8 new signatures:
MEDIUM | HTTP:MAL-REDIRECT-VUL-118 | HTTP: MAL-REDIRECT Infection-118 |
HIGH | HTTP:STC:DL:CVE-2020-1308-PE | HTTP: Microsoft Windows DirectX Kernel Driver CVE-2020-1308 Privilege Escalation |
CRITICAL | HTTP:CTS:INTEL-AMT-CVE2020-8758 | HTTP: Intel AMT and ISM CVE-2020-8758 Privilege Escalation |
MEDIUM | HTTP:SUSP-HDR-REDRCT-VUL-119 | HTTP: SUSP-HDR-REDRCT Infection-119 |
CRITICAL | HTTP:STC:ADOBE:CVE-2020-9698-CE | HTTP: Adobe Acrobat and Reader CVE-2020-9698 Remote Code Execution |
HIGH | HTTP:STC:DL:CVE-2020-1152-PE | HTTP: Microsoft Windows Win32k Kernel Driver CVE-2020-1152 Privilege Escalation |
MEDIUM | HTTP:STC:ADOBE:CVE-2020-9694-CE | HTTP: Adobe Acrobat and Reader CVE-2020-9694 Remote Code Execution |
CRITICAL | HTTP:STC:ADOBE:CVE-2020-9693-CE | HTTP: Adobe Acorabat Reader CVE-2020-9693 Remote Code Execution |
236 new application2 signatures:
Multimedia:Video-Streaming:GRABOID | This signature detects Graboid, an application that searches the internet for videos and makes it simple to view them as a streaming video. |
Gaming:INJUSTICE-2 | This plugin classify injustice 2 web site. Injustice 2 is an online game edited by NetherRealm Studios and published by Warner Bros. |
Messaging:HIKE-MESSENGER | Hike Messenger is an Indian instant messaging application. |
Web:INSKIN | Inskin is a media advertising company. |
Gaming:MOBILE-LEGENDS | mobile_legends provide in-App communication cloud services for games. |
Gaming:LOL-GAME | League of Legends is a popular Multiplayer Online Battle Arena video game developed by Riot Games. |
Messaging:YOUME | Youme provides in-App communication cloud services for games. |
Web:FULLSTORY | FullStory is a digital analytics platform. This plugin classifies website traffic |
Web:IBM | IBM (International Business Machines Corporation) is an American multinational technology company. |
Web:CIBN | China International Broadcasting Network (CIBN) is an internet TV platform. This plugin classifies website traffic. |
Web:GAODE-MAP | Gaode Map is a chinese online mapping service. Gaode Map belongs to Alibaba Group which has acquired AutoNavi which offers its map services at Amap.com. It is also known as Gaode in China. |
Web:GOOGLE-VIDEO | Google Video hosting service provides video streaming to Google Youtube applications (Youtube, Kids, Music and Google Program such Youtube Premium). |
Web:APPNEXT | Appnext is mobile monetization, app marketing & re-engagement platform. |
Infrastructure:CYBERGHOST | CyberGhost is a VPN service used to unblock sites and browse privately and anonymously. |
Web:MONDIA-MEDIA | Mondia Media is a content and entertainment services provider. This plugin classifies website browsing. |
Gaming:HARRY-POTTER-WU | Harry Potter: Wizards Unite is an online mobile game developed by Niantic Labs. |
Infrastructure:DICOM | DICOM stands for Digital Imaging and Communications in Medicine, supported traffic on usual TCP port 104, 11112 (decrypted traffic, no support of DICOM-TLS or DICOM-ISCL). |
Multimedia:RAKUTEN-VIDEO | Rakuten Video hosting service provides video streaming to Rakuten TV application. |
Web:MONDAY-COM | Monday.com is a collaboration solution for enterprise. |
Messaging:TRIBAIR | Tribair is an VoIP application for national and international audio calls. |
Web:GOOGLE-BLOG | blog.google is the public blog of Google (products, news, ...). |
Web:COINIMP | Classification of traffic related to cryptocurrency Monero (XMR) mining and web traffic from web site. |
Messaging:MUMBLE | Mumble is an open source, low-latency, high quality voice chat software primarily intended for use while gaming. |
Web:YOPMAIL | YOPmail is a disposable email platform. YOPmail provides a fake temporary and anonymous email address. |
Messaging:COCO | Coco is an instant messaging application with VoIP feature. |
Web:GOOGLE-ONE | Google One is a service for managing the storage paid plan for Google applications. |
