

Correlates SIP/SDP and RTCP control quality. Includes Diameter, GTP and IPsec/ESP risk signals. Correlates QoS policy mismatch and fragmentation/path-MTU evidence.

Only captured, decoded layers can be correlated; encrypted tunnels do not automatically expose their inner traffic.

Telecom control-plane signals

Control-plane findings grouped across telecom signaling.

Aggregates captured control-plane rule signals. Provides protocol context for telecom investigation.

Coverage depends on available rule signals; listing a protocol does not imply every interface or procedure is evaluated.

Telecom session & mobility state

Session churn, charging failures, rejects and mobility failures.

GTP session/tunnel summaries and keepalive collapse. Diameter charging failures and NAS rejects. LTE attach/release loops, GTPv2 session churn and S1AP/NGAP handover failure chains. TCAP abort observations and abort storms.

Procedure coverage varies by protocol and captured messages; this is not a complete mobile-core conformance test.

Multicast video quality

Multicast membership stability and media delivery.

RTP/RTCP delivery-quality signals. IGMP membership instability. Source and SSRC churn.

Requires the relevant multicast control and media traffic; does not evaluate decoded picture quality.

Security & threat detection 15

Service placement & protocol/port conflicts

Public-address placement and decoded protocol/port mismatches.

Evaluates public-address and service placement. Checks exact decoded HTTP/name-protocol port conflicts.

Requires complete-capture coverage; unusual placement needs site policy context.

Captive portal manipulation indicators

Portal redirects correlated with encrypted delivery.

Correlates captive-portal redirects with same-client encrypted delivery.

Correlation is bounded to captured evidence; campaign indicators are handled by threat intelligence.

Destination-set callback analysis Qualification only

Qualification-only callback and persistent-session ranking.

Ranks callbacks across exact logical destinations at multiple timescales. Examines reconnecting HTTP task/result cadence and sparse persistent sessions.

Qualification only. Listed for registry completeness, not as a generally available diagnostic.

Behavioral C2 beaconing

Periodic callbacks, long connections and high-frequency strobes.

Scores repeated connection-start timing and byte behavior using RITA-aligned statistics. Produces long-connection and high-frequency strobe signals. Applies safeguards for known discovery, signaling and real-time UDP cadence.

Behavioral candidates are not proof of malware. Needs sufficient repeated observations and exact event coverage; queued follow-up processing can finish after initial Triage.

Periodic TCP C2 classifier

Separate periodic-C2 classification over indexed connections.

Evaluates periodic TCP behavior using 30-minute observation windows. Uses exact indexed connection evidence.

Best with captures spanning at least 30 minutes. UDP is unsupported in v1. Availability and capture eligibility are checked; execution is a queued follow-up.

IDS signature scan

Suricata-compatible signature findings in the capture.

Runs the configured IDS security scan on the active capture session. Makes retained alert evidence available for Triage correlation.

Full IDS must be requested. Actual coverage follows the installed, enabled rules and engine capabilities. This catalogue does not claim support for every Suricata rule or publish a live ruleset count.

DNS tunneling

Suspicious DNS query shapes and related security evidence.

Evaluates bounded query-shape behavior. Correlates retained security-scan and rule evidence.

Unusual DNS names can be legitimate; encrypted queries require visible decoded evidence.

Network scans & floods

Capture-wide scan and flood signal correlation.

Correlates primary scan/flood rule findings with connection facts. Includes TCP NULL scan evidence when present.

Results depend on captured traffic and evaluated rules; benign discovery and authorized scanning need analyst context.

East-west lateral movement

Host-traversal correlation across internal connections.

Correlates SMB, RDP and WinRM host traversal. Uses related authentication and directory protocol context.

Requires complete-capture coverage. Administrative activity can resemble lateral movement.

Authentication & identity control plane

Authentication failures, fallback and related service outcomes.

Classifies Kerberos, LDAP and RADIUS failures. Correlates DNS discovery, NTLM fallback and public-peer placement. Associates SMB/LDAP outcomes with identity evidence.

Requires the relevant visible protocol facts and processor availability; does not replace domain-controller audit logs.

JA3 / JA4 intelligence matching

Connection fingerprints correlated with local intelligence.

Evaluates available JA3/JA4-family fingerprints. Matches fingerprints against local intelligence signatures.

Depends on the local intelligence set and observable handshake fields. A shared fingerprint does not uniquely identify malware.

Proxy, VPN & covert-channel indicators

Explicit tunnel protocols and suspicious opaque-channel behavior.

Identifies exact decoded proxy/VPN tunnel protocols. Evaluates suspicious encrypted-channel behavior using optional connection metrics.

A VPN or proxy is not inherently malicious; behavioral coverage requires the optional metrics.

FTP / SMTP exfiltration indicators

Outbound upload and authenticated mail-submission patterns.

Detects FTP upload to external hosts. Detects SMTP authenticated submission to external hosts.

These patterns can be legitimate. Authorization and data sensitivity require context outside the capture.

Suspicious web delivery chains

Visible delivery stages followed by encrypted connections.

Correlates archive/MSI/PHP delivery or literal-IP POST stages. Links visible stages to encrypted follow-on traffic.

Requires HTTP and TLS evidence plus complete flows. Temporal association does not independently establish payload execution.

DNS / SNI / HTTP authority consistency

Name and authority inconsistencies on exact connections.

Compares captured DNS, TLS SNI and HTTP authority facts. Correlates inconsistencies within connection identity evidence.

Legitimate hosting and proxy arrangements can differ; encrypted or missing authority fields limit evaluation.

Wireless, provider networks & OT 3

Wi-Fi quality & control-plane risks

RF quality, contention, authentication and roaming issues.

RF quality and channel-contention observations. Authentication, disconnect and roaming behavior. Rogue/probe risk indicators.

Requires complete-capture coverage and appropriate wireless/radio metadata. Ethernet-only captures do not reveal RF conditions.

Provider network path integrity

Encapsulation, routing-session and label-stack path evidence.

VXLAN length consistency. BGP TTL and session progression. SR/MPLS label stacks and MPLS path-MTU evidence.

Requires complete flows and the relevant primary protocol summaries; does not reconstruct unseen network hops.

Industrial & robotics protocol analysis

Protocol lifecycle/error evidence and industrial-abuse indicators.

Bounded protocol lifecycle and error analysis. BACnet inventory observations. Industrial-protocol abuse detection. Optional process-aware OTSM verification when a process mapping is supplied.

Checks differ by protocol. Process-aware verification requires the optional mapping; packet visibility alone cannot establish physical-process safety.

Capture context 2

Capture topology & packet comments

Multi-leg, proxy and tunnel capture caveats.

Examines packet comments for endpoint proxy or tunnel capture topology. Preserves multi-leg capture caveats for downstream investigation.

Requires available capture comments; does not infer undocumented capture topology.

Host & service identity

Capture-local names associated with connections.

Collects name-resolution, TLS and HTTP identity observations. Associates observed names with exact connection evidence.

Names are observations from this capture, not verified asset ownership.

Packet-level checks 483

Explore automatic checks for protocol behavior, performance issues and security indicators, including optional traffic identification. Browse by protocol or investigation area.

Addressing & network paths 41ARP Storm · BFD Peer Reports Session Down · BGP Notification Message
  • ARP Storm

    Rapid or repeated ARP packets from one or multiple senders indicate a broadcast/ARP storm that can saturate the local segment and disrupt layer-2 connectivity, requiring immediate source isolation.

  • BFD Peer Reports Session Down

    A BFD control packet reports the transmitting peer's session state as Down. This is exact session-state evidence, but it can represent an unestablished or failed adjacency and is not by itself proof that traffic failed over.

  • BGP Notification Message

    BGP session received a Notification message (type 3), denoting a fatal protocol error that likely caused session termination or route withdrawal.

  • DHCP DECLINE Message

    DHCP client transmitted a DECLINE (message type 4), rejecting an offered IP due to duplicate-address detection and indicating an address conflict or stale DHCP lease.

  • DHCP Failure (APIPA Assigned)

    Host IP within 169.254.0.0/16 indicates DHCP negotiation failed and the client assigned an APIPA address, requiring DHCP server, relay, and network path verification.

  • DHCP NAK from Server

    DHCP server issued a NAK (message type 6), rejecting the client's request and requiring the client to restart lease acquisition due to invalid or conflicting state.

  • DHCP Relay (Option 82)

    Flags DHCP relay agent information (Option 82) to surface helper-induced latency or scope issues.

  • DHCPv6 ODoH Configuration Advertised

    A DHCPv6 DNR payload carrying svc_params.odohconfig exposes oblivious DoH bootstrap material even though the current dissector registers that service parameter under the shared svc_params namespace.

  • Gratuitous ARP Request

    Gratuitous ARP request or duplicate-address event with identical source and target IPv4 indicates a host announcing or probing its own IP, commonly seen during failover or address conflict resolution.

  • Gratuitous or Duplicate ARP

    A gratuitous ARP or duplicate-address-detected event shows two hosts claiming the same IPv4 address or a failover announcement, so verify MAC-to-IP mappings and recent failover activity.

  • HSRP State Transition

    HSRP packet reports a state outside common stable values, indicating a router virtual IP role change or HSRP topology event that may affect forwarding.

  • ICMP Affecting TCP Flow

    ICMP errors observed in packets associated with a TCP flow (excluding fragmentation-needed) indicate delivery or filtering issues impacting that TCP connection and require route, firewall, or endpoint checks.

  • ICMP Destination Unreachable

    ICMP type 3 destination-unreachable message indicates the packet could not be delivered due to routing or filtering for the reported protocol/port and should guide reachability troubleshooting.

  • ICMP Echo No Reply

    ICMP echo request flagged as response not found indicates probes are not being answered, suggesting reachability loss, filtering, or an unresponsive target.

  • ICMP Error Indicators

    ICMP error or time-exceeded messages observed indicate delivery failures or TTL expiration that require investigation of routing, filtering, or endpoint reachability.

  • ICMP Fragmentation Needed

    ICMP Destination Unreachable code 4 (fragmentation needed) signals a packet exceeded the path MTU and the sender must reduce packet size or enable appropriate fragmentation handling.

  • ICMP Host Unreachable

    Flags ICMP Host Unreachable (Type 3 Code 1), indicating the destination host cannot be reached.

  • ICMP Network Unreachable

    Flags ICMP Network Unreachable (Type 3 Code 0), indicating no route to the destination network.

  • ICMP Parameter Problem

    ICMP Type 12 parameter-problem indicates a forwarding device detected a malformed header or unsupported option and the offending packet fields should be inspected.

  • ICMP Port Unreachable

    Flags ICMP Port Unreachable (Type 3 Code 3), indicating UDP service not running or blocked.

  • ICMP Redirect

    Highlights ICMP Redirect messages (Type 5) indicating suboptimal routing—router informs host of a better next hop.

  • ICMP Redirect Message

    ICMP code 5 redirect observed, indicating a gateway instructing the source to use an alternate next-hop and changing the route for the flow in question.

  • ICMP Source Quench

    ICMP Source Quench (type 4) indicates a downstream device requested the sender to slow transmission due to congestion, pointing to transient or persistent bandwidth pressure.

  • ICMP Time-Exceeded TTL=1

    ICMP Time Exceeded with IP TTL equal to 1 likely corresponds to a traceroute-style probe where an intermediate router expired the TTL and sent the response.

  • ICMPv6 Packet Too Big

    ICMPv6 Packet Too Big (type 2) indicates a forwarded packet exceeded the next hop MTU and the sender must reduce packet size or adjust MSS/fragmentation behavior.

  • ICMPv6 Redirect Message

    ICMPv6 redirect (type 137) shows a router directing the host to a different next-hop for a destination and may indicate on-link optimization or route updates.

  • Infrastructure Checksum Failures

    One or more link/network/transport checksum validations failed (CDP/EDP/IP/TCP/ICMP/MSTP), indicating capture corruption, offload inconsistencies, or faulty network hardware.

  • IPv6 Neighbor Advertisement

    ICMPv6 Neighbor Advertisement (type 136) indicates a host announcing or updating its IPv6-to-link-layer mapping and should be used to validate neighbor resolution consistency.

  • IPv6 Router Advertisement

    ICMPv6 Router Advertisement (type 134) advertises prefixes, MTU, and router information used by hosts for IPv6 autoconfiguration and default route selection.

  • IPv6 Router Solicitation

    ICMPv6 Router Solicitation (type 133) shows a host requesting routers on-link to solicit advertisements for IPv6 autoconfiguration and router discovery.

  • Large ICMP Payload

    ICMP packet with payload over 100 bytes indicates oversized pings used for MTU discovery or probing and may be used for active reconnaissance or stress-testing.

  • Malformed ARP Packet

    ARP frame contains nonstandard opcode, hardware/protocol type, or size values, suggesting a malformed or crafted ARP packet that may indicate misconfiguration or network reconnaissance.

  • Multicast High TTL

    Local multicast uses an unexpected TTL, excluding routing protocols and standard mDNS TTL 255. Check the protocol's TTL requirements before attributing a configuration problem.

  • OSPF Topology Update

    Observed an OSPF message other than Hello (e.g., LS Update/LSReq/LSAck), typically indicating topology changes, LSDB updates, or adjacency events.

  • STP High Root Path Cost

    Root path cost ≥500 indicates a long or low-bandwidth path to the root bridge that may slow convergence and impact forwarding performance for affected VLANs.

  • STP Non-Default Timers

    BPDU contains hello, forward, or max_age values different from 2/15/20 seconds, showing altered STP timers that change convergence characteristics and should be reviewed against policy.

  • STP Non-Default Timers/Cost

    BPDU carries hello/forward/max_age timers outside 2/15/20 or root path cost ≥500, indicating customized STP timers or a long root path that will affect convergence behavior.

  • STP Root Priority Nonstandard

    Reported STP root priority >32768 indicates a non-default root election or altered bridge priority that can change spanning-tree topology and should be validated against intended design.

  • STP Topology-Change Flag

    BPDU carries the topology-change (TC) flag set, indicating a recent topology modification and that affected ports will transition forwarding states.

  • STP Type-Change BPDU

    BPDU with type 0x80 observed, indicating a specialized STP type-change event that signals topology change handling is required.

  • Unusual IPv4 TTL Range (Initial TTL Unknown)

    The observed TTL falls outside common endpoint defaults, but the initial TTL is unknown so hop count cannot be inferred reliably from this packet alone.

Authentication & access 37802.1X EAP Failure · 802.1X EAPOL Key · AD Anonymous NTLM Authentication Attempt
  • 802.1X EAP Failure

    EAP packet with code 4 indicates an authentication failure in the 802.1X exchange, which typically results in port denial or reauthentication.

  • 802.1X EAPOL Key

    Marks 802.1X EAPOL key exchanges used by WPA/WPA2/WPA3 authentication; repeated early key messages without completion indicate wireless association/authentication trouble.

  • AD Anonymous NTLM Authentication Attempt

    Highlights NTLM authentication using an explicit anonymous or NULL username; correlate the following SMB status before deciding whether access succeeded.

  • AD GPO Directory Change Observed

    Highlights creation of a GPO directory object or modification of a GPO link as a bounded SYSVOL-correlation candidate; the directory operation alone does not prove malicious policy or endpoint execution.

  • AD Kerberos Password Expired Response

    Highlights Kerberos error 23, which states that the principal password has expired and explains why the authentication exchange failed.

  • AD Kerberos RC4 AS Request Observed

    Highlights an AS request carrying RC4 enctype 23 as an investigation pivot; packets do not reveal whether the client used a password, NT hash, or another credential source.

  • AD Kerberos SMB Service Authentication Observed

    Highlights a Kerberos AP request carried in SMB session setup; absence of a nearby KDC exchange is an investigation pivot but does not prove pass-the-ticket activity.

  • AD Kerberos TGT Revoked Response

    Highlights Kerberos error 20, which shows that the KDC rejected the presented TGT; packet data alone does not prove that the ticket was forged.

  • AD LDAP NTLM Authentication Observed

    Highlights an NTLM authenticate message carried by LDAP as a bounded cross-flow correlation candidate; ordinary direct LDAP authentication remains possible.

  • AD NTLMv1 Authentication Response Observed

    Highlights an NTLM authenticate message with a 24-byte NT response and no NTLMv2 response field. Correlate the server response before claiming authentication success.

  • AD Privileged NTLM Authentication Observed

    Highlights NTLM authentication as Administrator as an investigation pivot; it does not distinguish a password from pass-the-hash or prove remote execution.

  • AD RC4 CIFS Service Ticket Observed

    Highlights an RC4-encrypted CIFS Kerberos service ticket as an investigation pivot; packet data alone does not prove a forged golden or silver ticket.

  • AD RPC Endpoint Mapper Interface Observed

    Highlights a bind to the RPC endpoint-mapper interface as a useful DCE/RPC pivot; this common administrative exchange does not prove enumeration or coercion.

  • AD SAMR Account or Group Write Observed

    Highlights SAMR account creation or group-membership write methods as a bounded correlation candidate; the method alone does not prove success or malicious persistence.

  • AD Unsigned LDAP Simple Bind Observed

    Highlights a simple LDAP bind sent over cleartext TCP/389. A successful response proves that the directory accepted the bind, but does not make the activity malicious.

  • Authentication

    PotatoFrames Wi-Fi frame taxonomy marker for Authentication.

  • Authentication (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Authentication (Retry).

  • Diameter Auth Failure

    Diameter authentication or subscriber-state signaling returns an explicit non-success result and should be treated as a real auth-chain failure.

  • Diameter Authentication Failure

    Diameter message with error flag and Result-Code AVP (code 268) indicates an authentication or authorization failure returned by the server.

  • Diameter Subscriber-State/Auth Traffic

    Diameter subscriber-state and authentication command traffic indicates auth/update/cancel/purge activity that should be counted and checked for churn or repetition.

  • EAP

    PotatoFrames Wi-Fi frame taxonomy marker for EAP.

  • EAPOL

    PotatoFrames Wi-Fi frame taxonomy marker for EAPOL.

  • EAPOL

    PotatoFrames Wi-Fi frame taxonomy marker for EAPOL.

