User Tools

Site Tools


paloaltonetworks:decoders

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
paloaltonetworks:decoders [2020/08/11 08:43] bstaffordpaloaltonetworks:decoders [2022/11/23 12:49] (current) – external edit 127.0.0.1
Line 2: Line 2:
 I got this list by monitoring the Dynamic Update release emails from Palo Alto Networks. I got this list by monitoring the Dynamic Update release emails from Palo Alto Networks.
  
-Remember a "decoder" is effectivly a "base protocol". You can also detect these within the App-ID database as any application that does not have a "depends on" or "implicily uses". +Remember a "decoder" is effectivly a "base protocol". You can also detect these within the App-ID database as any application that does not have a "depends on" or "implicily uses"Howeverif we take this definition then the following list is wrong. In the list below we list some dependencies.
- +
-In their updatesthey often list "decoder" udpates in addition to App-ID updates.+
  
 +Listed as a decoder by the dynamic update emails and we have an App-ID for it.
   * asterisk-iax   * asterisk-iax
   * bacnet   * bacnet
Line 16: Line 15:
   * ed137   * ed137
   * ftp   * ftp
-  * ftp-data 
-  * functions 
   * gds-db   * gds-db
-  * generic 
   * gtp   * gtp
   * hp-data-protector   * hp-data-protector
-  * http 
-  * http2 
   * icmp   * icmp
   * iec-60870-5-104   * iec-60870-5-104
Line 30: Line 24:
   * imap   * imap
   * ipsec-esp-udp   * ipsec-esp-udp
-  * kerberos 
   * ldap   * ldap
   * llmnr   * llmnr
   * lpd   * lpd
-  * medical 
   * mms-ics   * mms-ics
   * modbus   * modbus
Line 42: Line 34:
   * netbios-ss   * netbios-ss
   * ntp   * ntp
-  * open-vpn 
   * oracle   * oracle
   * pop3   * pop3
Line 49: Line 40:
   * rpc   * rpc
   * rtsp   * rtsp
-  * scada 
-  * sccp 
-  * sctp 
   * sip   * sip
-  * smb 
-  * smb-8-1 
   * smtp   * smtp
   * ssh   * ssh
Line 61: Line 47:
   * teamviewer   * teamviewer
   * tftp   * tftp
-  * vmware 
   * vnc   * vnc
   * unknown-tcp   * unknown-tcp
   * unknown-udp   * unknown-udp
-  * unknown-peer-to-peer+  * unknown-p2p 
 +   
 +   
 +Listed as a decoder by the dynamic update emails and we have no App-ID for it. 
 +  * ftp-data 
 +  * functions 
 +  * generic 
 +  * http 
 +  * http2 
 +  * medical 
 +  * scada 
 +  * sctp 
 +  * smb 
 +  * smb-8-1 
 +   
 +Listed as a decoder by the dynamic update emails and we have an App-ID for it but it implicitly uses another App-ID. Thus, is it actually a decoder? 
 +  * kerberos - implicitly uses rpc   
 +  * vmware - implicitly uses ssl and web-browsing 
 +   
 +Listed as a decoder by the dynamic update emails and we have an App-ID for it but it depends on another App-ID. Thus, is it actually a decoder? 
 +  * open-vpn - depends on ssl and web-browsing 
 +  * sccp - depends on  tftp 
 + 
 +Also remember, there are 147 members of the "ip-protocol" list in Application Filters in August 2020. This includes all the IPv6 stuff.
paloaltonetworks/decoders.1597135399.txt.gz · Last modified: (external edit)