Web:9GAG | 9gag is a humorous website or application based on the sharing of images and videos. |
Infrastructure:VPN-MASTER | This protocol plug-in is deprecated. |
Messaging:TIKL | Tikl is a simple VoIP push-to-talk communication application. |
Web:TIBBR | Tibbr is a social network for work. This plugin classifies traffic generated by the website browsing. |
Web:ICF-TECHNOLOGY | ICF Technology is a provider of high-definition video streaming and credit card processing services. Numerous adult content services have icf_technology as a subflow. |
Infrastructure:VPN-MONSTER | This protocol plug-in is deprecated. |
Web:APPLE-NEWS | Apple News is a mobile app and news aggregator developed by Apple Inc. |
Gaming:AGE-OF-MAGIC | Age of Magic is a single player video game for mobile platforms. |
Gaming:DEMONWARE | DemonWare is a software development company and a subsidiary of Activision Blizzard, Inc. |
Infrastructure:CISCO-IP-SLA | Cisco IP SLA is used to monitor IP applications by using active traffic. |
Web:IBOOKS | Standard iOS application to buy, read and manage books and audio books. |
Web:GRAMMARLY | Grammarly is a cloud-based English-language writing-enhancement platform. |
Infrastructure:SPLUNK-CLOUD | Splunk Cloud is the data collection, indexing, and visualization service for operational intelligence. |
Multimedia:FUZE | Fuze (formerly known as ThinkingPhones) is a provider of cloud-based Unified Communications as a Service (UCaaS). |
Infrastructure:PCCC | PCCC stands for "Programmable Controller Communication Commands", it is used to control software running in Programmable Logic Controler (PLC). PCCC traffic can be hardware specific, this plugin addresses traffic generated by Rockwell/Allen-Bradley to talk to SLC5, PLC5E and MicroLogix PLC for service. |
Web:OPEN-SIGNAL | OpenSignal is a company that specializes in wireless coverage mapping. This plugin classifies traffic of OpenSignal traffic on iOS and Android platform. |
Gaming:DRAGON-BALL | The Dragon Ball video game series are based on the manga and anime. This plugin classifies traffic generated by DRAGON BALL FighterZ video game. |
Multimedia:LIFESIZE | Lifesize is a video and audio telecommunications company. This plugin classifies traffic generated on Android and Chrome platforms. |
Infrastructure:VPN-ROBOT | This protocol plug-in is deprecated. |
Web:FUTURE-PLC | Future Plc is a British publisher media company. |
Web:MINEXMR-COM | Mining pool for cryptocurrency named Monero (blockchain). |
Messaging:VYKE | Vyke is an IM allowing to buy phone number from countries such US, UK, Canada and do VoIP, text messaging (SMS), and usual chat (File transfer/text). |
Web:TVB | Television Broadcasts Limited is a Hong Kong audio-visual group. This plugin classifies only website browsing. |
Infrastructure:EPROXY | Eproxy is a VPN for forward proxies with custom payload and optional ssh support. This plugin classifies automatically generated fake HTTP headers and the embedded ssh clients. |
Messaging:DISCORD | Discord is a chat, audio and video call application for gaming. |
Web:TRELLO | Trello is list making application. |
Web:BIGO | BIGO Technology, a Singapore-based social media company. |
Infrastructure:TWEAKWARE | Tweakware is a vpn application. |
Web:MONERO | Classification of traffic related to cryptocurrency Monero (XMR) mining and web traffic from web site. |
Infrastructure:HRPC | HPRC is used between client and NameNode machine. |
Web:DUCKDUCKGO | DuckDuckGo is an Internet search engine and a web browser for mobile devices |
Gaming:CALL-OF-DUTY | Call of duty (aka COD) is a video game First Personal Shooter (FPS) available on Xbox, PS4, Microsoft windows and published by Activision. This plugin classifies the World War II edition. |
Web:BYTEDANCE | ByteDance is a Chinese company that publishes several applications including TikTok (aka Musically), BuzzVideo and Vigo Video. This plugin classifies traffic from web site. |