  • EAPOL 4-Way Handshake M1

    Highlights WPA/RSN 4-way handshake message 1 from authenticator to supplicant; repeated M1 frames are useful anchors for AP retry or supplicant response analysis.

  • EAPOL 4-Way Handshake M2

    Highlights WPA/RSN 4-way handshake message 2 from supplicant to authenticator; repeated M1/M2 pairs without M3/M4 point to key installation or policy mismatch failures.

  • EAPOL 4-Way Handshake M3

    Highlights WPA/RSN 4-way handshake message 3 carrying key installation progress; its absence after repeated M1/M2 pairs is a strong wireless authentication hotspot.

  • EAPOL 4-Way Handshake M4

    Highlights WPA/RSN 4-way handshake message 4, the completion marker for the pairwise key exchange.

  • Kerberos Authentication Traffic

    Kerberos protocol exchanges indicate ticket requests and responses and should be examined for replay attempts, repeated failures, or atypical principal usage.

  • LDAP Error Response

    LDAP operation returned a non-zero resultCode, indicating the request failed (authentication, search, modify, etc.) and requires troubleshooting.

  • RADIUS Access-Reject

    RADIUS server returned Access-Reject (code 3), indicating authentication failure or explicit credential rejection for the authentication attempt.

  • RADIUS Access-Request Retransmission

    decoder correlated this Access-Request with an earlier request carrying the same RADIUS identifier and request authenticator. This is exact retry evidence, but the capture alone may not distinguish a lost request, lost response, slow AAA server, or capture-path omission.

  • RPC Null Authentication

    RPC request uses AUTH_NULL (authentication flavor 0). This is normal for some discovery and NFS-related procedures; treat it as inventory unless an unauthorized sensitive operation is independently established.

  • SIP Authentication Challenge

    SIP 401 or 407 responses requesting authentication, indicating credential-based challenge/response during signaling.

  • SMTP AUTH Command

    SMTP AUTH command observed; verify whether the session is encrypted because credentials may be transmitted in cleartext.

  • VNC Authentication Exchange

    VNC authentication response detected, indicating an attempted remote desktop authentication that may reveal the authentication method or weak credential exchange.

  • Wi-Fi Auth/Association Failure

    Authentication or association status codes indicate client onboarding failures at the WLAN control plane.

  • Wi-Fi EAP Failure

    EAP failure events indicate rejected 802.1X/WPA enterprise authentication attempts.

DNS & name resolution 25DDR Discovery Query · DHCP DNS Resolver Advertisement · DHCPv6 Encrypted DNS Advertisement
  • DDR Discovery Query

    Queries for _dns.resolver.arpa indicate Designated Resolver Discovery and help correlate a client with encrypted-resolver bootstrap behavior.

  • DHCP DNS Resolver Advertisement

    DHCP option 6 exposes IPv4 recursive resolvers advertised by the network and helps explain endpoint DNS configuration without visible resolver traffic.

  • DHCPv6 Encrypted DNS Advertisement

    DHCPv6 DNR options advertise network-designated encrypted resolvers and provide resolver context even when no plaintext DNS packets are present.

  • DNS AAAA Records

    DNS AAAA queries or responses indicate IPv6 name resolution activity useful for validating dual-stack behavior and IPv6 reachability.

  • DNS AXFR Query

    AXFR queries request a full DNS zone transfer and must only be allowed from trusted secondary servers to prevent disclosure of zone data.

  • DNS Format Error Response

    Highlights DNS FORMERR responses, often seen when resolvers reject malformed or unsupported probe payloads.

  • DNS IXFR Query

    IXFR queries request incremental zone transfers and should originate only from authorized secondaries to avoid unintended exposure of zone changes.

  • DNS over HTTPS Request

    HTTP requests for the standard DoH endpoint indicate encrypted DNS over HTTPS and explain why plaintext DNS queries may be absent.

  • DNS over QUIC Session

    QUIC sessions on UDP 853 indicate encrypted DNS over QUIC and are useful when resolver usage is visible but DNS payloads are protected.

  • DNS over TCP (No TLS)

    DNS carried over plaintext TCP without TLS can indicate zone transfers, large responses, or legacy resolver behavior that exposes more of the transaction to inspection.

  • DNS over TLS Session

    TLS sessions on TCP 853 indicate encrypted DNS transport and explain why the DNS tab may lack plaintext query visibility.

  • DNS Queries Lacking Answers

    DNS queries that return no answers (and are not PTR lookups) often reflect unresolved requests, active scanning, or monitoring and should be correlated with client behavior.

  • DNS Response No Answers

    DNS replies with zero answer records and an NOERROR code indicate unresolved names, filtering, or missing authoritative data that merit resolver troubleshooting.

  • DNS Retransmission

    Packets flagged as DNS retransmissions point to packet loss, timeouts, or overloaded resolvers and should be correlated with network loss metrics and server load.

  • DNS Retransmitted Query

    A retransmitted DNS query indicates retry behavior due to missing responses or perceived timeouts and should be examined alongside client retry patterns and network conditions.

  • DNS Retransmitted Response

    Retransmitted DNS responses suggest delayed or duplicate answers caused by network instability or server retransmit logic and require path and server correlation.

  • DNS Zone Transfer Indicators

    AXFR/IXFR queries or DNS opcode 4 indicate potential zone-transfer activity capable of exposing entire zone contents and should be blocked or validated against authorized servers.

  • Excessively Long DNS Query

    Unicast DNS requests with names of 50 bytes or more (non-PTR) are a low-confidence observation for follow-up; ordinary cloud hostnames can be this long, so tunneling requires repeated high-entropy query-shape or detector evidence.

  • High DNS Answer Count

    DNS responses containing more than seven answer records can indicate CDN/load-balanced answers, DNS-based load distribution, or potential amplification scenarios that deserve scrutiny.

  • IPv4 DNS Root Server Traffic

    Packets involving known IPv4 root server addresses reveal direct root-level resolution activity or misconfigured resolvers bypassing local caches and should be validated.

  • IPv6 DNS Root Server Traffic

    Traffic to known IPv6 root server addresses indicates direct root resolution or IPv6-enabled resolver behavior that may bypass hierarchical caching and merits review.

  • IPv6 RA DNS Search List

    Router Advertisements carrying DNSSL options reveal advertised search domains that can explain resolver behavior and suffix expansion.

  • IPv6 RA Recursive DNS Server

    Router Advertisements carrying RDNSS options expose advertised recursive resolvers and help explain client DNS configuration without DHCP.

  • Outbound DNS Queries

    DNS questions with recursion desired and no response yet show active client resolution attempts and help enumerate domains requested by hosts.

  • Slow DNS Transactions

    DNS queries taking one second or longer reveal resolver latency or upstream delays and should be investigated for network path or server performance issues.

Encryption & secure connections 19IKE Notify Payload Present · IKE/IPsec Negotiation · Possible Tor Node Connection
  • IKE Notify Payload Present

    An IKE notify payload is present. Notify payloads include normal NAT-detection and capability feedback, so this is context rather than failure evidence by itself.

  • IKE/IPsec Negotiation

    ISAKMP/IKE traffic or UDP 500/4500 exchanges identify VPN tunnel negotiation and should be checked for failed handshakes, rekeys, or NAT traversal fallbacks.

  • Possible Tor Node Connection

    A short TLS ClientHello with a www/.com SNI shape resembles an older Tor fingerprint. Treat this as weak triage context, not confirmation of Tor traffic.

  • TLS 1.2 Negotiated

    Handshake selected TLS 1.2 without advertising TLS 1.3 supported_version, indicating the session will use TLS 1.2 and may lack TLS 1.3 features.

  • TLS 1.3 Negotiated

    Handshake selected TLS 1.3, indicating the session uses the modern TLS 1.3 handshake and associated cryptographic semantics.

  • TLS Alert Not CloseNotify

    TLS alert message other than CloseNotify was sent, indicating an error or abnormal termination that should be inspected by alert description code.

  • TLS ClientHello Message

    Packet contains a TLS ClientHello, exposing the client's offered protocol versions, cipher suites, and extensions used to negotiate the session.

  • TLS Close Notify

    TLS alert with description 0 (close_notify) indicates an orderly TLS session shutdown from the peer.

  • TLS Fatal Alert

    TLS peer sent a fatal alert (level 2), indicating the connection was aborted due to a protocol or handshake error that terminated the session.

  • TLS JA3 Client Fingerprint

    Client Hello includes a JA3 fingerprint, enabling client TLS fingerprinting and correlation of client TLS stacks or automated agents.

  • TLS JA3S Server Fingerprint

    Server Hello contains a JA3S fingerprint, providing a server-side TLS fingerprint useful for identifying server TLS stacks or middlebox behavior.

  • TLS Missing Certificate Chain

    The server Certificate message contains only the leaf certificate length equal to the total certificates_length, indicating intermediates were not sent and client chain validation may fail.

  • TLS Non-Close Alert Record

    A TLS alert record with a non-zero description was transmitted, indicating an in-band TLS error that likely affected or terminated the session.

  • TLS Non-Zero Alert

    A TLS alert with a non-zero description was emitted, signaling an error condition that requires inspection of the handshake or session state.

  • TLS Renegotiation Extension Present

    Renegotiation info extension appears in the handshake, indicating support for TLS renegotiation which can have security and compatibility implications.

  • TLS ServerHello Message

    Packet contains a TLS ServerHello, revealing the negotiated protocol version, selected cipher suite, and any server-chosen extensions.

  • TLS1.3 Offered Legacy ClientHello

    ClientHello presents TLS 1.3 support via supported_versions while using the legacy_version field, indicating a TLS1.3-capable ClientHello pattern to monitor for 1.3 negotiations.

  • TLS1.3 Offered, TLS1.2 Selected

    Server responded selecting TLS 1.2 despite the client offering TLS 1.3, showing the server does not negotiate TLS 1.3 and may be limited or downgraded.

  • Undecoded TLS Ciphersuite

    Handshake contains a ciphersuite value that the dissector could not decode, which may indicate an unsupported, malformed or proprietary cipher suite.

Mobile networks & telecom 73CAMEL Abort Reason · CAMEL Duplicate Session · CAMEL Error Code Present
  • CAMEL Abort Reason

    A CAMEL abort reason indicates abnormal termination of the CAMEL transaction.

  • CAMEL Duplicate Session

    A duplicate CAMEL session marker indicates retry or duplicate service-logic activity that may reflect upstream churn.

  • CAMEL Error Code Present

    A CAMEL local error code indicates explicit service-logic or dialogue failure.

  • CAMEL Problem Present

    A CAMEL problem code indicates protocol or service-logic trouble in the CAMEL transaction.

  • CAMEL Reject

    A CAMEL Reject indicates rejected service-logic or component processing.

  • CAMEL Return Error

    A CAMEL ReturnError indicates service-logic or control-plane transaction failure.

  • Diameter Answer Error

    Diameter Answer with error flag set indicates the request failed due to protocol, AVP, or authorization error returned by the peer.

  • Diameter Capability Exchange Failure

    A Capability-Exchange-Answer with a non-success Result-Code indicates peer capability or application support mismatch.

  • Diameter Command-Level 3002

    Diameter answer returned exact command-level Result-Code 3002, which is a distinct failure cohort in the telco corpus and should be surfaced separately from generic non-success results.

  • Diameter Command-Level 4010

    Diameter answer returned exact command-level Result-Code 4010, which is a narrow high-signal charging/policy failure cohort in the telco corpus.

  • Diameter Command-Level Failure

    A Diameter credit-control answer with a non-success command-level Result-Code indicates an explicit control-plane failure that should be surfaced independently of nested MSCC or transport-only issues.

  • Diameter Credit-Control Answer Failure

    A Credit-Control-Answer with a non-success Result-Code indicates charging or policy control failure for the subscriber session.

  • Diameter Device-Watchdog

    Diameter Device-Watchdog traffic is normal ambient keepalive traffic and should be counted but collapsed during first-pass triage.

  • Diameter Experimental Result

    Presence of an Experimental-Result AVP indicates vendor-specific error or status information that requires vendor-specific interpretation.

  • Diameter Nested MSCC 4012

    Diameter credit-control answer contains exact nested MSCC Result-Code 4012, which should remain distinct from other nested charging failures.

  • Diameter Nested MSCC 5012

    Diameter credit-control answer contains exact nested MSCC Result-Code 5012, which is a separate high-value charging failure cohort in the telco corpus.

  • Diameter Nested MSCC Failure

    A Diameter credit-control answer with a successful outer command but failing nested MSCC result indicates subscriber charging failure hidden inside a nominal response.

  • Diameter Nested MSCC Hidden Behind 2001

    A Diameter credit-control answer returns outer success 2001 while nested MSCC still fails, which is a high-signal hidden charging failure.

  • Diameter Non-Success Result-Code

    Diameter answer with a non-success Result-Code indicates an explicit control-plane failure returned by the peer.

  • Diameter Retransmission

    Diameter message with the T-bit set indicates retransmission of a request due to missing response or perceived loss.

  • Diameter Session Rejection

    Diameter response with Result-Code AVP and error flag set indicates session establishment was explicitly rejected by the server.

  • Diameter Session Timeout

    Diameter message contains a Session-Timeout AVP, indicating the configured session lifetime after which the session will be terminated.

  • Diameter Transport Retransmission Overlap

    Diameter traffic coinciding with TCP retransmission indicates transport impairment affecting control-plane exchange reliability.

  • Diameter Transport Zero Window Overlap

    Diameter traffic coinciding with TCP zero-window behavior indicates receiver backpressure on the charging or policy connection.

  • Diameter/NGAP 5QI Present

    An NGAP 5QI descriptor or Diameter QoS subscription blob is present, indicating bearer QoS context that should be compared with observed service quality.

  • GTP Bearer ID Present

    A GTP bearer identifier is present, allowing bearer-specific correlation for session setup and QoS troubleshooting.

  • GTP/QoS QCI Present

    A GTP QoS QCI value is present, providing bearer-level QoS context that should be checked for degradation or mismatch against the expected policy.

  • GTPv2 Mandatory IE Incorrect

    GTPv2 cause 69 indicates a malformed or unacceptable mandatory information element during session or bearer procedures.

  • GTPv2 Network Failure

    GTPv2 cause 72 indicates network failure during session establishment or bearer procedures.

  • GTPv2 Non-Accept Cause

    GTPv2 messages with cause values >=64 indicating non-acceptance or failure in session/bearer procedures needing core diagnostics.

  • M3UA Error Code Present

    An M3UA Error Code indicates explicit control-plane failure signaled by the M3UA peer.

  • M3UA Status Present

    An M3UA status message indicates state transition or degraded signaling availability that may explain higher-layer transaction failures.

  • M3UA Unavailability Cause

    An M3UA Unavailability Cause indicates unavailable application server or signaling destination state.

  • NAS 5GS Registration Reject PLMN Not Allowed

    5GS mobility-management cause 11 indicates the UE is rejected at registration because the PLMN is not allowed.

  • NAS EPS Attach Reject Network Failure

    EPS mobility-management cause 17 indicates attach or service procedures failed due to network-side failure.

  • NAS EPS PDN Collision With Network Request

    EPS session-management cause 56 indicates the UE PDN request collided with a network-initiated request, which commonly appears in detach/reattach churn loops.

  • NAS EPS PDN Reject Network Failure

    EPS session-management cause 38 indicates network failure during PDN connectivity establishment.

  • NAS EPS PDN Reject Request Rejected

    EPS session-management cause 31 indicates the PDN connectivity request was rejected without a more specific acceptance cause.

  • NGAP Cause Present

    NGAP messages containing a Cause IE which identifies RAN/AMF-level failure reasons to correlate with UE or session impact.

  • NGAP Handover Cancel

    NGAP HandoverCancel indicates handover preparation did not complete and the relocation attempt was cancelled.

  • NGAP Handover Preparation Failure

    NGAP HandoverPreparationFailure is an exact mobility failure selector and should be kept distinct from later cancel or release cleanup.

  • NGAP Handover Required

    NGAP HandoverRequired marks the start of a mobility handover sequence and is useful as a baseline event for handover outcome correlation.

  • NGAP Path Switch Request

    NGAP PathSwitchRequest is part of a successful mobility completion path and should be treated as contextual signaling, not a failure.

  • NGAP Path Switch Request Acknowledge

    NGAP PathSwitchRequestAcknowledge is a positive handover progression signal and should be down-weighted outside sequence correlation.

  • NGAP QoS Flow Identifier Present

    An NGAP QoS flow identifier is present, indicating bearer-specific QoS state worth checking for degradation or mapping issues.

  • PFCP Cause Present

    A PFCP Cause field is present, indicating a session-management response that should be checked for explicit failure or non-accept status.

  • PFCP Heartbeat

    PFCP heartbeat request/response traffic is normal ambient session liveness signaling and should be collapsed in summaries unless asymmetric or failing.

  • PFCP Non-Success Cause

    PFCP non-success causes indicate session establishment, modification, or deletion failure and should be treated as explicit control-plane failure evidence.

  • QoS Data

    PotatoFrames Wi-Fi frame taxonomy marker for QoS Data.

  • QoS Data (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for QoS Data (Retry).

  • QoS Null Data

    PotatoFrames Wi-Fi frame taxonomy marker for QoS Null Data.

  • QoS Null Data (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for QoS Null Data (Retry).

  • S1AP Cause Present

    S1AP messages including a Cause field that identifies eNodeB/MME error conditions affecting handover, release, or paging flows.

  • S1AP Handover Failure

    S1AP HandoverFailure indicates an explicit mobility procedure failure for the affected UE context.

  • S1AP Handover Preparation Failure

    S1AP HandoverPreparationFailure indicates the relocation attempt failed before completion.

  • SCCP Error Cause

    An SCCP Error Cause indicates explicit SCCP-level failure for the current message or dialogue.

  • SCCP Reassembly Error

    SCCP message reassembly error indicates fragmented signaling data could not be reassembled cleanly.

  • SCCP Refusal Cause

    An SCCP Refusal Cause indicates the message or connection was refused by the remote side or network.

  • SCCP Release Cause

    An SCCP Release Cause indicates explicit connection or transaction release with a cause code.