Web:JIBE | Google provides a platform implementing Rich Communication Services (RCS) named Jibe Cloud. This plugin only handles traffic related to web page promoting Jibe Cloud, while Jibe Cloud platform is classified by jibe_cloud plugin. |
Web:WEBRTC | WebRtc is a free, open-source project that provides real-time communication (RTC) API for web browsers and mobile applications. |
Web:OPENLOAD | Openload is a file host combined with a streaming site. |
Infrastructure:MODBUS-RTU | Traffic related to Modbus Remote Terminal Unit (RTU), a distributed control system used in industrial process control (Emerson Process Management). |
Web:CISCO-CMX-CLOUD | Cisco Connected Mobile Experiences (CMX) Cloud is a cloud-delivered version of the on-premises CMX 10 software. CMX Cloud is used in the delivery of wireless services, integrating with the Cisco wireless infrastructure and creating out-of-the-box capabilities. |
Web:LEARNET | Learnet2.ns.sg is an online training website for Singaporean soldiers. This plugin classifies only the SSL traffic on learnet2.ns.sg. |
Infrastructure:BARRACUDA-VPN | Appliance edited by Barracuda and providing VPN service. This plugin classifies TINA protocol. |
Infrastructure:CISCO-AMC | This plugin classifies the protocol of CUCAM (Cisco Unified Communications Alert Manager and Collector). This service is used by CUC (Cisco Unified Communications) or the RTMT (Real-Time Monitoring Tool) to provide performance monitoring, data collection, logging, and alerting. |
Messaging:TALKRAY | Talkray is an instant messaging application. |
Infrastructure:OPERA-VPN | Opera VPN is a feature provided by Opera Web Browser. This feature provides VPN fonctionalities. |
Web:ACRONIS-CLOUD | Acronis Cloud is the cloud platform used by Acronis product, including Acronis Backup. |
Web:TIM | Tim is an Italian telecommunication company. This plugin classifies the website browsing. |
Infrastructure:KAFKA | High throughput distributed messaging system |
Web:VISUAL-IQ | Visual IQ is a marketing solution provider. |
Web:TENOR | Tenor is a GIF search engine. |
Web:BARRACUDA | Barracuda Networks, Inc. is a company providing security, networking and storage products based on network appliances and cloud services. This plugin classifies traffic related to Barracuda web site and its Could Control service. |
Multimedia:GAANA | Gaana is an application of musical streaming. |
Web:TECH-RADAR | TechRadar is a technology news web site. |
Web:RIPPLE | Ripple is a cryptocurrency but unlike other cryptocurrencies it is not based on a block chain. RippleNet design is more centralized. |
Web:TIANGE-9158 | Tiange 9158 is a social network that provides streaming and broadcast live video feature. This plugin does not support the traffic of broadcast of live video workflow. |
Infrastructure:ROCKWELL-RNA | Rockwell Network Applications (RNA) is Rockwell implementation of Windows DNA-M and is used for communication between Rockwell FactoryTalk products. |
Messaging:TEXTPLUS | textPlus is an instant messaging application which can send and receive sms / text / MMS / group messages to anyone in the US or Canada. |
Web:AWS-CONSOLE | AWS Console is a web application for managing Amazon Web Services. |
Web:ACRONIS | This plugin classifies flows related to Acronis products. |
Infrastructure:CODEMETER | Wibu Codemeter is a license server (Software Asset Management). This plugins classifies this product as used in FactoryTalk Activation Manager. |
Web:QUALTRICS | Qualtrics is a major online survey platform. This plugin classifies web site browsing. |
Messaging:VENTRILO | Ventrilo is a low-latency, encrypted voice chat software primarily intended for use while gaming. |
Multimedia:GVCP | GVCP stands for Give Vision Control Protocol a standard for industrial cameras supported by several companies. This plugin classifies GVCP traffic related to control and discovery. |
Web:ARTE-TV | Arte TV is a Franco-German television channel. This plugin classifies traffic generated by the website. |
Web:TARGET-COM | Target Corporation is the department store retailer in the United States. This plugin classifies traffic generated by Target website and Android application. |
Web:FOXNETWORKS | Fox Networks Group is a subsidiary of Fox Entertainment Group for television and cable. |
Web:W3SCHOOLS | W3Schools is an educational website for learning web technologies online (content includes tutorials and references). |
Gaming:WB-GAMES | This protocol plug-in classifies traffic related to Warner Bros Interactive Entertainment. Warner Bros. Interactive Entertainment (also known as WB Games) is the video game production arm of Warner Bros. |
Web:ROCKYOU | RockYou is a full-service entertainment and media company. |
Gaming:UBISOFT | Ubisoft is an online Game software editor and publisher (Far Cry, Assasin's Creed, Watchdogs...). |
Messaging:RING-CENTRAL | This plugin classifies website traffic of RingCentral, an application for video/audio conferencing. |
Web:PREZI | Prezi is a presentation software. This plugin classifies traffic generated by Individual Premium features. |
Web:TIM-VISION | Tim Vision is a smartphone application and web application provided by TIM (Italian telecom company). |
Web:YANDEX-TAXI | Yandex Taxi is a Russian online transportation network company which connects smartphone consumers looking for a trip with drivers. Yandex Taxi and Uber in Russia and East European countries had merged in 2017. |
Messaging:LIBON | Libon is an application that provides international audio call feature. This application is owned by Orange. |
Web:MYTV-SUPER | MyTV SUPER is an online video platform operated by TVB. This plugin classifies only website browsing. |
Multimedia:STARZ | Starz is an American cable and satellite television network. This plugin classifies traffic generated by Starz which is a website and mobile app that featured original programming and feature film content from Starz available for streaming. |
Infrastructure:HADOOP | Apache Hadoop is an open source tool that enables distributed parallel processing of huge amounts of data across servers that both store and process the data. |
Infrastructure:HEXATECH | hexatech is a vpn to unblock anonymously any site or app. |
Web:4SYNC | 4Sync is a cloud storage service. |
Web:ALIBABA-GROUP | Alibaba Group Holding Limited is a Chinese multinational conglomerate specializing in e-commerce, retail, Internet, AI and technology. This plugin is the default classification of domain names owned by Alibaba Group. |
Infrastructure:TOYO-PROTOCOL | This layer classifies only a limited number of protocols known to be used by Toyo hardware (PLC). |
Web:GOOGLE-BOOKS | On-line file storage and sharing web-service by Google. Important: most of the traffic is encrypted with generic Google certificates. The classification of this service then needs non-encrypted traffic to be injected. Classification is also correct for traffic under a proxy and some limited workflows. |
Web:FANDOM | A free Wiki website hosting service. |
Web:VUNGLE | Vungle is a mobile advertising platform. |
Infrastructure:DNS-CRYPT | The DNScrypt protocol is used to translate FQDN (Fully Qualified Domain Name) into address IP and vice versa with encrypted communication |
Messaging:LINE2-COM | Line2 (formerly Toktumi) is a telecommunication company that provides a second phone number for USA or Canada. |
Web:IRONSOURCE | IronSource is a digital content company. |
Web:SIMPLI-FI | Simpli.fi is an advertising technology company. |
Infrastructure:KODI | Kodi (formerly XBox Media Center) is a free media player sofware application. |
Web:GOV-SG | Gov.sg is the web portal for Singapore Government. This plugin classifies the website traffic. |
Web:BLUEHOST | Bluehost is a website hosting providers. This plugin classifies web site management traffic. |
Web:MEDIUM | Medium is an online publishing platform. |