  • SCCP Reset Cause

    An SCCP Reset Cause indicates a reset of the SCCP connection or transaction context.

  • SCCP Unexpected Class

    Unexpected SCCP class for the message type indicates malformed or incompatible signaling behavior.

  • SCTP ABORT Chunk

    SCTP ABORT chunk observed, indicating the peer abruptly terminated the association.

  • SCTP ERROR Chunk

    SCTP ERROR chunk present, indicating a protocol-level error during association negotiation or data transfer.

  • SCTP Heartbeat

    SCTP HEARTBEAT and HEARTBEAT ACK chunks are ambient path-liveness signaling and should be collapsed unless they dominate the capture or become asymmetric.

  • SCTP Retransmission

    Detected SCTP retransmission events, indicating packet loss, congestion, or path instability affecting the association.

  • SCTP SACK with Gaps

    SCTP SACK with gap blocks indicates selective acknowledgments due to out-of-order delivery or partial loss on the path.

  • TCAP Abort

    A TCAP Abort indicates the dialogue was terminated abnormally.

  • TCAP Dialogue Abort

    A TCAP DialogueAbort indicates explicit abnormal dialogue termination and should be surfaced separately from generic TCAP problems.

  • TCAP Duplicate Session

    A duplicated TCAP session marker indicates retry or duplicate dialogue activity that can reflect churn or replay of transaction state.

  • TCAP Problem Present

    A TCAP problem code indicates protocol or application transaction trouble in the dialogue.

  • TCAP Reject

    A TCAP Reject indicates a rejected component or dialogue problem.

  • TCAP Return Error

    A TCAP ReturnError indicates application-level transaction failure in the TCAP dialogue.

  • Unknown Diameter Command

    Diameter request uses an unknown or unsupported command code, indicating a mismatched application or misconfigured peer.

Other traffic & capture observations 26Capture Timestamp Gap >1day · Capture Timestamp Gap >1hr · Capture Timestamp Gap >60s
  • Capture Timestamp Gap >1day

    Consecutive frames in capture order are separated by at least one day. Treat this as capture chronology or stitching context, never as a flow outage or performance failure by itself.

  • Capture Timestamp Gap >1hr

    Consecutive frames in capture order are separated by at least one hour. This can result from capture rotation, concatenation, or inactive collection and is not per-flow outage evidence.

  • Capture Timestamp Gap >60s

    Consecutive frames in capture order are separated by at least 60 seconds. This is capture-wide chronology context only and does not prove per-flow silence, latency, an outage, or packet loss.

  • Client Using APIPA Address

    Packet sourced from 169.254.0.0/16 indicates the host self-assigned an APIPA address after DHCP failure, signaling DHCP server or relay reachability problems.

  • Dissector Malformed Packet

    Packet flagged as malformed by protocol dissectors, indicating truncated or corrupted protocol structures that can break session processing.

  • Early Capture Timestamps

    Packet timestamp is earlier than Apr 1, 1970. Absolute times may be synthetic or use an unset capture clock; this does not establish packet corruption.

  • Early Packet Truncation

    Captured length smaller than the original length on early frames with original length >64 bytes indicates packet slicing/truncation occurred during capture.

  • ESP Payload Present

    ESP traffic indicates encrypted tunnel payloads that should be checked for replay, sequence, or negotiation instability when paired with VPN setup signals.

  • Ethernet Preamble Capture

    A giant frame contains repeated 0x55 preamble bytes, supporting bounded follow-up for a possible collision or framing artifact.

  • Frame Comment Present

    Packet contains an analyst-supplied frame comment, signaling prior annotations or notes relevant to the investigation.

  • Inter-packet Gap >250ms

    Capture-wide timing context only; consecutive-frame gaps are not flow-specific evidence of latency or jitter.

  • Inter-packet Gap >500ms

    Capture-wide timing context only; consecutive-frame gaps are not flow-specific evidence of latency or jitter.

  • IP Evil Bit Set

    Reserved 'evil' bit set in the IP header indicates nonstandard packet marking often used for experimental or malicious signaling.

  • IP Fragment Overlap

    Fragments overlap or conflict during IP reassembly, a typical indicator of evasion techniques or corrupted fragmentation that invalidates payload reconstruction.

  • IP Fragmentation Error

    IP fragment error detected during reassembly, indicating missing or invalid fragments that will prevent successful payload reconstruction.

  • IP Low TTL (Possible Loop)

    IP TTL below five for a unicast destination suggests the packet is close to TTL expiry or may be caught in a routing loop requiring path validation.

  • IP MF and DF Both Set

    Both More-Fragments and Don't-Fragment flags are set simultaneously, an inconsistent combination that signals malformed or manipulated packets.

  • IP Options Present

    IP header length exceeds 20 bytes, revealing options that can affect routing, processing, or indicate tunneling and diagnostic data.

  • IPv4 DF Set With Offset

    IP packet has Dont-Fragment set while also showing a non-zero fragment offset, representing an inconsistent or malformed packet likely to trigger interoperability errors.

  • IPv4 Fragments Observed

    IP packets with MF set or non-zero fragment offsets detected, indicating fragmentation that may cause reassembly failures, increased latency, or broken parsing in middleboxes.

  • IPv6 Fragments Observed

    IPv6 Fragment headers were observed. Fragmentation is valid traffic but can reduce middlebox visibility and should be correlated with reassembly failures before it is treated as impact.

  • Long Base64-like Payload

    Long uninterrupted Base64-like character sequences in packet payloads indicate embedded encoded blobs often used for covert channels or staged file transfer and should be extracted for analysis.

  • Multicast/Broadcast Frame

    Ethernet destination has the IEEE group bit set, identifying multicast or broadcast delivery.

  • NTP Stratum 16 Unreachable

    NTP packet reports stratum 16, which denotes an unreachable server or invalid time source and requires time configuration or server health checks.

  • Runt/Giant Ethernet Frame

    A complete Ethernet record with a captured FCS is shorter than the on-wire minimum, or its length exceeds conservative FCS/VLAN/QinQ sizes while remaining below the jumbo-frame range. Treat this as a bounded size-anomaly candidate, not proof of an on-wire fault.

  • SNMP Error Response

    SNMP response includes a non-zero error-status, indicating the SNMP operation failed or was rejected by the agent.

Suspicious traffic & threats 32AD RDP Security Negotiation Observed · Cleartext Mail Authentication · CTF Flag
  • AD RDP Security Negotiation Observed

    Highlights RDP security-protocol offers and selections; repeated negotiations may justify bounded source/target correlation but do not reveal credentials or authentication outcome.

  • Cleartext Mail Authentication

    Unencrypted IMAP/POP/SMTP authentication commands expose credentials on the wire and identify clients using insecure authentication that require remediation.

  • CTF Flag

    Frame payload contains bounded CTF-style flag tokens (for example 'FLAG{...}', 'CTF{...}', or named '*CTF{...}' formats), indicating potential capture of challenge/flag material or sensitive test data while avoiding CSS class false positives such as '.ui-icon-flag{...}'.

  • DNS ANY/TXT Responses

    Marks DNS ANY/TXT responses which are frequently abused in reflection/amplification attacks.

  • DNS Non-Standard Opcode Probe

    Highlights DNS request opcodes other than standard query, a useful marker for service/capability probing.

  • DNS version.bind Probe

    Highlights CHAOS/TXT version.bind DNS probes used for resolver fingerprinting and service reconnaissance.

  • FTP Cleartext Credentials

    FTP USER or PASS command observed in cleartext, exposing username or password on the wire.

  • Gratuitous ARP Reply Spoofing

    ARP reply where sender and target MACs match but IPs differ indicates a gratuitous-reply pattern consistent with ARP spoofing or proxying and warrants immediate MAC/IP owner verification.

  • HTTP Basic Auth Present

    HTTP Basic authentication headers observed in cleartext, exposing credentials when traffic is unencrypted.

  • HTTP Cookie Transmitted

    HTTP requests or responses carrying Cookie or Set-Cookie headers that may expose session identifiers in plaintext.

  • IMAP Cleartext LOGIN

    IMAP LOGIN command observed in cleartext, exposing user credentials unless the session is TLS-encrypted.

  • IRC IDENTIFY Credentials

    IRC IDENTIFY message present in plaintext, indicating client authentication tokens or passwords are being transmitted unencrypted.

  • Legacy TLS Record Version

    A legacy record-layer version appears outside a modern ClientHello compatibility header. Confirm the negotiated version from ServerHello; the record header alone does not establish a downgrade.

  • Legacy TLS Version Selected

    ServerHello selected an outdated protocol (SSLv2/SSLv3/TLS1.0/TLS1.1), indicating use of legacy encryption and increased downgrade or compatibility risk.

  • MSN Plaintext Tokens

    MSN protocol markers detected in cleartext payload, indicating messaging tokens or credentials may be exposed.

  • NULL TLS Ciphersuite Selected

    Server selected the 0x0000 NULL ciphersuite, meaning no encryption or integrity is being applied and signaling a critical misconfiguration or malicious behavior.

  • Oversized ICMP Payload

    ICMP packets with payloads at or above 200 bytes can be used for tunneling or data exfiltration and should be inspected for embedded content and unusual endpoints.

  • POP Cleartext Password

    POP PASS command observed in cleartext, exposing the user's password to network observers.

  • Potential ICMP Flood

    Large or frequent ICMP packets (>56 bytes) observed that may indicate ICMP flood or amplification probing capable of overwhelming hosts or links and warrant rate/source analysis.

  • Potential TCP Injection (OOO+302)

    Flags out-of-order or retransmitted packets containing HTTP 302 redirects—may indicate TCP injection attack.

  • SMBv1 Legacy Command

    SMB packet using command 0x72 indicating SMBv1 legacy negotiation or operations that present known security and compatibility risks.

  • SMBv2 Older Dialect

    SMB2 negotiation selecting dialect 0x0202 or 0x0210, indicating use of older SMBv2 dialects that may lack modern encryption/features.

  • SSLv3 or Older Handshake

    TLS/SSL handshake advertises or negotiates SSLv3 or earlier, indicating use of deprecated protocols with known cryptographic weaknesses.

  • TCP ACK Initial Fragment

    IPv4 initial fragment with More Fragments set and a decoded TCP ACK header. This exact frame evidence can corroborate fragmented ACK floods without treating unrelated ACK-with-data traffic as fragmentation.

  • TCP Null Scan Pattern

    TCP packets with no flags set (NULL scans) are indicative of active port scanning techniques aimed at mapping services while evading simple signature detection.

  • TCP-Injected HTTP 302 Redirect

    Out-of-order or retransmitted TCP segments containing ' 302 ' in the payload indicate likely injected HTTP 302 redirect responses from a man-in-the-middle.

  • TLS 1.0/1.1 Handshake

    Handshake indicates TLS 1.0 or TLS 1.1 was negotiated or offered, representing legacy protocol versions that lack modern security features.

  • TLS Heartbeat Length Anomaly

    TLS heartbeat message reports an invalid payload_length, indicating a potential Heartbleed-style memory disclosure vulnerability in the peer.

  • TLS Null Cipher Suite

    TLS handshake offering or selecting a NULL cipher suite indicates no payload encryption and a misconfigured or weak TLS setup that requires immediate cipher/certificate configuration remediation.

  • VLAN Hopping Detection

    DTP frames or packets with excessive VLAN tags detected indicate potential VLAN hopping attempts or misconfigured trunking that can leak traffic across VLAN boundaries and require trunk configuration review.

  • Windows PE Header Transmit

    Payload contains the ASCII PE header string 'This program cannot be run in DOS mode', indicating transmission of a Windows executable or binary header.

  • WPAD Name Lookup

    WPAD lookups via DNS, LLMNR, or NetBIOS indicate proxy auto-discovery activity that can be abused for proxy hijacking or credential interception and should be monitored.

TCP & transport performance 120ACK Data FIN RST Packet · ACK Data RST Packet · ACK FIN RST Packet
  • ACK Data FIN RST Packet

    TCP packet that contains ACK, payload, FIN and RST together, indicating an abrupt teardown of an established session while data was transmitted.

  • ACK Data RST Packet

    TCP packet carrying payload with ACK and RST flags set, indicating an immediate connection reset while data was in-flight and potential data loss.

  • ACK FIN RST Packet

    TCP packet with ACK, FIN and RST flags present, signifying an abnormal or overlapping teardown where a connection was both closed and reset.

  • ACK for Unseen Segment

    Detects ACKs acknowledging data for which no prior segment was observed, suggesting upstream loss or reordering.

  • ACK Only Exchange

    ACK-only packets without an observed handshake context point to capture gaps, asymmetric routing, or mid-stream monitoring and should be correlated with other session fragments.

  • ACK Plus Data Only

    TCP streams consisting of ACKs carrying payload but lacking a recorded handshake imply resumed sessions or partial captures and need sequence reassembly to validate data integrity.

  • ACK RTT >10s

    Flags ACKs with RTT above 10 seconds, indicating extreme delay or pathological path conditions impacting recovery.

  • ACK RTT >1s

    Flags ACKs with measured RTT over 1.0 second, indicating elevated latency that can degrade session responsiveness.

  • ACK RTT >5s

    Flags ACKs with RTT exceeding 5 seconds, indicating significant latency spikes affecting TCP performance.

  • ACK+FIN Without Handshake

    ACK plus FIN packets in the absence of a prior handshake indicate unexpected connection closure or out-of-order capture and should be correlated across the capture to reconstruct the session.

  • ACK+RST Only

    Packets containing ACK and RST only typically represent abrupt session termination or firewall-induced resets and merit endpoint and policy correlation.

  • Bytes In Flight >100k

    Outstanding bytes in flight exceed 100,000, indicating a large amount of unacknowledged data that can increase retransmission cost and buffer pressure.

  • Bytes In Flight >10M

    Outstanding bytes in flight exceed ten million, signaling extreme sender buffering or pathological congestion conditions that risk throughput collapse.

  • Bytes In Flight >1M

    Outstanding bytes in flight exceed one million, suggesting a very large congestion window or potential for retransmission amplification under loss.

  • Client Small Advertised Window

    Marks client SYNs advertising a receive window below 65,535 bytes, potentially limiting initial client-side throughput.

  • Critical TCP Window (<1460)

    An established-session segment advertises a nonzero receive window under 1,460 bytes. Correlate sustained window pressure and sender demand before attributing a throughput problem.

  • CWR Without ECE

    CWR set without a preceding ECE indicates a sender claiming congestion recovery without receiving ECN feedback, suggesting a misbehaving stack or middlebox flag manipulation.

  • Data+FIN Without Handshake

    ACK with payload and FIN but no recorded handshake suggests resumed connections or capture discontinuities and should be validated by reassembling adjacent packets.

  • Deprecated/Unwanted Protocols

    Detected deprecated or uncommon protocols (IPX/SPX/AARP/AIM) or whois ports, suggesting legacy systems, misconfiguration, or undesired traffic.

  • Duplicate ACK

    Marks duplicate TCP ACKs sent by the receiver to signal missing segments and trigger fast retransmit.

  • Excessive Duplicate ACKs >100

    Flags flows generating over 100 duplicate ACKs, indicating severe loss, a forwarding loop, or pathological retransmission behavior.

  • Excessive Duplicate ACKs >1000

    Flags flows generating over 1000 duplicate ACKs, indicating severe loss, a forwarding loop, or pathological retransmission behavior.

  • Excessive TCP Options

    Flags SYN packets with TCP header length over 44 bytes, indicating many or oversized TCP options that may affect parsing.

  • FIN+PSH+URG without ACK

    Packet sets FIN, PSH, and URG with no ACK, an uncommon flag combination that may indicate malformed traffic, evasive scans, or buggy implementations.

  • Forged TCP Reset Same Subnet

    RST packet with ACK RTT >2ms and TTL 64/128/255 suggests a locally-sourced forged TCP reset terminating the connection.

  • Handshake FIN+RST With Data

    Connections that exhibit a handshake followed by FIN and RST while carrying data reflect abnormal teardown behavior possibly caused by middlebox resets or application crashes and should be investigated.

  • Handshake Lacks SACK/MSS

    SYN with header length under expected size lacks SACK/MSS options, which can result from constrained stacks, tunneling, or path MTU limitations.

  • Handshake Missing SACK/WS

    SYN lacks TCP SACK and window scale options, limiting loss recovery effectiveness and capping receive-window scaling for high-BDP paths.

  • Handshake Only No Teardown

    Traffic contains only the TCP handshake frames with no data or teardown flags, indicating connection attempts that never carried payload.

  • Handshake then FIN Only

    TCP flows that complete a handshake then immediately send FIN with no data suggest aborted connections, scanning behavior, or misconfigured clients requiring correlation.

  • Handshake then RST Only

    TCP sessions showing a handshake followed by an immediate RST without payload often indicate closed services, injected resets, or active scanning.

  • Handshake With Data No Teardown

    TCP flow shows completed handshake with application data exchanged but no FIN/RST observed, representing an active session that has not cleanly closed.

  • High-Port to High-Port TCP

    TCP flow between high-numbered source and destination ports (both non-well-known), excluding common service ports, which often indicates ephemeral services or peer-to-peer traffic.

  • Huge TCP Window Size

    Identifies TCP segments advertising receive windows larger than 1,000,000 bytes, which can enable very high throughput or reflect incorrect scaling.

  • Incomplete Handshake with RST

    SYN then SYN/ACK followed by RST without FIN or data indicates aborted connection attempts or network devices injecting resets and should be correlated with host behavior.

  • Initial RTT >1s

    Initial RTT above one second indicates severe path latency or transient reachability problems likely to disrupt application behavior.

  • Initial RTT >200ms

    Initial RTT measured during handshake exceeds 200 ms, indicating a high-latency path that will slow connection setup and interactive performance.

  • Initial RTT >5s

    Initial RTT over five seconds reflects pathological connectivity delays or measurement anomalies preventing timely session establishment.

  • Invalid SACK Range Single Block

    Single-block SACK where the right edge is less than or equal to the left edge, constituting a malformed SACK block that should be treated as invalid.