Web:CISCO | Cisco Systems, Inc. is an American multinational technology. This plugin classifies the website browsing. |
Multimedia:HOOQ | HOOQ is a video on demand streaming service deployed in Asia (2018). |
Web:TIM-MUSIC | Tim Music is a smartphone application and web application provided by TIM (Italian telecom company). |
Web:GLOBE-TELCO | Globe Telecom is a provider of telecommunications services in the Philippines. The plugin classifies website traffic. |
Web:EVOZI | Evozi is an apk downloader website and also a mobile apps developer. This plugin classifies website traffic. |
Web:MOODLE | Moodle is an open-source learning platform (MOOC). This plugin classifies Moodle website, Moodle cloud instances and HTTP only local instances. |
Web:XMRPOOL-EU | Mining pool for cryptocurrency named Monero (blockchain). |
Web:ALIBABA-CLOUD | Alibaba Cloud, also known as Aliyun, is a Chinese cloud computing company, a subsidiary of Alibaba Group. |
Web:OPTIMICDN | OptimiCDN pilots multiple CDNs in an All-in-One Multi CDN service for optimized web performances & enhanced User Experience. |
Infrastructure:EXPRESSVPN | ExpressVPN is a provider of VPN tunnels with servers located in over 140 countries, a wide range of supported clients, and several standards or obfuscated protocols. This plugin classifies the website, the provided software, and manual setups using the ExpressVPN's provided configuration file. |
Web:LITRES-RU | This plugin classifies traffic generated by e-book reader applications Litres Audio and Listres Listen. |
Infrastructure:CISCO-NMSP | This protocol is used for data exchange between the Cisco Mobility Service Engine (MSE) and the Cisco Wireless LAN Controller (WLC). |
Web:PROTONMAIL | This plugin classifies ProtonMail website, webmail and mail applications. |
Infrastructure:HTTP-INJECTOR | HTTP Injector is a VPN tool. This plugin classifies the ssh tunneling. high_entropy plugin must be enabled to get shadowsocks classification. |
Web:WISH-COM | Wish is an e-commerce website and application. |
Infrastructure:SPRINGTECH-VPN | This plugin classifies traffic relative to VPN applications distributed by SpringTech company (namely Guangzhou Quanyong Information Technology Company), like Hot VPN, Turbo VPN, VPN Robot, Snap VPN, VPN Master Pro, VPN Monster, VPN Master. |
Infrastructure:WINDSCRIBE | Windscribe is a desktop application and browser extension that provide VPN and Ad blocker features. |
Messaging:KEKU | KeKu provides virtual phone numbers to make and receive calls, send and receive SMS. |
Web:NETIGATE | Netigate is an enterprise feedback management platform. This plugin classifies website traffic. |
Multimedia:RAKUTEN-TV | Rakuten TV is a video-on-demand (VOD) streaming service. This plugin classifies traffic for Europe and Japan. |
Gaming:BRAWLHALLA | Brawlhalla is a free to play battle arena on-line multiplayer game edited by Blue Mammoth Games and plublished by Ubisoft. |
Web:AIR-WATCH | Air Watch is a Mobile Device Management solution (MDM). This plugin classifies traffic generated by the cloud solution. |
Web:EASY-ANTI-CHEAT | Easy Anti-Cheat is an anti-cheat service for multiplayer PC games. |
Web:FAST-COM | Fast is a web service allowing to assess Internet throughput. This service is provided by Netflix. |
Web:PATREON | Patreon is a crowdfunding platform. |
Web:ACCOUNTKIT | Account Kit is a product of Facebook that lets people quickly register for and log in to some registered apps by using just their phone numbers or email addresses without needing a password. |
Web:24SEVENOFFICE | 24SevenOffice is a web-based Enterprise resource planning (ERP) systems. |
Web:HYPERS | HYPERS is a chinese cloud platform. This plugin classifies only website browsing. |
Web:JIBE-CLOUD | Jibe Cloud is a platform implementing Rich Communication Services (RCS) distributed by google to telecom operators integrating RCS. |