  • IPv4 Fragmentation (Non-TCP)

    IPv4 packet with the More Fragments flag set and not carrying TCP, indicating fragmentation that can affect reassembly and inspection.

  • IPv4 ID Zero (Non-RST)

    IPv4 packets with IP ID equal to zero (excluding TCP RSTs), a fingerprinting or tunneling artifact that can indicate unusual host/network stacks.

  • Legacy Service Ports

    Traffic observed on legacy cleartext service ports (e.g., 21, 23, 79, 119, 513, 514, 69, 520) indicating use of obsolete protocols that are insecure or require modernization.

  • Low Ephemeral Source Port

    Identifies SYNs originating from low ephemeral source ports (1026–4999), characteristic of older Windows stacks or nonstandard client configurations.

  • Missing Final ACK

    Observed SYN and SYN/ACK without the final ACK indicate incomplete handshakes due to packet loss, scanning, or spoofed attempts and require sequence and path analysis.

  • Moderate Duplicate ACK Burst

    Flags flows with 6–19 consecutive duplicate ACKs, indicating partial loss or prolonged reordering requiring recovery.

  • No Window Scaling Used

    A SYN or SYN/ACK lacks the Window Scale option, proving that window scaling is unavailable for that connection direction and may constrain throughput on high-BDP paths.

  • Nonzero Urgent Pointer

    Urgent pointer field is nonzero without consistent URG semantics, causing receivers expecting proper urgent signaling to misinterpret payload boundaries.

  • Null TCP Packet

    Identifies TCP segments with all control flags cleared, a pattern commonly used for reconnaissance or stealth scanning.

  • Post-handshake TCP Options

    Detects non‑SYN packets carrying TCP options but lacking a TSval and SACK, which may indicate improper option negotiation after the handshake.

  • Previous TCP Segment Missing

    Flags a gap where a prior TCP segment in the sequence is missing, indicating packet loss on the path.

  • Reduced MSS <1300

    Identifies TCP SYNs negotiating MSS below 1,300 bytes, indicating severe MTU reduction or tunneling impact.

  • Reduced MSS <1460

    Identifies TCP SYNs negotiating MSS below 1460 bytes, suggesting path MTU constraints or encapsulation overhead.

  • RPC Latency ≥500ms

    Observed RPC call or response time of 500 milliseconds or greater, indicating backend slowness, congestion, or RPC server performance issues.

  • SACK Left Edge Behind ACK

    Single-block SACK whose left edge is at or before the cumulative ACK (and not a D-SACK), indicating a stale or redundant SACK that does not advance received-data tracking.

  • SACK Present Without Permission

    SACK option appears on a segment despite SACK-permitted not negotiated in the handshake, indicating a protocol anomaly or middlebox injecting options.

  • SACK Right Edge Behind ACK

    Single-block SACK with right edge at or before the cumulative ACK (and not DSACK), implying the reported SACK covers data already cumulatively acknowledged and may be spurious.

  • SACK-Perm Outside SYN

    SACK-permitted option observed on a non-SYN packet, which is out of the expected handshake flow and suggests a malformed packet or intermediary modification.

  • SACK/ACK Gap Over 2GB

    Selective ACK reports a block more than ~2 GB past the ACK, which strongly suggests sequence-number wrap, capture corruption, or misbehaving TCP implementation.

  • SACK/ACK Gap Over 500MB

    SACK block far (>500 MB) beyond the receiver's cumulative ACK, indicating severe sequence-space divergence or corrupted/incorrect sequence numbers requiring immediate investigation.

  • SACK/ACK Gap Over 50MB

    Selective ACK reports a left edge exceeding ~50 MB past the cumulative ACK, pointing to extreme reordering, long retransmission spans, or measurement/sequence anomalies.

  • SACK/ACK Gap Over 5MB

    Selective ACK reports a left edge more than ~5 MB ahead of the cumulative ACK, indicating large out-of-order data ranges or sizeable retransmission windows to investigate.

  • Server Small Advertised Window

    Marks SYN-ACKs advertising a receive window below 65,535 bytes, which can constrain server-to-client throughput.

  • Silly Window Syndrome

    A small nonzero receive window outside the handshake is a candidate for further inspection. A single advertisement does not establish silly window syndrome or its performance impact.

  • Small TCP Segments Sent

    Flow contains numerous small TCP segments (non-zero length but under typical MSS) without PUSH/SYN/FIN/RST, suggesting fragmentation, application-level small writes, or path MTU/segmentation issues.

  • Spurious Retransmission

    Detects retransmitted segments that later prove redundant, indicating false retransmit decisions due to reordering or delayed ACKs.

  • Spurious TCP NOP Options

    Historical raw predicate retained for stable-ID compatibility. Compact native handshake profiles now expose MSS, window scale, SACK, timestamps, option order, and exact retransmission conflicts without attributing a middlebox from one capture vantage.

  • SYN Followed by RST

    A SYN immediately followed by RST is characteristic of closed ports or RST-injecting devices and is commonly seen during port scans or hardened host responses.

  • SYN with Zero Window

    Flags TCP SYN packets advertising a zero receive window, indicating the receiver reports no available buffer during connection setup.

  • SYN Without SACK-Perm

    Initial SYN does not advertise SACK-permitted, meaning the connection will not negotiate SACK and sender-side loss recovery will be limited.

  • SYN/ACK then FIN Without SYN

    SYN/ACK, ACK, and FIN sequences observed without the initiating SYN typically reflect missed packets, injected resets, or asymmetric capture and require endpoint correlation.

  • SYN/ACK+RST Without SYN

    SYN/ACK followed by RST without a recorded initiating SYN can indicate asymmetric capture, remote reset behavior, or injected responses and should be investigated.

  • TCP Accurate ECN (AE)

    AE flag indicates Accurate ECN negotiation is active between endpoints, meaning ECN counters should follow AE semantics for congestion marking.

  • TCP Ambiguous ACK

    Flags ambiguous ACK analysis events that can obscure loss or retransmit behavior.

  • TCP Connection Teardown

    Marks segments carrying FIN to indicate progression toward TCP connection closure.

  • TCP D-SACK

    D-SACK option present in a TCP segment, confirming the receiver observed and reported duplicate data delivery for the specified sequence ranges.

  • TCP D-SACK

    Identifies acknowledgments containing duplicate SACK information, indicating packet reordering or duplicate delivery during recovery.

  • TCP D-SACK Edges Present

    D-SACK left/right edge values are present, providing explicit sequence-range details of duplicate deliveries useful for diagnosing retransmission or duplication sources.

  • TCP DF-Clear Payload Retransmission

    Payload-bearing TCP retransmission with IPv4 DF clear. Isolated matches are weak evidence; clustered matches on one flow can highlight unusual path or sender retransmission behavior.

  • TCP ECE Flag Set

    ECE flag present signals explicit congestion notification was reported by a peer or path and can explain a reduction in sender throughput.

  • TCP ECN Flags Present

    ECE or CWR set on the packet indicates ECN congestion signaling was observed on the path and should correlate with sender congestion-control state.

  • TCP Excessive Options

    SYN header length exceeds typical size, indicating many TCP options present which can affect MSS negotiation and interoperability.

  • TCP Fast Open Indicator

    Packet shows TCP Fast Open negotiation or usage, indicating data may have been exchanged during the SYN handshake and altering expected handshake semantics.

  • TCP Fast Retransmission

    Packet is a fast retransmission triggered by duplicate ACKs, pointing to isolated loss recovered via fast-recovery mechanisms.

  • TCP FIN Flag Set

    Indicates a TCP segment carrying the FIN flag marking connection teardown from the sender.

  • TCP Immediate Reset

    RST with initial sequence numbers indicates an immediate connection rejection, typically due to a closed port, application refusal, or enforcement by an intermediary.

  • TCP Inter-packet Delay >0.5s

    Packet gap over 0.5 seconds in an active flow suggests intermittent latency spikes or pauses that will degrade responsiveness.

  • TCP Inter-packet Delay >10s

    Packet arrives more than 10 seconds after the previous packet on the same flow without teardown or keepalive, indicating a stalled application or extreme path delay.

  • TCP Inter-packet Delay >1s

    Inter-packet gap exceeds one second in an active connection without FIN/RESET, pointing to elevated latency or sender-side stalls affecting throughput.

  • TCP Keep-Alive

    Marks keep‑alive probes or their ACKs used to verify liveness of an otherwise idle TCP connection.

  • TCP No Flags Set

    Packet with no TCP flags set is atypical and may indicate crafted traffic, keepalive variants, or capture anomalies demanding scrutiny.

  • TCP Offload Large Frame

    Single TCP frame larger than typical MTU (jumbo frame) that commonly results from NIC offload or jumbo-frame transmission and can skew packet-level timing and reassembly.

  • TCP Out-of-Order

    Identifies TCP segments received out of sequence, indicating network reordering or delayed retransmissions.

  • TCP Oversized Segment

    Segment flagged as too long for protocol expectations, indicating segmentation problems or mismatched MSS leading to fragmentation or drop.

  • TCP Partial ACK

    Marks ACKs that acknowledge only part of previously outstanding data, commonly seen during selective loss recovery.

  • TCP Port Reuse

    Identifies reuse of previously used TCP port tuples within a short interval, which can complicate connection correlation.

  • TCP PSH Flag

    Marks segments with the PSH flag set, indicating the sender requests immediate delivery of the enclosed data to the application.

  • TCP Reserved Flags Set

    One or more TCP reserved flag bits are set, which violates standard flag usage and likely indicates malformed packets or proprietary/experimental behavior.

  • TCP Reset Packet

    Packet sets the RST flag, immediately terminating or rejecting the connection, commonly due to closed sockets or active policy enforcement.

  • TCP Retransmission

    The decoder flags a retransmission (not fast retransmit). Confirm repeated sequence ranges and capture completeness; this observation alone does not prove packet loss or locate its cause.

  • TCP Segment Error

    TCP segment parsing error detected, which points to malformed payloads, capture corruption, or deliberate evasion attempts requiring packet-level analysis.

  • TCP Segment Overlap

    Overlapping TCP segment regions were observed during reassembly, signifying retransmits, packet duplication, or capture reordering that affects payload reconstruction.

  • TCP Segment Overlap Conflict

    Overlapping TCP segments contain conflicting payload bytes for the same sequence range, indicating data inconsistency between retransmits or capture corruption.

  • TCP Segment Parse Error

    TCP segment flagged as a parse/reassembly error, indicating malformed TCP headers or corrupted capture causing parsing failures.

  • TCP SYN Carrying Data

    Initial SYN contains payload data, indicating in-handshake data transfer used by some protocols or scans and altering normal handshake expectations.

  • TCP SYN Flag Set

    Any packet with the TCP SYN flag set, representing either connection initiation or a SYN retransmission during a handshake.

  • TCP SYN Packet

    TCP packet with only SYN set (no ACK) indicating the start of a new three-way handshake and a fresh connection initiation attempt.

  • TCP TFO ACK

    Marks ACKs that indicate successful TCP Fast Open data was accepted by the peer.

  • TCP TFO Ignored

    Flags TCP Fast Open attempts that the peer rejected or did not honor.

  • TCP TFO SYN

    Identifies SYN packets initiating TCP Fast Open handshakes by carrying TFO-specific options.

  • TCP URG Flag Set

    URG flag set indicates urgent-pointer semantics in use and may reflect application-level out-of-band data or nonstandard stack behavior.

  • TCP Urgent Pointer Set

    Marks segments with a nonzero urgent pointer, indicating data the sender marked for expedited processing.

  • TCP Window Full

    Flags receivers reporting a full receive window, causing senders to pause transmission until buffer space is available.

  • TCP Window Update

    Marks segments that change the advertised receive window size to resume or throttle sender transmission.

  • TCP Xmas Scan

    Detects TCP segments with FIN, PSH, and URG set (Xmas scan), a scanner technique to elicit specific stack or firewall responses.

  • TCP Zero Window

    Advertised TCP window is zero or zero-window condition detected, indicating receiver buffer exhaustion and a sender stall until window updates resume.

  • TCP Zero-Window Probe ACK

    Packet is a zero-window probe ACK, showing the receiver previously advertised a zero window and is probing for available buffer space.

  • Timestamp Option On SYN

    SYN packet includes TCP timestamp option, indicating the peer advertises PAWS/timestamp-based RTT measurement for the connection.

  • Unusual Window Scale x10

    Marks TCP sessions using a window scale factor of 10, which changes interpretation of the advertised window.

  • Zero Window Probe

    Detects probes sent to check whether a previously advertised zero receive window has freed buffer space.

  • Zero Window Tarpit Pattern

    Flags initial-session packets advertising a zero window without a reset, suggesting an intentional stall or tarpit behavior.

VoIP & call quality 35DNS Error (Non-PTR) · DNS Non-zero RCODE · Heuristic RTP Candidate
  • DNS Error (Non-PTR)

    Non-zero DNS rcode for non-PTR queries signals client-visible resolution failures that can impact service reachability and require investigation.

  • DNS Non-zero RCODE

    DNS messages with a non-zero rcode indicate lookup failures or server-side errors commonly produced by monitoring, PTR lookups, or misconfiguration.

  • Heuristic RTP Candidate

    UDP payload matches an RTP-like byte pattern but is not decoded as RTP, indicating a likely RTP media stream that needs port/SSRC verification.

  • IPv4 DSCP Context Required

    Non-default DSCP markings are present. Many values are standard QoS classes, so they require service-policy context and are not anomalies by themselves.

  • IPv4 DSCP Non-Zero

    IPv4 packet with a non-zero DSCP value indicating the packet has QoS markings applied.

  • IPv4 DSCP Zero (Best Effort)

    IPv4 packet with DSCP set to 0 (Best Effort), used as the baseline class for QoS transition and policy-shift correlation.

  • RTCP High Loss Fraction

    RTCP report shows a packet loss fraction >=26, indicating substantial media packet loss on the RTP flow that will impact quality.

  • RTCP Low MOS

    RTCP XR reports MOS-LQ or MOS-CQ below 3.5, indicating perceptually poor call quality that likely requires network or codec investigation.

  • RTP Inter-Packet Gap >60ms

    RTP stream exhibits gaps greater than 60 ms between packets, which can produce audio gaps, jitter buffer underruns, or degraded call quality.

  • RTP/RTCP DSCP Not EF (IPv4)

    IPv4 RTP/RTCP packets whose DSCP is not EF (46). This records the observed marking class; without a configured marking requirement or independent impairment evidence, it does not establish a QoS defect.

  • RTP/RTCP DSCP Not EF (IPv6)

    IPv6 RTP/RTCP packets whose traffic-class DSCP is not EF (46). This records the observed marking class; without a configured marking requirement or independent impairment evidence, it does not establish a QoS defect.

  • RTP/RTCP Low VLAN Priority

    RTP/RTCP frames with VLAN priority below 5 indicating low Layer-2 priority that can degrade real-time media delivery.

  • SDP Invalid Parameters

    SDP contains invalid fields (invalid media port, sample rate, channels, or general invalid flag) that will prevent successful media negotiation.

  • SDP Port Zero (Disabled Media)

    SDP media line with port 0 explicitly disables that media stream, so no RTP will be established for that m= line.

  • SIP 403 Forbidden

    SIP 403 Forbidden is an explicit rejection that often appears in interconnect, roaming, or policy-gated call attempts and should be handled separately from timeout failures.

  • SIP 404 Not Found

    SIP 404 Not Found indicates the target could not be resolved or routed and is a useful narrow interconnect or routing-edge seed.

  • SIP 408 Request Timeout

    SIP 408 responses indicate request timeouts, pointing to unreachable endpoints or signaling path delays.

  • SIP 484 Address Incomplete

    SIP 484 Address Incomplete indicates the called address could not be accepted as formed and is a narrow interconnect or dialing-seed failure.

  • SIP ACK Requests

    SIP ACK requests completing a successful INVITE transaction and confirming final session negotiation.

  • SIP BYE Requests

    SIP BYE requests signaling teardown of an established session and indicating call termination.

  • SIP CANCEL Requests

    SIP CANCEL requests abort a pending INVITE, indicating caller-initiated cancellation of the call attempt.

  • SIP Error Responses

    SIP transactions returning status codes 4xx–6xx indicating failed requests or call setup errors requiring troubleshooting of the call flow.

  • SIP INVITE 480 Temporarily Unavailable

    An INVITE transaction ending with 480 indicates temporary destination unavailability rather than generic call setup failure.

  • SIP INVITE 487 Request Terminated

    An INVITE transaction ending with 487 indicates the setup attempt was terminated before answer, commonly after CANCEL or parallel branch failure.

  • SIP INVITE 487 With Reason

    An INVITE transaction ending with 487 and a SIP Reason header indicates an explicit downstream reject or policy decision, not just generic cleanup.

  • SIP INVITE 488 Not Acceptable Here

    A 488 response to INVITE rejects call setup because the offered media or session parameters are not acceptable. Failures of other SIP methods remain transaction-level evidence.

  • SIP INVITE 603 Decline

    An INVITE transaction ending with 603 indicates explicit call decline rather than timeout or routing failure.

  • SIP INVITE Failure

    Responses to SIP INVITE requests with status codes >=400 indicating failed call establishment and requiring error-cause analysis.

  • SIP INVITE Messages

    SIP INVITE requests initiating session setup and carrying SDP offers useful for tracing call initiation and media negotiation.

  • SIP INVITE Success

    SIP INVITE responses with 2xx status codes confirming call establishment and providing final session parameters.

  • SIP Provisional Responses

    SIP 1xx provisional responses indicating intermediate call progress states (ringing/progress) before the final outcome.

  • SIP Response Time High

    SIP 180/183 provisional responses with post-dial delay >=2500ms, indicating elevated call-setup latency before ringing or session progress.

  • SIP SDP MTU Fragmentation Risk

    SIP or SDP signaling observed in UDP packets at or above large MTU thresholds or with IP fragmentation set, indicating call setup or SDP payloads at risk of fragmentation-induced failure.

  • SIP Signaling Traffic

    SIP packets reveal call setup, negotiation, and teardown details and should be reviewed for abnormal methods, header manipulation, or failed session negotiation.

  • STUN Error Attribute

    STUN message carries an error attribute indicating binding/allocation failure or other NAT traversal errors to diagnose.

Web, email & file services 27AD CS Web Enrollment Activity Observed · AD RDP Negotiation on Nonstandard TCP Port · AD SMB IPC Session Observed
  • AD CS Web Enrollment Activity Observed

    Highlights requests to AD CS web-enrollment endpoints as a bounded relay-correlation candidate. Ordinary certificate enrollment remains possible.

  • AD RDP Negotiation on Nonstandard TCP Port

    Highlights a raw RDP/X.224 negotiation request sent to a port other than 3389. This is only supporting context; gateways and port forwarding can be legitimate, and the primary proxy detector does not depend on this signal.

  • AD SMB IPC Session Observed

    Highlights access to the IPC$ share as an investigation pivot for remote administration and authentication flows; IPC$ access is not malicious by itself.

  • FTP PASV Response

    Flags FTP PASV (227) responses which may expose private IPs if NAT doesn't rewrite embedded addresses.

  • FTP Unexpected Response Codes

    FTP server responded with 202 or codes >=332 which represent unimplemented/redirect/error states that can disrupt file transfers.

  • HTTP 3xx Redirects

    HTTP responses with 3xx status codes indicating resource redirection that can alter request flows or create redirect chains.

  • HTTP 4xx Client Errors

    HTTP responses with 4xx status codes representing client-side request failures useful for diagnosing request validity and access issues.

  • HTTP 5xx Server Errors

    HTTP responses with 5xx status codes indicating server-side failures affecting availability or backend behavior.

  • HTTP Downloaded Artifact

    HTTP responses with binary or archive content types indicate downloadable artifacts that should be extracted and scanned for malicious payloads.

  • HTTP Large Response (>20MB)

    HTTP response with content length ≥20MB indicating a large file transfer that can impact bandwidth and may require download management.

  • HTTP Response Time High

    HTTP transactions with server response times ≥0.5 seconds indicating potential performance issues or backend latency.

  • HTTP Uncommon User-Agent

    HTTP requests whose User-Agent does not match common browser identifiers, often indicating custom clients, scripts, or scanners to investigate.

  • iSCSI Latency ≥500ms

    iSCSI command or response latency of 500 milliseconds or more indicates storage I/O delays or network problems affecting storage performance.

  • MySQL Error Response

    MySQL response contains a non-zero error code, indicating the server rejected the request due to query, authentication, or permission failure.

  • Non-Standard HTTP Version

    HTTP requests using a protocol version other than HTTP/1.0 or HTTP/1.1, indicating atypical clients or protocol misuse.

  • POP3 Negative Response

    POP3 server returned '-ERR', indicating command failure, authentication rejection, or mailbox-level errors to investigate.

  • Short HTTP User-Agent

    User-Agent header shorter than 30 characters, commonly used by bots or minimal clients and useful for anomaly detection.

  • SMB CVE-2009-3103 Probe

    SMB command 0x72 with a nonzero PID High field matches behavior associated with CVE-2009-3103 exploitation attempts, indicating a crafted transaction request that warrants further packet and host correlation.

  • SMB Echo Request

    SMB echo (command 0x2B) observed, indicating a client liveness probe or keepalive and potentially highlighting delayed server responses or polling behavior.

  • SMB Nonzero NTSTATUS

    SMB or SMB2 response carries a nonzero NTSTATUS code indicating the server rejected the operation, so record the NTSTATUS value and associated command to diagnose authentication, permission, or file-access failures.

  • SMB STATUS_LOCK_NOT_GRANTED

    Server returned NTSTATUS 0xC0000055 (lock not granted), indicating a requested file or byte-range lock was denied and suggesting concurrent lock contention or stale lock ownership.

  • SMB/SMB2 Lock Denied

    NTSTATUS 0xC0000055 present in SMB or SMB2 responses means a requested file/byte-range lock was denied, suggesting contention or application-level locking logic problems.

  • SMB/SMB2 NTSTATUS Errors

    SMB or SMB2 packet reports a nonzero NTSTATUS code indicating an operation failure; correlate the NTSTATUS with the SMB command to pinpoint authentication, permission, or file-operation root causes.

  • SMB2 High Response Time

    SMB2 request/response latency ≥0.5 seconds indicates slow server processing or network delay that can degrade file I/O performance and should be correlated with server load and path metrics.

  • SMB2 Server Error Conditions

    SMB2 response contains NTSTATUS 0xC0000016 or 0x00000103 or MXAC status 0x40000013, indicating server-side file/object access or metadata errors that require investigation of server file namespace and permissions.

  • SMTP 4xx/5xx Response

    SMTP server returned a 4xx or 5xx response code indicating a temporary or permanent command failure that requires follow-up.

  • TDS Login Packet

    TDS login packet detected, indicating SQL Server authentication credentials are being sent and may be exposed if encryption is not in use.

Wi-Fi & wireless 48802.11 Disassociation or Deauth · 802.11 Frame Retransmission · 802.11 Probe Request/Response
  • 802.11 Disassociation or Deauth

    802.11 management frame subtype 10 or 12 indicates a disassociation/deauthentication event forcibly terminating a client's session.

  • 802.11 Frame Retransmission

    802.11 frame retry flag set indicates this is a retransmission and points to link-layer delivery failures or poor signal conditions.

  • 802.11 Probe Request/Response

    802.11 probe request or response frame indicates active SSID discovery or AP advertisement during network scanning.

  • Ack

    PotatoFrames Wi-Fi frame taxonomy marker for Ack.

  • Ack (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Ack (Retry).

  • Action

    PotatoFrames Wi-Fi frame taxonomy marker for Action.

  • Action (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Action (Retry).

  • Aruba Management

    PotatoFrames Wi-Fi frame taxonomy marker for Aruba Management.

  • Association Request

    PotatoFrames Wi-Fi frame taxonomy marker for Association Request.

  • Association Request (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Association Request (Retry).

  • Association Response

    PotatoFrames Wi-Fi frame taxonomy marker for Association Response.

  • Association Response (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Association Response (Retry).

  • Bad (Failed Checksum)

    Highlights 802.11 frames with failed FCS checksums.

  • Bad (Malformed)

    Highlights decoder malformed-frame expert findings in Wi-Fi captures.

  • Beacon

    PotatoFrames Wi-Fi frame taxonomy marker for Beacon.

  • Block Ack

    PotatoFrames Wi-Fi frame taxonomy marker for Block Ack.

  • Block Ack (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Block Ack (Retry).

  • Block Ack Request

    PotatoFrames Wi-Fi frame taxonomy marker for Block Ack Request.

  • CTS

    PotatoFrames Wi-Fi frame taxonomy marker for CTS.

  • Data

    PotatoFrames Wi-Fi frame taxonomy marker for Data.

  • Data (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Data (Retry).

  • Deauthentication

    PotatoFrames Wi-Fi frame taxonomy marker for Deauthentication.

  • Deauthentication (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Deauthentication (Retry).

  • Disassociation

    PotatoFrames Wi-Fi frame taxonomy marker for Disassociation.

  • Neighbor Report Request

    PotatoFrames Wi-Fi frame taxonomy marker for Neighbor Report Request.

  • Neighbor Report Response

    PotatoFrames Wi-Fi frame taxonomy marker for Neighbor Report Response.

  • Non-Standard 2.4GHz Channel

    Frame on 2.4 GHz frequency other than 2412/2437/2462 (channels 1/6/11) indicates use of a non-standard channel selection that may increase interference.

  • Null Data

    PotatoFrames Wi-Fi frame taxonomy marker for Null Data.

  • Null Data (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Null Data (Retry).

  • Other Control Frame

    PotatoFrames Wi-Fi frame taxonomy marker for Other Control Frame.

  • Other Management Frame

    PotatoFrames Wi-Fi frame taxonomy marker for Other Management Frame.

  • Probe Request

    PotatoFrames Wi-Fi frame taxonomy marker for Probe Request.

  • Probe Request (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Probe Request (Retry).

  • Probe Response

    PotatoFrames Wi-Fi frame taxonomy marker for Probe Response.

  • Probe Response (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for Probe Response (Retry).

  • Reassociation Request

    PotatoFrames Wi-Fi frame taxonomy marker for Reassociation Request.

  • Reassociation Response

    PotatoFrames Wi-Fi frame taxonomy marker for Reassociation Response.

  • RTS

    PotatoFrames Wi-Fi frame taxonomy marker for RTS.

  • RTS (Retry)

    PotatoFrames Wi-Fi frame taxonomy marker for RTS (Retry).

  • Transmit Power Control Report

    PotatoFrames Wi-Fi frame taxonomy marker for Transmit Power Control Report.

  • Transmit Power Control Request

    PotatoFrames Wi-Fi frame taxonomy marker for Transmit Power Control Request.

  • Wi-Fi Channel Congestion Pattern

    Retry-heavy traffic on overlapping 2.4GHz channels (1/6/11) indicates likely airtime contention.

  • Wi-Fi Disconnect Burst

    Clusters of disassociation/deauthentication frames often indicate service instability or intentional disconnect behavior.

  • Wi-Fi Low SNR

    Low signal-to-noise readings indicate reduced modulation headroom and increased frame corruption risk.

  • Wi-Fi Probe Request Flood

    High probe-request volume indicates active scan storms that can consume airtime and destabilize nearby clients.

  • Wi-Fi Reassociation Activity

    Reassociation request/response bursts can indicate roaming flap or unstable AP transitions.

  • Wi-Fi SSID/BSSID Spread

    Beacon/probe-response advertising with SSID+BSSID pairs used to correlate broad SSID spread and rogue AP suspicion.

  • Wi-Fi Weak Signal Strength

    Low received signal levels (RSSI) suggest weak RF coverage and a higher chance of retries, disconnects, or unstable throughput.

Connection issues & correlations 103

76 issue rules and 27 correlation rules combine signals on related connections. Expand an entry to learn what the pattern means and why it matters.

Addressing & network paths 6ICMP echo flood or sustained outage probe · Latency/stall path · Path MTU connection failure
  • ICMP echo flood or sustained outage probe

    Highlights a possible icmp echo flood or sustained outage probe based on related traffic observations.

  • Latency/stall path

    Highlights a possible latency/stall path based on related traffic observations.

  • Path MTU connection failure

    PacketSafari inferred a path MTU blackhole from repeated large-payload retransmissions on the same sequence space. High risk: transfers can stall or fail until PMTUD is fixed or segmentation is reduced. Check ICMP frag-needed / packet-too-big visibility, tunnel/VPN MTU, firewall ICMP handling, and MSS clamping along the path.

  • Path MTU workaround detected

    PacketSafari inferred PMTUD adaptation or manual MSS fallback after large-payload retransmissions. Moderate/high risk: the connection recovered, but throughput and reliability are degraded by a path MTU mismatch. Validate true path MTU, confirm ICMP frag-needed handling, and review tunnel overhead or MSS rewrite policies.

  • Routing control flap (BGP/OSPF)

    Highlights a possible routing control flap (bgp/ospf) based on related traffic observations.

  • Routing control-plane instability (BGP/OSPF)

    BGP notifications and/or OSPF topology change signals were correlated on the same flow set. Route convergence churn can add latency, drops, or short outages. Inspect neighbor resets, flap frequency, and route-change timing against user impact.

Authentication & access 6AAA authentication failure chain · Diameter auth/subscriber-state churn · Plaintext credentials exposed
  • AAA authentication failure chain

    RADIUS Access-Reject and/or 802.1X EAP failure signals matched on related flows. User/device authentication failures are likely and immediately user-impacting. Check credential validity, AAA backend health, and policy mismatches between NAS/supplicant/server.

  • Diameter auth/subscriber-state churn

    Subscriber-state/auth command traffic is present together with an explicit non-success result on the same Diameter path. Authentication or subscriber-state maintenance may be unstable. Inspect the exact command codes, result codes, Session-Id, and whether the same peer repeatedly returns failures.

  • Plaintext credentials exposed

    PacketSafari observed an explicit cleartext credential-bearing protocol signal such as HTTP Basic authentication, FTP USER/PASS, or Redis AUTH on a TLS-policy port. High security risk: credentials may be visible to any observer on the path and should be treated as exposed. Confirm the affected account and host, rotate exposed credentials if appropriate, and move the protocol or client configuration to an encrypted authentication path.

  • Redis plaintext AUTH on TLS port

    The first application payload is a cleartext Redis authentication command rather than a TLS ClientHello. Credentials can be exposed and the server may reject or close the connection because the client is misconfigured for plaintext instead of TLS. Check the Redis client TLS setting, server TLS listener configuration, and whether the application is connecting to the intended plaintext or TLS port.

  • SIP authentication challenge loop

    Repeated auth challenges were observed relative to INVITE attempts. Calls may fail or be delayed during setup. Validate credentials, digest realm config, clock skew, and SBC auth policy.

  • Wi-Fi authentication failure chain

    Highlights a possible wi-fi authentication failure chain based on related traffic observations.

DNS & name resolution 3DNS anomaly cluster · DNS instability/tunneling risk · DNS resolution instability
  • DNS anomaly cluster

    DNS errors/reliability/suspicious signals clustered in the same flow context. Resolution quality risk and possible application impact. Inspect resolver response codes, retry patterns, and abnormal query characteristics.

  • DNS instability/tunneling risk

    Highlights a possible dns instability/tunneling risk based on related traffic observations.

  • DNS resolution instability

    DNS error/retransmission/no-answer/suspicious-name signals co-occurred. Name resolution may be slow/unreliable; can break call setup and service access. Review resolver health, retries, NXDOMAIN/timeout rates, and potential tunneling indicators.

Encryption & secure connections 5IPsec/ESP tunnel alert or instability · Post-quantum TLS offered but not selected · TLS connection setup failure
  • IPsec/ESP tunnel alert or instability

    ESP payload traffic appeared together with IKE/ISAKMP notify feedback on the same tunnel context. Tunnel setup or maintenance may be unstable. Inspect notify message types, peer SPI values, and whether the tunnel is repeatedly rekeying or tearing down.

  • Post-quantum TLS offered but not selected

    Highlights a possible post-quantum tls offered but not selected based on related traffic observations.

  • TLS connection setup failure

    The TLS connection-failure postindex rule correlated ClientHello-only streams or TLS alerts to this connection. The application may fail to establish a secure session, often because of SNI, policy, certificate, or middlebox handling. Compare the requested SNI with server policy, certificate coverage, reset/alert timing, and any proxy or firewall TLS inspection on the path.

  • TLS negotiation or policy risk

    Legacy-version or negotiation anomalies co-occurred with transport/security stress signals. Handshake reliability and compliance posture may be degraded. Check negotiated versions/ciphers, endpoint policy mismatches, and packet loss during handshake.

  • TLS negotiation pathology

    Highlights a possible tls negotiation pathology based on related traffic observations.

Mobile networks & telecom 345G registration reject · CAMEL service-logic failure · CAMEL transaction failure chain
  • 5G registration reject

    NAS 5GS mobility-management reject fields provide the primary admission failure reason without requiring fuzzy NGAP interpretation. The UE cannot complete registration or proceed to session setup. Inspect exact 5GMM causes, PLMN policy, allowed tracking areas, and subscription/admission configuration.

  • CAMEL service-logic failure

    CAMEL returnError, reject, abort, or local error markers were observed. IN/CAMEL service execution may fail, retry, or terminate abnormally. Inspect CAMEL operation sequence, local error codes, abort reasons, and correlated TCAP issues.

  • CAMEL transaction failure chain

    Highlights a possible camel transaction failure chain based on related traffic observations.

  • Diameter application/policy mismatch

    Unknown application/command and/or vendor experimental result co-occurred with Diameter error signals. Subscriber policy/session procedures may fail intermittently or fully. Validate app-id/command support, peer configuration, and AVP policy compatibility.

  • Diameter command-level 3002

    The control-plane exchange hit the specific 3002 cohort seen across multiple telco corpus captures and should stay distinct from generic non-success Diameter answers. The Diameter procedure failed at the command level for the affected transaction or session. Inspect Session-Id, command code, peer routing/host selection, and whether the same 3002 result repeats across the same host pair.

  • Diameter command-level 4010

    A narrow high-signal charging/policy failure was returned at the command level and should be escalated separately from broader command-level errors. The Diameter control-plane step failed with a specific policy or charging error. Inspect Session-Id, command code, charging policy inputs, and whether the same application or subscriber context repeatedly returns 4010.

  • Diameter command-level failure

    The answer itself reports an explicit command-level failure and should remain separate from nested MSCC failures or transport-only impairment. The Diameter procedure failed at the command level for the affected session or transaction. Inspect Session-Id, command code, CC-Request-Type/Number, peer policy, and whether the same application or host pair repeats the same Result-Code.

  • Diameter control-plane failure pattern

    Diameter error patterns co-occurred with auth/retransmission/timeout/reject indicators. Subscriber/session control can fail or degrade. Inspect Diameter AVPs, peer policy, retransmission, and timeout counters.

  • Diameter credit-control failure chain

    Credit-Control-Answer failure co-occurred with Diameter retransmission, timeout, or non-success indicators. Charging and policy decisions can fail for active subscriber sessions. Inspect CCA result codes, CCR/CCA balance, peer retransmission behavior, and backend policy state.

  • Diameter failure chain

    Highlights a possible diameter failure chain based on related traffic observations.

  • Diameter hidden nested credit failure

    The control-plane exchange appears successful at the outer command level, but nested MSCC Result-Code values still indicate a charging or policy failure. Later AI should not treat 2001 as a clean baseline for the affected session. Inspect Session-Id, CC-Request-Type/Number, outer 2001 status, nested MSCC result codes, and whether the same session also shows transport stress.

  • Diameter nested credit failure

    The command-level answer may look successful, but nested Result-Code-MSCC-Level values indicate charging failure for part of the request. Charging or policy enforcement can fail even when the top-level CCA appears successful. Inspect Session-Id, CC-Request-Type/Number, command-level versus MSCC-level result codes, and affected MSCC blocks.

  • Diameter nested MSCC 4012

    The outer answer may look acceptable, but nested MSCC blocks contain the exact 4012 failure and should be preserved as a distinct charging cohort. Charging or service-control behavior can fail for part of the request even when the outer answer appears nominal. Inspect Session-Id, CC-Request-Type/Number, the affected MSCC blocks, and any repeated 4012 values on the same subscriber flow.

  • Diameter nested MSCC 5012

    The outer answer may look acceptable, but nested MSCC blocks contain the exact 5012 failure and should remain distinct from other nested charging outcomes. Charging or policy enforcement can fail inside an otherwise nominal credit-control exchange. Inspect Session-Id, CC-Request-Type/Number, the failing MSCC blocks, and whether the same subscriber/session repeatedly returns 5012.

  • Diameter transport backpressure

    Diameter packets overlap with TCP zero-window or retransmission behavior on the same control-plane flow. Subscriber control can stall even when the application semantics are otherwise valid. Inspect the carrier TCP stream, receiver window behavior, retransmissions, and whether CCR-U/CCR-T progress is delayed rather than rejected.

  • Diameter transport impairment

    Diameter non-success answers are appearing alongside SCTP or M3UA instability signals. Control-plane failures may reflect transport impairment, not only application rejection. Correlate Diameter failures with SCTP retransmission/abort patterns and M3UA path state.

  • LTE attach or PDN reject

    EPS mobility/session-management reject fields indicate network-side session admission failure. Attach or default bearer establishment fails for the user. Inspect EMM/ESM causes together with any paired S1AP/GTPC session actions.

  • LTE PDN collision after network action

    EPS PDN collision and/or GTPv2 mandatory-IE failure indicators suggest a churn loop rather than a one-off reject. Repeated session setup/teardown loops may occur for the same UE. Correlate UE keys, PDN request timing, detach/re-attach activity, and GTPv2 response causes.

  • LTE PDN reject network failure

    EPS cause 38 and/or GTPv2 cause 72 indicate a network-side PDN/session establishment failure. Default bearer or session setup fails for the affected UE. Correlate UE IDs, PDN request timing, Create Session responses, and any cleanup traffic that follows.

  • M3UA control-plane error

    M3UA error, unavailability, or status-change signals correlated on the same signaling path. Higher-layer SIGTRAN traffic can fail or flap even when IP reachability exists. Inspect ASP state, availability causes, route context status, and SCTP path health.

  • Mobile core session failure

    Highlights a possible mobile core session failure based on related traffic observations.

  • Mobile core session failure chain (GTP/NGAP/S1AP)

    GTPv2 non-accept causes co-occurred with NGAP/S1AP/SCTP stress signals. Attach/session setup may fail for users. Correlate GTP cause values with NGAP/S1AP causes and transport stability.

  • NGAP handover cancelled

    NGAP HandoverRequired and HandoverCancel signals co-occurred for the same UE context. Mobility preparation failed and the UE remained on the old path or was released. Correlate AMF/RAN UE IDs, SCTP association, handover request path, and subsequent release/re-registration activity.

  • NGAP handover preparation failure loop

    HandoverRequired and HandoverPreparationFailure markers co-occurred on the same NGAP UE key, indicating a preparation-stage mobility failure rather than a later cancel-only path. Mobility attempts fail before successful relocation can complete. Correlate AMF/RAN UE IDs, SCTP association, the exact failure window, and whether the same UE retries handover or falls back to release/re-registration.

  • PFCP session failure pattern

    A PFCP Cause field indicated session establishment, modification, or deletion failure. The user plane session may not come up or may fail to update cleanly. Inspect PFCP cause values, SEID, request type, and whether the same peer/session pair repeats failures.

  • QoS/bearer degradation

    Bearer context fields such as QCI, 5QI, QFI, or bearer IDs appeared with QoS policy mismatch evidence. Service quality can degrade when bearer treatment does not match the intended policy. Inspect QCI/5QI/QFI values, bearer IDs, and downstream DSCP/VLAN treatment for the affected flow.

  • RAN/core signaling churn

    NGAP/S1AP cause activity appears with SCTP transport stress. Control-plane inefficiency and setup instability risk. Inspect cause distribution, retries, and transport events around failures.

  • S1AP handover failure chain

    HandoverFailure and/or HandoverPreparationFailure was observed for the same S1AP UE context. Mobility did not complete successfully for the affected UE. Inspect ENB/MME UE IDs, the narrow failure window, and whether the same UE retries handover or is released afterward.

  • SCCP control-plane failure

    SCCP error/refusal/reset/release/class-unexpected evidence was observed. Higher-layer TCAP/CAMEL services may fail to route, reset, or complete. Inspect SCCP cause distribution, addressing, and any adjacent M3UA or SCTP instability.

  • SIGTRAN transaction failure chain

    Highlights a possible sigtran transaction failure chain based on related traffic observations.

  • SIGTRAN transport instability

    Highlights a possible sigtran transport instability based on related traffic observations.

  • SIGTRAN/SCTP transport instability

    SCTP retransmission/gap/error/abort evidence co-occurred. Control-plane reliability risk for telco signaling. Inspect SCTP path loss, MTU, multi-homing behavior, and peer health.

  • TCAP transaction error signal

    TCAP abort, reject, returnError, or problem markers were observed. Service-control transactions may fail or terminate abnormally. Inspect dialogue/session ids, invoke ids, abort causes, and any correlated SCCP/M3UA errors.

  • Wi-Fi roaming instability

    Highlights a possible wi-fi roaming instability based on related traffic observations.

Other traffic & capture observations 2Control-plane failure cluster · Legacy protocol exfiltration
  • Control-plane failure cluster

    SIGTRAN/Diameter/mobile-core related failure signals clustered on one connection set. High risk of control-plane instability and session setup failure. Inspect SCTP reliability plus Diameter/GTP/NGAP/S1AP cause/error patterns together.

  • Legacy protocol exfiltration

    The connection showed authenticated FTP upload or authenticated SMTP submission behavior to an external host. Critical: sensitive data may have been uploaded or submitted off-network. Confirm the client host, destination server, commands used, and any associated credential theft or staged data collection.

Suspicious traffic & threats 2Security alert correlated with this connection · Suspicious web delivery chain
  • Security alert correlated with this connection

    Suricata/Zeek-derived alert evidence mapped to this 5-tuple. Potential security incident on top of performance symptoms. Open Security details, validate signature context, and correlate with packet timeline.

  • Suspicious web delivery chain

    Object-like web staging requests were followed by an external encrypted follow-on cluster from the same client. High risk: this pattern is consistent with browser-driven malware delivery or post-click staging. Review the initiating HTTP request, downloaded object/script type, external follow-on SNI set, and the affected client host.

TCP & transport performance 10Persistent TCP window pressure · Small-write / delayed-ACK latency candidate · TCP ACK RTT degradation
  • Persistent TCP window pressure

    Highlights a possible persistent tcp window pressure based on related traffic observations.

  • Small-write / delayed-ACK latency candidate

    Highlights a possible small-write / delayed-ack latency candidate based on related traffic observations.

  • TCP ACK RTT degradation

    ACK RTT indicators crossed thresholds consistent with path delay or queueing pressure. Interactive responsiveness and transaction latency are likely degraded. Check one-way delay/queue build-up, path asymmetry, and RTT trends around the same interval.

  • TCP incomplete handshake fan-in

    PacketSafari saw a concentrated setup-failure fan-in pattern toward one target, suggesting listener, load-balancer, or path setup trouble rather than an isolated client glitch. High availability risk: client transactions can stall or fail before application exchange starts. Check the shared target endpoint, SYN backlog/listener health, upstream filtering or reset behavior, and whether many affected clients point to the same load-balanced service.

  • TCP initial RTT elevated

    Initial handshake RTT measurements exceeded configured thresholds. Connection setup and request/response cycles may feel slow. Validate network distance/path selection, WAN health, and handshake latency per direction.

  • TCP latency pathology

    ACK RTT/initial RTT/slow-delta indicators formed a consistent latency pathology pattern. Sustained user-visible slowness is likely. Correlate RTT growth with retransmissions, queue occupancy, and endpoint processing delays.

  • TCP loss cascade

    Highlights a possible tcp loss cascade based on related traffic observations.

  • TCP port reuse/lifecycle pressure

    PacketSafari saw explicit TCP port-reuse evidence, but not enough loss or security evidence to promote it as a severe transport incident. Short-lived connection churn or endpoint/socket reuse may complicate troubleshooting and can produce confusing late packets or resets. Check client connection churn, TIME_WAIT reuse settings, NAT/load-balancer reuse behavior, and whether stale packets overlap with new sessions.

  • TCP SYN flood setup pattern

    PacketSafari saw a high-volume SYN setup pattern from many source IPs toward the same target, consistent with a SYN flood or spoofed DoS traffic. High availability risk: the target service may be overloaded by incomplete or spoofed connection attempts. Confirm source distribution, target service exposure, SYN backlog/listener health, firewall counters, and upstream DDoS controls.

  • Transport loss/reordering pattern

    Retransmission/reordering/window-pressure evidence crossed thresholds on the same connection. Throughput and transaction latency are likely degraded. Inspect loss hotspots by direction, RTT growth, and queue/drop behavior on the path.

VoIP & call quality 26DSCP policy transition detected · DSCP policy transition/correlation · Roaming/interconnect SIP edge case
  • DSCP policy transition detected

    The flow showed both DSCP 0 (Best Effort) and non-zero DSCP markings, with evidence of an in-flow transition. Critical signal of unstable QoS policy application; real-time and latency-sensitive traffic may be intermittently de-prioritized. Trace DSCP at ingress, policy trust boundaries, and egress rewrite points. Validate class-map/policy-map counters during the transition window.

  • DSCP policy transition/correlation

    Highlights a possible dscp policy transition/correlation based on related traffic observations.

  • Roaming/interconnect SIP edge case

    Exact SIP 403, 404, 484, or 488 responses were observed on the same signaling path. The interconnect or roaming path may be policy-blocked, unroutable, or capability-mismatched. Inspect SIP status codes, request URI formatting, route selection, and peer policy for the affected dialog.

  • SIP 2xx response without ACK

    2xx responses appeared but ACK was missing on the same flow. Dialogs can fail to establish cleanly. Inspect ACK routing/NAT traversal and transaction state handling.

  • SIP call cancelled before answer

    CANCEL signaling appeared before successful INVITE completion. User-perceived failed/abandoned call setup. Correlate with user behavior, ring-time policy, and upstream response delays.

  • SIP destination temporarily unavailable

    An INVITE transaction ended with an exact 480 final response rather than a generic signaling failure bucket. Call setup failed because the destination was temporarily unreachable or unavailable. Inspect destination registration/state, routing policy, and whether fallback routes or parallel branches exist.

  • SIP dialog teardown missing (BYE/CANCEL not observed)

    Setup/success indicators appeared without BYE/CANCEL closure evidence. Session leaks or abnormal call lifecycle behavior may occur. Check endpoint/session timers and teardown routing path.

  • SIP INVITE cancelled with 487

    CANCEL signaling and exact 487 Request Terminated co-occurred without a successful INVITE completion. Strong evidence of a pre-answer cancelled call attempt. Correlate by Call-ID/CSeq and determine whether the cancel was user-driven, branch-driven, or due to upstream timing.

  • SIP INVITE declined with 603

    A final 603 Decline response was observed for the call attempt. Call setup failed due to an explicit decline rather than timeout or cancellation. Inspect Call-ID/CSeq, called-party policy, user decline behavior, and any parallel branch outcomes.

  • SIP INVITE explicit 487 reject

    A 487 final response carried SIP Reason evidence without a matching CANCEL, so the transaction should be treated as an explicit downstream rejection rather than normal teardown cleanup. Call setup failed due to an explicit policy, service, or interconnect decision. Inspect Call-ID/CSeq, SIP Reason headers, and whether the reject aligns with downstream policy, call-forwarding, or interconnect restrictions.

  • SIP INVITE has no provisional/final progress

    Repeated INVITEs with no provisional/success/failure completion were observed. Call setup stalls and user-facing delays are likely. Verify upstream signaling path, proxy responses, and timeout/error handling.

  • SIP INVITE rejected or failed

    INVITE signaling appears with failure/error responses. Call setup failure likely user-impacting. Inspect response codes, auth policy, routing, and trunk/peer configuration.

  • SIP NAT/ICE setup failure

    STUN error evidence appeared with active INVITE signaling. One-way/no-audio risk is high. Check STUN/TURN reachability, NAT bindings, and ICE candidate validity.

  • SIP request timeout (408)

    INVITE signaling includes 408 timeout behavior. Call setup failed due to signaling timeout. Check reachability, proxy responsiveness, and retransmission policy.

  • SIP transaction timeout/stall pattern

    Repeated slow responses were observed without a clear failure completion. Call setup can stall or exceed SLA. Check proxy/SBC latency, upstream route responsiveness, and retransmission timers.

  • SIP/SDP media negotiation failure

    SDP invalid or disabled-media indicators appeared during call setup. Calls may connect without usable media. Verify SDP offer/answer, media port policies, and codec negotiation.

  • VoIP bidirectional media degradation

    Highlights a possible voip bidirectional media degradation based on related traffic observations.

  • VoIP call setup failure chain

    Highlights a possible voip call setup failure chain based on related traffic observations.

  • VoIP dialog completion failure

    Highlights a possible voip dialog completion failure based on related traffic observations.

  • VoIP media/signaling quality risk

    Jitter/loss/RTCP quality indicators crossed thresholds associated with audible impact. User experience likely degraded (choppy audio, delay, or packet loss artifacts). Review RTP inter-packet gaps, RTCP loss/MOS, and path congestion around the affected time interval.

  • VoIP MTU/fragmentation pathology

    Highlights a possible voip mtu/fragmentation pathology based on related traffic observations.

  • VoIP NAT/ICE traversal failure

    Highlights a possible voip nat/ice traversal failure based on related traffic observations.

  • VoIP QoS marking/policy mismatch

    Media traffic appears under-marked/mis-marked or not effectively prioritized end-to-end. Medium/high risk depending on load; can become severe during congestion. Validate DSCP marking continuity hop-by-hop and compare class queue drops/latency on voice classes.

  • VoIP QoS policy mismatch

    Highlights a possible voip qos policy mismatch based on related traffic observations.

  • VoIP signaling retry/stall pattern

    Highlights a possible voip signaling retry/stall pattern based on related traffic observations.

  • VoIP signaling/media anomaly cluster

    Signaling and/or media quality signals formed a clustered VoIP fault pattern. Elevated risk of call setup or media quality problems. Correlate SIP transaction states with RTP/RTCP quality metrics by time.

Web, email & file services 4SMB exploit/error chain · SMB failure cluster · SMB upload recovery delay
  • SMB exploit/error chain

    Highlights a possible smb exploit/error chain based on related traffic observations.

  • SMB failure cluster

    SMB errors clustered with transport resets/loss or legacy SMB indicators. Likely SMB transaction failures or instability for clients. Check SMB status/error codes, reset patterns, and transport loss on the path.

  • SMB upload recovery delay

    PacketSafari observed a TCP/445 upload pattern where client retransmissions proceed one segment at a time, server ACKs arrive around delayed-ACK timing, and SACK right-edge evidence repeats instead of advancing normally. High performance risk: the upload can appear stalled while each retransmitted segment waits on delayed ACK recovery behavior. Inspect the SMB client retransmission algorithm, NAS/server SACK behavior, delayed ACK settings, and the original packet-loss source around the marked recovery window.

  • TFTP NAT/address mismatch

    PacketSafari found repeated UDP/TFTP-like transfer attempts to one server-side high port without the expected return transfer flow. The client may reject the transfer or report an unexpected peer because the address/port tuple seen by each side does not match. Compare client and server vantage points, confirm NAT helper behavior for TFTP, and check whether server replies use the expected client-facing address and UDP port.

Wi-Fi & wireless 5Wi-Fi channel contention cascade · Wi-Fi disconnect instability · Wi-Fi probe flood pattern
  • Wi-Fi channel contention cascade

    Highlights a possible wi-fi channel contention cascade based on related traffic observations.

  • Wi-Fi disconnect instability

    Highlights a possible wi-fi disconnect instability based on related traffic observations.

  • Wi-Fi probe flood pattern

    Highlights a possible wi-fi probe flood pattern based on related traffic observations.

  • Wi-Fi RF quality degradation

    Highlights a possible wi-fi rf quality degradation based on related traffic observations.

  • Wi-Fi rogue AP suspicion

    Highlights a possible wi-fi rogue ap suspicion based on related traffic observations.

Traffic signals 206

Supporting observations, grouped by investigation area

Traffic observations used to connect related events and identify patterns. These support correlation and are not additional independent detectors.

Addressing & network paths 11ARP duplicate address · ARP Storm · BFD Peer Reports Session Down
  • ARP duplicate address

    Highlights gratuitous or duplicate ARP activity for investigation of address conflicts, failover or unexpected address ownership changes.

  • ARP Storm

    Rapid or repeated ARP packets from one or multiple senders indicate a broadcast/ARP storm that can saturate the local segment and disrupt layer-2 connectivity, requiring immediate source isolation.

  • BFD Peer Reports Session Down

    A BFD control packet reports the transmitting peer's session state as Down. This is exact session-state evidence, but it can represent an unestablished or failed adjacency and is not by itself proof that traffic failed over.

  • BGP Notification Message

    BGP session received a Notification message (type 3), denoting a fatal protocol error that likely caused session termination or route withdrawal.

  • Gratuitous ARP Reply Spoofing

    ARP reply where sender and target MACs match but IPs differ indicates a gratuitous-reply pattern consistent with ARP spoofing or proxying and warrants immediate MAC/IP owner verification.

  • ICMP Fragmentation Needed

    ICMP Destination Unreachable code 4 (fragmentation needed) signals a packet exceeded the path MTU and the sender must reduce packet size or enable appropriate fragmentation handling.

  • ICMPv6 Packet Too Big

    ICMPv6 Packet Too Big (type 2) indicates a forwarded packet exceeded the next hop MTU and the sender must reduce packet size or adjust MSS/fragmentation behavior.

  • OSPF Topology Update

    Observed an OSPF message other than Hello (e.g., LS Update/LSReq/LSAck), typically indicating topology changes, LSDB updates, or adjacency events.

  • Potential ICMP Flood

    Large or frequent ICMP packets (>56 bytes) observed that may indicate ICMP flood or amplification probing capable of overwhelming hosts or links and warrant rate/source analysis.

  • tcp path mtu failure

    Highlights tcp path mtu failure observations so they can be considered alongside related connection activity.

  • tcp path mtu workaround

    Highlights tcp path mtu workaround observations so they can be considered alongside related connection activity.

Authentication & access 12802.1X EAP Failure · Diameter Auth Failure · Diameter Authentication Failure
  • 802.1X EAP Failure

    EAP packet with code 4 indicates an authentication failure in the 802.1X exchange, which typically results in port denial or reauthentication.

  • Diameter Auth Failure

    Diameter authentication or subscriber-state signaling returns an explicit non-success result and should be treated as a real auth-chain failure.

  • Diameter Authentication Failure

    Diameter message with error flag and Result-Code AVP (code 268) indicates an authentication or authorization failure returned by the server.

  • Diameter Subscriber-State/Auth Traffic

    Diameter subscriber-state and authentication command traffic indicates auth/update/cancel/purge activity that should be counted and checked for churn or repetition.

  • FTP Cleartext Credentials

    FTP USER or PASS command observed in cleartext, exposing username or password on the wire.

  • HTTP Basic Auth Present

    HTTP Basic authentication headers observed in cleartext, exposing credentials when traffic is unencrypted.

  • RADIUS Access-Reject

    RADIUS server returned Access-Reject (code 3), indicating authentication failure or explicit credential rejection for the authentication attempt.

  • RADIUS Access-Request Retransmission

    decoder correlated this Access-Request with an earlier request carrying the same RADIUS identifier and request authenticator. This is exact retry evidence, but the capture alone may not distinguish a lost request, lost response, slow AAA server, or capture-path omission.

  • redis plaintext auth on tls port

    Highlights redis plaintext auth on tls port observations so they can be considered alongside related connection activity.

  • SIP Authentication Challenge

    SIP 401 or 407 responses requesting authentication, indicating credential-based challenge/response during signaling.

  • Wi-Fi Auth/Association Failure

    Authentication or association status codes indicate client onboarding failures at the WLAN control plane.

  • Wi-Fi EAP Failure

    EAP failure events indicate rejected 802.1X/WPA enterprise authentication attempts.

DNS & name resolution 8DNS ANY/TXT Responses · dns error · DNS Response No Answers
  • DNS ANY/TXT Responses

    Marks DNS ANY/TXT responses which are frequently abused in reflection/amplification attacks.

  • dns error

    Highlights dns error observations so they can be considered alongside related connection activity.

  • DNS Response No Answers

    DNS replies with zero answer records and an NOERROR code indicate unresolved names, filtering, or missing authoritative data that merit resolver troubleshooting.

  • DNS Retransmission

    Packets flagged as DNS retransmissions point to packet loss, timeouts, or overloaded resolvers and should be correlated with network loss metrics and server load.

  • Excessively Long DNS Query

    Unicast DNS requests with names of 50 bytes or more (non-PTR) are a low-confidence observation for follow-up; ordinary cloud hostnames can be this long, so tunneling requires repeated high-entropy query-shape or detector evidence.

  • Excessively Long DNS Query

    Unicast DNS requests with names of 50 bytes or more (non-PTR) are a low-confidence observation for follow-up; ordinary cloud hostnames can be this long, so tunneling requires repeated high-entropy query-shape or detector evidence.

  • High DNS Answer Count

    DNS responses containing more than seven answer records can indicate CDN/load-balanced answers, DNS-based load distribution, or potential amplification scenarios that deserve scrutiny.

  • Slow DNS Transactions

    DNS queries taking one second or longer reveal resolver latency or upstream delays and should be investigated for network path or server performance issues.

Encryption & secure connections 12ESP Payload Present · IKE Notify Payload Present · Legacy TLS Record Version
  • ESP Payload Present

    ESP traffic indicates encrypted tunnel payloads that should be checked for replay, sequence, or negotiation instability when paired with VPN setup signals.

  • IKE Notify Payload Present

    An IKE notify payload is present. Notify payloads include normal NAT-detection and capability feedback, so this is context rather than failure evidence by itself.

  • Legacy TLS Record Version

    A legacy record-layer version appears outside a modern ClientHello compatibility header. Confirm the negotiated version from ServerHello; the record header alone does not establish a downgrade.

  • pq hybrid key establishment negotiated

    Highlights pq hybrid key establishment negotiated observations so they can be considered alongside related connection activity.

  • pq key establishment offered not selected

    Highlights pq key establishment offered not selected observations so they can be considered alongside related connection activity.

  • pq posture visibility incomplete

    Highlights pq posture visibility incomplete observations so they can be considered alongside related connection activity.

  • tls classical key exchange selected

    Highlights tls classical key exchange selected observations so they can be considered alongside related connection activity.

  • tls connection failure risk

    Highlights tls connection failure risk observations so they can be considered alongside related connection activity.

  • tls pq hybrid negotiated

    Highlights tls pq hybrid negotiated observations so they can be considered alongside related connection activity.

  • tls pq hybrid offered

    Highlights tls pq hybrid offered observations so they can be considered alongside related connection activity.

  • tls pq offer not selected

    Highlights tls pq offer not selected observations so they can be considered alongside related connection activity.

  • Undecoded TLS Ciphersuite

    Handshake contains a ciphersuite value that the dissector could not decode, which may indicate an unsupported, malformed or proprietary cipher suite.

Mobile networks & telecom 70CAMEL Abort Reason · CAMEL Duplicate Session · CAMEL Error Code Present
  • CAMEL Abort Reason

    A CAMEL abort reason indicates abnormal termination of the CAMEL transaction.

  • CAMEL Duplicate Session

    A duplicate CAMEL session marker indicates retry or duplicate service-logic activity that may reflect upstream churn.

  • CAMEL Error Code Present

    A CAMEL local error code indicates explicit service-logic or dialogue failure.

  • CAMEL Problem Present

    A CAMEL problem code indicates protocol or service-logic trouble in the CAMEL transaction.

  • CAMEL Reject

    A CAMEL Reject indicates rejected service-logic or component processing.

  • CAMEL Return Error

    A CAMEL ReturnError indicates service-logic or control-plane transaction failure.

  • Diameter Answer Error

    Diameter Answer with error flag set indicates the request failed due to protocol, AVP, or authorization error returned by the peer.

  • Diameter Capability Exchange Failure

    A Capability-Exchange-Answer with a non-success Result-Code indicates peer capability or application support mismatch.

  • Diameter Command-Level 3002

    Diameter answer returned exact command-level Result-Code 3002, which is a distinct failure cohort in the telco corpus and should be surfaced separately from generic non-success results.

  • Diameter Command-Level 4010

    Diameter answer returned exact command-level Result-Code 4010, which is a narrow high-signal charging/policy failure cohort in the telco corpus.

  • Diameter Command-Level Failure

    A Diameter credit-control answer with a non-success command-level Result-Code indicates an explicit control-plane failure that should be surfaced independently of nested MSCC or transport-only issues.

  • Diameter Credit-Control Answer Failure

    A Credit-Control-Answer with a non-success Result-Code indicates charging or policy control failure for the subscriber session.

  • Diameter Device-Watchdog

    Diameter Device-Watchdog traffic is normal ambient keepalive traffic and should be counted but collapsed during first-pass triage.

  • Diameter Experimental Result

    Presence of an Experimental-Result AVP indicates vendor-specific error or status information that requires vendor-specific interpretation.

  • Diameter Nested MSCC 4012

    Diameter credit-control answer contains exact nested MSCC Result-Code 4012, which should remain distinct from other nested charging failures.

  • Diameter Nested MSCC 5012

    Diameter credit-control answer contains exact nested MSCC Result-Code 5012, which is a separate high-value charging failure cohort in the telco corpus.

  • Diameter Nested MSCC Failure

    A Diameter credit-control answer with a successful outer command but failing nested MSCC result indicates subscriber charging failure hidden inside a nominal response.

  • Diameter Nested MSCC Hidden Behind 2001

    A Diameter credit-control answer returns outer success 2001 while nested MSCC still fails, which is a high-signal hidden charging failure.

  • Diameter Non-Success Result-Code

    Diameter answer with a non-success Result-Code indicates an explicit control-plane failure returned by the peer.

  • Diameter Retransmission

    Diameter message with the T-bit set indicates retransmission of a request due to missing response or perceived loss.

  • Diameter Session Rejection

    Diameter response with Result-Code AVP and error flag set indicates session establishment was explicitly rejected by the server.

  • Diameter Session Timeout

    Diameter message contains a Session-Timeout AVP, indicating the configured session lifetime after which the session will be terminated.

  • Diameter Transport Retransmission Overlap

    Diameter traffic coinciding with TCP retransmission indicates transport impairment affecting control-plane exchange reliability.

  • Diameter Transport Zero Window Overlap

    Diameter traffic coinciding with TCP zero-window behavior indicates receiver backpressure on the charging or policy connection.

  • Diameter/NGAP 5QI Present

    An NGAP 5QI descriptor or Diameter QoS subscription blob is present, indicating bearer QoS context that should be compared with observed service quality.

  • GTP Bearer ID Present

    A GTP bearer identifier is present, allowing bearer-specific correlation for session setup and QoS troubleshooting.

  • GTP/QoS QCI Present

    A GTP QoS QCI value is present, providing bearer-level QoS context that should be checked for degradation or mismatch against the expected policy.

  • GTPv2 Mandatory IE Incorrect

    GTPv2 cause 69 indicates a malformed or unacceptable mandatory information element during session or bearer procedures.

  • GTPv2 Network Failure

    GTPv2 cause 72 indicates network failure during session establishment or bearer procedures.

  • GTPv2 Non-Accept Cause

    GTPv2 messages with cause values >=64 indicating non-acceptance or failure in session/bearer procedures needing core diagnostics.

  • M3UA Error Code Present

    An M3UA Error Code indicates explicit control-plane failure signaled by the M3UA peer.

  • M3UA Status Present

    An M3UA status message indicates state transition or degraded signaling availability that may explain higher-layer transaction failures.

  • M3UA Unavailability Cause

    An M3UA Unavailability Cause indicates unavailable application server or signaling destination state.

  • NAS 5GS Registration Reject PLMN Not Allowed

    5GS mobility-management cause 11 indicates the UE is rejected at registration because the PLMN is not allowed.

  • NAS EPS Attach Reject Network Failure

    EPS mobility-management cause 17 indicates attach or service procedures failed due to network-side failure.

  • NAS EPS PDN Collision With Network Request

    EPS session-management cause 56 indicates the UE PDN request collided with a network-initiated request, which commonly appears in detach/reattach churn loops.

  • NAS EPS PDN Reject Network Failure

    EPS session-management cause 38 indicates network failure during PDN connectivity establishment.

  • NAS EPS PDN Reject Request Rejected

    EPS session-management cause 31 indicates the PDN connectivity request was rejected without a more specific acceptance cause.

  • NGAP Cause Present

    NGAP messages containing a Cause IE which identifies RAN/AMF-level failure reasons to correlate with UE or session impact.

  • NGAP Handover Cancel

    NGAP HandoverCancel indicates handover preparation did not complete and the relocation attempt was cancelled.

  • NGAP Handover Preparation Failure

    NGAP HandoverPreparationFailure is an exact mobility failure selector and should be kept distinct from later cancel or release cleanup.

  • NGAP Handover Required

    NGAP HandoverRequired marks the start of a mobility handover sequence and is useful as a baseline event for handover outcome correlation.

  • NGAP Path Switch Request

    NGAP PathSwitchRequest is part of a successful mobility completion path and should be treated as contextual signaling, not a failure.

  • NGAP Path Switch Request Acknowledge

    NGAP PathSwitchRequestAcknowledge is a positive handover progression signal and should be down-weighted outside sequence correlation.

  • NGAP QoS Flow Identifier Present

    An NGAP QoS flow identifier is present, indicating bearer-specific QoS state worth checking for degradation or mapping issues.

  • PFCP Cause Present

    A PFCP Cause field is present, indicating a session-management response that should be checked for explicit failure or non-accept status.

  • PFCP Heartbeat

    PFCP heartbeat request/response traffic is normal ambient session liveness signaling and should be collapsed in summaries unless asymmetric or failing.

  • PFCP Non-Success Cause

    PFCP non-success causes indicate session establishment, modification, or deletion failure and should be treated as explicit control-plane failure evidence.

  • S1AP Cause Present

    S1AP messages including a Cause field that identifies eNodeB/MME error conditions affecting handover, release, or paging flows.

  • S1AP Handover Failure

    S1AP HandoverFailure indicates an explicit mobility procedure failure for the affected UE context.

  • S1AP Handover Preparation Failure

    S1AP HandoverPreparationFailure indicates the relocation attempt failed before completion.

  • SCCP Error Cause

    An SCCP Error Cause indicates explicit SCCP-level failure for the current message or dialogue.

  • SCCP Reassembly Error

    SCCP message reassembly error indicates fragmented signaling data could not be reassembled cleanly.

  • SCCP Refusal Cause

    An SCCP Refusal Cause indicates the message or connection was refused by the remote side or network.

  • SCCP Release Cause

    An SCCP Release Cause indicates explicit connection or transaction release with a cause code.

  • SCCP Reset Cause

    An SCCP Reset Cause indicates a reset of the SCCP connection or transaction context.

  • SCCP Unexpected Class

    Unexpected SCCP class for the message type indicates malformed or incompatible signaling behavior.

  • SCTP ABORT Chunk

    SCTP ABORT chunk observed, indicating the peer abruptly terminated the association.

  • SCTP ERROR Chunk

    SCTP ERROR chunk present, indicating a protocol-level error during association negotiation or data transfer.

  • SCTP Heartbeat

    SCTP HEARTBEAT and HEARTBEAT ACK chunks are ambient path-liveness signaling and should be collapsed unless they dominate the capture or become asymmetric.

  • SCTP Retransmission

    Detected SCTP retransmission events, indicating packet loss, congestion, or path instability affecting the association.

  • SCTP SACK with Gaps

    SCTP SACK with gap blocks indicates selective acknowledgments due to out-of-order delivery or partial loss on the path.

  • TCAP Abort

    A TCAP Abort indicates the dialogue was terminated abnormally.

  • TCAP Dialogue Abort

    A TCAP DialogueAbort indicates explicit abnormal dialogue termination and should be surfaced separately from generic TCAP problems.

  • TCAP Duplicate Session

    A duplicated TCAP session marker indicates retry or duplicate dialogue activity that can reflect churn or replay of transaction state.

  • TCAP Problem Present

    A TCAP problem code indicates protocol or application transaction trouble in the dialogue.

  • TCAP Reject

    A TCAP Reject indicates a rejected component or dialogue problem.

  • TCAP Return Error

    A TCAP ReturnError indicates application-level transaction failure in the TCAP dialogue.

  • Unknown Diameter Command

    Diameter request uses an unknown or unsupported command code, indicating a mismatched application or misconfigured peer.

  • Wi-Fi Reassociation Activity

    Reassociation request/response bursts can indicate roaming flap or unstable AP transitions.

Other traffic & capture observations 5classical key establishment negotiated · IPv4 Fragments Observed · Long Base64-like Payload
  • classical key establishment negotiated

    Highlights classical key establishment negotiated observations so they can be considered alongside related connection activity.

  • IPv4 Fragments Observed

    IP packets with MF set or non-zero fragment offsets detected, indicating fragmentation that may cause reassembly failures, increased latency, or broken parsing in middleboxes.

  • Long Base64-like Payload

    Long uninterrupted Base64-like character sequences in packet payloads indicate embedded encoded blobs often used for covert channels or staged file transfer and should be extracted for analysis.

  • TLS1.3 Offered, TLS1.2 Selected

    Server responded selecting TLS 1.2 despite the client offering TLS 1.3, showing the server does not negotiate TLS 1.3 and may be limited or downgraded.

  • web delivery chain risk

    Highlights web delivery chain risk observations so they can be considered alongside related connection activity.

Suspicious traffic & threats 4ftp exfil risk · Oversized ICMP Payload · Potential TCP Injection (OOO+302)
  • ftp exfil risk

    Highlights ftp exfil risk observations so they can be considered alongside related connection activity.

  • Oversized ICMP Payload

    ICMP packets with payloads at or above 200 bytes can be used for tunneling or data exfiltration and should be inspected for embedded content and unusual endpoints.

  • Potential TCP Injection (OOO+302)

    Flags out-of-order or retransmitted packets containing HTTP 302 redirects—may indicate TCP injection attack. Out-of-order or retransmitted TCP segments containing ' 302 ' in the payload indicate likely injected HTTP 302 redirect responses from a man-in-the-middle.

  • smtp exfil risk

    Highlights smtp exfil risk observations so they can be considered alongside related connection activity.

TCP & transport performance 34ACK RTT >10s · ACK RTT >1s · ACK RTT >5s
  • ACK RTT >10s

    Flags ACKs with RTT above 10 seconds, indicating extreme delay or pathological path conditions impacting recovery.

  • ACK RTT >1s

    Flags ACKs with measured RTT over 1.0 second, indicating elevated latency that can degrade session responsiveness.

  • ACK RTT >5s

    Flags ACKs with RTT exceeding 5 seconds, indicating significant latency spikes affecting TCP performance.

  • Excessive Duplicate ACKs >100

    Flags flows generating over 100 duplicate ACKs, indicating severe loss, a forwarding loop, or pathological retransmission behavior. Flags flows generating over 1000 duplicate ACKs, indicating severe loss, a forwarding loop, or pathological retransmission behavior.

  • Initial RTT >1s

    Initial RTT above one second indicates severe path latency or transient reachability problems likely to disrupt application behavior.

  • Initial RTT >200ms

    Initial RTT measured during handshake exceeds 200 ms, indicating a high-latency path that will slow connection setup and interactive performance.

  • Initial RTT >5s

    Initial RTT over five seconds reflects pathological connectivity delays or measurement anomalies preventing timely session establishment.

  • Moderate Duplicate ACK Burst

    Flags flows with 6–19 consecutive duplicate ACKs, indicating partial loss or prolonged reordering requiring recovery.

  • Packet timing gap over 500 ms

    Highlights a gap of more than half a second between packets, helping identify pauses that may warrant investigation.

  • Previous TCP Segment Missing

    Flags a gap where a prior TCP segment in the sequence is missing, indicating packet loss on the path.

  • SACK/ACK Gap Over 5MB

    Selective ACK reports a left edge more than ~5 MB ahead of the cumulative ACK, indicating large out-of-order data ranges or sizeable retransmission windows to investigate. Selective ACK reports a left edge exceeding ~50 MB past the cumulative ACK, pointing to extreme reordering, long retransmission spans, or measurement/sequence anomalies. SACK block far (>500 MB) beyond the receiver's cumulative ACK, indicating severe sequence-space divergence or corrupted/incorrect sequence numbers requiring immediate investigation. Selective ACK reports a block more than ~2 GB past the ACK, which strongly suggests sequence-number wrap, capture corruption, or misbehaving TCP implementation.

  • Silly Window Syndrome

    A small nonzero receive window outside the handshake is a candidate for further inspection. A single advertisement does not establish silly window syndrome or its performance impact.

  • Small TCP Segments Sent

    Flow contains numerous small TCP segments (non-zero length but under typical MSS) without PUSH/SYN/FIN/RST, suggesting fragmentation, application-level small writes, or path MTU/segmentation issues.

  • TCP Ambiguous ACK

    Flags ambiguous ACK analysis events that can obscure loss or retransmit behavior.

  • tcp conflicting overlap

    Highlights tcp conflicting overlap observations so they can be considered alongside related connection activity.

  • tcp df clear payload retransmission cluster

    Highlights tcp df clear payload retransmission cluster observations so they can be considered alongside related connection activity.

  • TCP Fast Retransmission

    Packet is a fast retransmission triggered by duplicate ACKs, pointing to isolated loss recovered via fast-recovery mechanisms.

  • tcp handshake option conflict

    Highlights tcp handshake option conflict observations so they can be considered alongside related connection activity.

  • TCP Immediate Reset

    RST with initial sequence numbers indicates an immediate connection rejection, typically due to a closed port, application refusal, or enforcement by an intermediary.

  • tcp incomplete handshake fan in

    Highlights tcp incomplete handshake fan in observations so they can be considered alongside related connection activity.

  • TCP Inter-packet Delay >0.5s

    Packet gap over 0.5 seconds in an active flow suggests intermittent latency spikes or pauses that will degrade responsiveness.

  • TCP Inter-packet Delay >1s

    Inter-packet gap exceeds one second in an active connection without FIN/RESET, pointing to elevated latency or sender-side stalls affecting throughput.

  • tcp nagle delayed ack candidate

    Highlights tcp nagle delayed ack candidate observations so they can be considered alongside related connection activity.

  • TCP Out-of-Order

    Identifies TCP segments received out of sequence, indicating network reordering or delayed retransmissions.

  • tcp port reuse lifecycle

    Highlights tcp port reuse lifecycle observations so they can be considered alongside related connection activity.

  • tcp port reuse observation

    Highlights tcp port reuse observation observations so they can be considered alongside related connection activity.

  • tcp pure ack delay vs initial rtt

    Highlights tcp pure ack delay vs initial rtt observations so they can be considered alongside related connection activity.

  • TCP Retransmission

    The decoder flags a retransmission (not fast retransmit). Confirm repeated sequence ranges and capture completeness; this observation alone does not prove packet loss or locate its cause.

  • tcp spurious retransmission

    Highlights tcp spurious retransmission observations so they can be considered alongside related connection activity.

  • tcp syn flood pattern

    Highlights tcp syn flood pattern observations so they can be considered alongside related connection activity.

  • tcp syn zero window

    Highlights tcp syn zero window observations so they can be considered alongside related connection activity.

  • tcp window critical

    Highlights tcp window critical observations so they can be considered alongside related connection activity.

  • TCP Window Full

    Flags receivers reporting a full receive window, causing senders to pause transmission until buffer space is available.

  • TCP Zero Window

    Advertised TCP window is zero or zero-window condition detected, indicating receiver buffer exhaustion and a sender stall until window updates resume.

VoIP & call quality 31IPv4 DSCP Context Required · IPv4 DSCP Non-Zero · IPv4 DSCP Zero (Best Effort)
  • IPv4 DSCP Context Required

    Non-default DSCP markings are present. Many values are standard QoS classes, so they require service-policy context and are not anomalies by themselves.

  • IPv4 DSCP Non-Zero

    IPv4 packet with a non-zero DSCP value indicating the packet has QoS markings applied.

  • IPv4 DSCP Zero (Best Effort)

    IPv4 packet with DSCP set to 0 (Best Effort), used as the baseline class for QoS transition and policy-shift correlation.

  • RTCP High Loss Fraction

    RTCP report shows a packet loss fraction >=26, indicating substantial media packet loss on the RTP flow that will impact quality.

  • RTCP Low MOS

    RTCP XR reports MOS-LQ or MOS-CQ below 3.5, indicating perceptually poor call quality that likely requires network or codec investigation.

  • RTP Inter-Packet Gap >60ms

    RTP stream exhibits gaps greater than 60 ms between packets, which can produce audio gaps, jitter buffer underruns, or degraded call quality.

  • RTP/RTCP DSCP Not EF (IPv4)

    IPv4 RTP/RTCP packets whose DSCP is not EF (46). This records the observed marking class; without a configured marking requirement or independent impairment evidence, it does not establish a QoS defect.

  • RTP/RTCP DSCP Not EF (IPv6)

    IPv6 RTP/RTCP packets whose traffic-class DSCP is not EF (46). This records the observed marking class; without a configured marking requirement or independent impairment evidence, it does not establish a QoS defect.

  • RTP/RTCP Low VLAN Priority

    RTP/RTCP frames with VLAN priority below 5 indicating low Layer-2 priority that can degrade real-time media delivery.

  • SDP Invalid Parameters

    SDP contains invalid fields (invalid media port, sample rate, channels, or general invalid flag) that will prevent successful media negotiation.

  • SDP Port Zero (Disabled Media)

    SDP media line with port 0 explicitly disables that media stream, so no RTP will be established for that m= line.

  • SIP 403 Forbidden

    SIP 403 Forbidden is an explicit rejection that often appears in interconnect, roaming, or policy-gated call attempts and should be handled separately from timeout failures.

  • SIP 404 Not Found

    SIP 404 Not Found indicates the target could not be resolved or routed and is a useful narrow interconnect or routing-edge seed.

  • SIP 408 Request Timeout

    SIP 408 responses indicate request timeouts, pointing to unreachable endpoints or signaling path delays.

  • SIP 484 Address Incomplete

    SIP 484 Address Incomplete indicates the called address could not be accepted as formed and is a narrow interconnect or dialing-seed failure.

  • SIP ACK Requests

    SIP ACK requests completing a successful INVITE transaction and confirming final session negotiation.

  • SIP BYE Requests

    SIP BYE requests signaling teardown of an established session and indicating call termination.

  • SIP CANCEL Requests

    SIP CANCEL requests abort a pending INVITE, indicating caller-initiated cancellation of the call attempt.

  • SIP Error Responses

    SIP transactions returning status codes 4xx–6xx indicating failed requests or call setup errors requiring troubleshooting of the call flow.

  • SIP INVITE 480 Temporarily Unavailable

    An INVITE transaction ending with 480 indicates temporary destination unavailability rather than generic call setup failure.

  • SIP INVITE 487 Request Terminated

    An INVITE transaction ending with 487 indicates the setup attempt was terminated before answer, commonly after CANCEL or parallel branch failure.

  • SIP INVITE 487 With Reason

    An INVITE transaction ending with 487 and a SIP Reason header indicates an explicit downstream reject or policy decision, not just generic cleanup.

  • SIP INVITE 488 Not Acceptable Here

    A 488 response to INVITE rejects call setup because the offered media or session parameters are not acceptable. Failures of other SIP methods remain transaction-level evidence.

  • SIP INVITE 603 Decline

    An INVITE transaction ending with 603 indicates explicit call decline rather than timeout or routing failure.

  • SIP INVITE Failure

    Responses to SIP INVITE requests with status codes >=400 indicating failed call establishment and requiring error-cause analysis.

  • SIP INVITE Messages

    SIP INVITE requests initiating session setup and carrying SDP offers useful for tracing call initiation and media negotiation.

  • SIP INVITE Success

    SIP INVITE responses with 2xx status codes confirming call establishment and providing final session parameters.

  • SIP Provisional Responses

    SIP 1xx provisional responses indicating intermediate call progress states (ringing/progress) before the final outcome.

  • SIP Response Time High

    SIP 180/183 provisional responses with post-dial delay >=2500ms, indicating elevated call-setup latency before ringing or session progress.

  • SIP SDP MTU Fragmentation Risk

    SIP or SDP signaling observed in UDP packets at or above large MTU thresholds or with IP fragmentation set, indicating call setup or SDP payloads at risk of fragmentation-induced failure.

  • STUN Error Attribute

    STUN message carries an error attribute indicating binding/allocation failure or other NAT traversal errors to diagnose.

Web, email & file services 10citrix edt stall bucket · citrix ica listener refused · citrix ica session reliability loss
  • citrix edt stall bucket

    Highlights citrix edt stall bucket observations so they can be considered alongside related connection activity.

  • citrix ica listener refused

    Highlights citrix ica listener refused observations so they can be considered alongside related connection activity.

  • citrix ica session reliability loss

    Highlights citrix ica session reliability loss observations so they can be considered alongside related connection activity.

  • citrix path change indicator

    Highlights citrix path change indicator observations so they can be considered alongside related connection activity.

  • citrix reconnect or reset

    Highlights citrix reconnect or reset observations so they can be considered alongside related connection activity.

  • legacy smbv1

    Highlights legacy smbv1 observations so they can be considered alongside related connection activity.

  • smb error

    Highlights smb error observations so they can be considered alongside related connection activity.

  • smb upload recovery delay

    Highlights smb upload recovery delay observations so they can be considered alongside related connection activity.

  • smb2 error

    Highlights smb2 error observations so they can be considered alongside related connection activity.

  • tftp nat mismatch

    Highlights tftp nat mismatch observations so they can be considered alongside related connection activity.

Wi-Fi & wireless 9802.11 Disassociation or Deauth · 802.11 Frame Retransmission · 802.11 Probe Request/Response
  • 802.11 Disassociation or Deauth

    802.11 management frame subtype 10 or 12 indicates a disassociation/deauthentication event forcibly terminating a client's session. Clusters of disassociation/deauthentication frames often indicate service instability or intentional disconnect behavior.

  • 802.11 Frame Retransmission

    802.11 frame retry flag set indicates this is a retransmission and points to link-layer delivery failures or poor signal conditions.

  • 802.11 Probe Request/Response

    802.11 probe request or response frame indicates active SSID discovery or AP advertisement during network scanning.

  • Non-Standard 2.4GHz Channel

    Frame on 2.4 GHz frequency other than 2412/2437/2462 (channels 1/6/11) indicates use of a non-standard channel selection that may increase interference.

  • Wi-Fi Channel Congestion Pattern

    Retry-heavy traffic on overlapping 2.4GHz channels (1/6/11) indicates likely airtime contention.

  • Wi-Fi Low SNR

    Low signal-to-noise readings indicate reduced modulation headroom and increased frame corruption risk.

  • Wi-Fi Probe Request Flood

    High probe-request volume indicates active scan storms that can consume airtime and destabilize nearby clients.

  • Wi-Fi SSID/BSSID Spread

    Beacon/probe-response advertising with SSID+BSSID pairs used to correlate broad SSID spread and rogue AP suspicion.

  • Wi-Fi Weak Signal Strength

    Low received signal levels (RSSI) suggest weak RF coverage and a higher chance of retries, disconnects, or unstable throughput.

IDS signatures 33

Security and protocol activity signatures

Browse built-in signatures for suspicious activity and notable protocol operations. Full IDS scanning must be requested.

Authentication & access 15DRSUAPI DRSGetNCChanges Observed · DRSUAPI Interface Bound · Key Credential Link Modification Observed
  • DRSUAPI DRSGetNCChanges Observed

    Identifies traffic matching this activity: DRSUAPI DRSGetNCChanges Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DRSUAPI Interface Bound

    Identifies traffic matching this activity: DRSUAPI Interface Bound. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • Key Credential Link Modification Observed

    Identifies traffic matching this activity: Key Credential Link Modification Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-DFSNM DFSCoerce Method Observed

    Identifies traffic matching this activity: MS-DFSNM DFSCoerce Method Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-DFSNM Interface Bound

    Identifies traffic matching this activity: MS-DFSNM Interface Bound. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-EFSR Alternate Interface Bound

    Identifies traffic matching this activity: MS-EFSR Alternate Interface Bound. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-EFSR Interface Bound

    Identifies traffic matching this activity: MS-EFSR Interface Bound. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-EFSR PetitPotam EfsRpcOpenFileRaw Alternate Interface Observed

    Identifies traffic matching this activity: MS-EFSR PetitPotam EfsRpcOpenFileRaw Alternate Interface Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-EFSR PetitPotam EfsRpcOpenFileRaw Observed

    Identifies traffic matching this activity: MS-EFSR PetitPotam EfsRpcOpenFileRaw Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-EVEN Interface Bound

    Identifies traffic matching this activity: MS-EVEN Interface Bound. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-FSRVP Interface Bound

    Identifies traffic matching this activity: MS-FSRVP Interface Bound. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-FSRVP ShadowCoerce Method Observed

    Identifies traffic matching this activity: MS-FSRVP ShadowCoerce Method Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-RPRN Interface Bound

    Identifies traffic matching this activity: MS-RPRN Interface Bound. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • MS-RPRN PrinterBug Coercion Method Observed

    Identifies traffic matching this activity: MS-RPRN PrinterBug Coercion Method Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • RBCD Attribute Modification Observed

    Identifies traffic matching this activity: RBCD Attribute Modification Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

Industrial & operational technology 15DNP3 Cold Restart Command Observed · DNP3 Direct Operate Control Observed · DNP3 Direct Operate No Ack Control Observed
  • DNP3 Cold Restart Command Observed

    Identifies traffic matching this activity: DNP3 Cold Restart Command Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DNP3 Direct Operate Control Observed

    Identifies traffic matching this activity: DNP3 Direct Operate Control Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DNP3 Direct Operate No Ack Control Observed

    Identifies traffic matching this activity: DNP3 Direct Operate No Ack Control Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DNP3 Disable Unsolicited Messages Command Observed

    Identifies traffic matching this activity: DNP3 Disable Unsolicited Messages Command Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DNP3 Initialize Data Command Observed

    Identifies traffic matching this activity: DNP3 Initialize Data Command Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DNP3 Operate Control Observed

    Identifies traffic matching this activity: DNP3 Operate Control Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DNP3 Select Control Observed

    Identifies traffic matching this activity: DNP3 Select Control Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DNP3 Stop Application Command Observed

    Identifies traffic matching this activity: DNP3 Stop Application Command Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • DNP3 Warm Restart Command Observed

    Identifies traffic matching this activity: DNP3 Warm Restart Command Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • Modbus Force Listen Only Diagnostic Observed

    Identifies traffic matching this activity: Modbus Force Listen Only Diagnostic Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • Modbus Restart Communications Diagnostic Observed

    Identifies traffic matching this activity: Modbus Restart Communications Diagnostic Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • Modbus Write Multiple Coils Observed

    Identifies traffic matching this activity: Modbus Write Multiple Coils Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • Modbus Write Multiple Registers Observed

    Identifies traffic matching this activity: Modbus Write Multiple Registers Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • Modbus Write Single Coil Observed

    Identifies traffic matching this activity: Modbus Write Single Coil Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • Modbus Write Single Register Observed

    Identifies traffic matching this activity: Modbus Write Single Register Observed. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

Web, email & file services 3FTP Bruteforce Attempt (Request) · RDP Negotiation on Nonstandard Port · SMBv3 Compression Transform Header (Possible CVE-2020-0796)
  • FTP Bruteforce Attempt (Request)

    Identifies traffic matching this activity: FTP Bruteforce Attempt (Request). Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • RDP Negotiation on Nonstandard Port

    Identifies traffic matching this activity: RDP Negotiation on Nonstandard Port. Review the surrounding traffic to determine whether the activity is expected or needs investigation.

  • SMBv3 Compression Transform Header (Possible CVE-2020-0796)

    Identifies traffic matching this activity: SMBv3 Compression Transform Header (Possible CVE-2020-0796). Review the surrounding traffic to determine whether the activity is expected or needs investigation.

Externally managed IDS rule feedsET Open · abuse.ch SSLBL · abuse.ch URLhaus · Stamus lateral movement

The IDS build supports independently configured ET Open, abuse.ch SSLBL, abuse.ch URLhaus and Stamus lateral-movement sources. Their signature inventories change with feed updates and enabled sources; they are additional to the local signatures listed above. This static datasheet does not claim a complete or live list of externally managed signatures.

03

Agentic analysis

The protocols and Triage evidence above, with AI-assisted investigation and reasoning.

Agent can work across the protocol catalogue and available Triage outputs to investigate your question. It combines decoded packet facts with the context you provide, develops hypotheses, inspects relevant evidence and explains likely causes with packet references.

  1. 01

    Understand the question

    Use the reported symptom and available capture evidence to decide what to investigate.

  2. 02

    Connect the evidence

    Relate protocol behavior, connection timelines, Triage findings and selected packet details across the listed protocols.

  3. 03

    Test explanations

    Inspect supporting and conflicting evidence, distinguish observations from hypotheses and identify missing visibility.

  4. 04

    Explain the result

    Return an evidence-backed explanation with packet references and the next evidence needed when a conclusion remains uncertain.

Protocol availability is shared with the catalogue above. AI reasoning is adaptive, so depth depends on the question and visible evidence; it is not a promise of equal diagnostic accuracy for every protocol or access to encrypted content.