Messaging:TALKBOX | TalkBox is a mobile group chat application from Hong Kong with support for voice messages. |
Infrastructure:FIREFOX-VPN | Firefox Private Network is a Firefox extension which provides a secure and encrypted tunnel. |
Web:ROCKWELL | This plugin classifies the Rockwell Automation websites and related API. |
APPROOT:GOLANG | This plug-in classifies some web sites developped with go language (https://golang.org/) |
Web:FOXPLUS | Fox Plus is a streaming platform that let people watch Fox Networks' group latest TV series, documentaries, Hollywood & Asian movies. |
Web:DWARFPOOL-COM | Mining pool for cryptocurrency named Monero (blockchain). |
Infrastructure:COUCHBASE | Couchbase Server is a distributed, open source NoSQL database engine, storing key/values or JSON documents. |
Web:YOLO | Yolo is an application to send questions and answers to Snapchat users. Currently only available on iOS. |
Infrastructure:CISCO-SMARTPROBE | This are packets sent by Cisco PfRv3 enabled routers to measure link quality. |
Web:MEGAPHONE-FM | Megaphone provides podcast technology for publishers and advertisers. This plugin classifies only website traffic. |
Web:VPN1-COM | vpn1.com is a website hosting two popular anonymizing web proxies: Hoxx VPN and setupvpn. |
Multimedia:DAZN | DAZN is a video streaming service for sports. |
Web:GRAB | Grab Taxi is a company offering ride hailing service in South East of Asia. |
Web:GOOGLE-NEWS | Google News is a news aggregator and application developed by Google. |
Web:CODEPEN-IO | CodePen is an online community for testing and showcasing user-created HTML, CSS and JavaScript code snippets. This plugin classifies only traffic generated by the free plan. |
Messaging:VOXER | Voxer is an instant messaging application that provides voice, text, photo, and video with walkie talkie messaging (Push-to-talk PTT) features in a secure messaging app. |
Web:INMOJI | Inmoji provides advertising emojis. This plugin classifies traffic generated by the web site. |
Web:JSCOUNT | JsCount is a real-time website monitoring service for web server performance measurement. This plugin classifies website traffic. |
Web:MONEROHASH-COM | Mining pool for cryptocurrency named Monero (blockchain). |
Messaging:MTALK | Mtalk is an instant messaging application that can provide a landline phone number. |
Gaming:PLAYKOT | Playkot Ltd. is a mobile apps developer company |
Infrastructure:SYMANTEC-SEP | Symantec Endpoint Protection, developed by Symantec, is a security software suite, which consists of anti-malware, intrusion prevention and firewall features for servers and desktops. It has the largest market-share of any product for endpoint security. |
Web:AMAZON-COGNITO | Cognito is an Amazon AWS server allowing to keep track of user. |
Remote-Access:ARD | Apple Remote Desktop allows to manage Mac computers remotely. |
Infrastructure:REDIS | Redis is a data structure server. It is open-source, networked, in-memory, and stores keys with optional durability. |
Messaging:OTO-GLOBAL | OTO Global is an instant messaging application that provides feature to make landline or international calls. |
Multimedia:QUICKPLAY | Quickplay is a video service provider for IP connected devices. |
Messaging:FREEPP | FreePP is an instant messaging application, that provides domestic and international calls feature. This plugin only classifies the instant messaging traffic. |
Gaming:MOONTON | Moonton is a video game editor. |
Web:ANONYTUN-VPN | AnonyTun is an android VPN client offering to their users to customize a few parameters related to tunnel. |
Web:STOREBUFF | Storebuff tests and analyzes network traffic from a given URL. This plugin classifies traffic from web site. |
Web:GCASH | Gcash is a mobile payment application. The plugin classifies website traffic. |
Infrastructure:TURBO-VPN | This protocol plug-in is deprecated. |
Web:FACE-APP | FaceApp is a mobile application to transform faces in photographs. This plugin classifies traffic from free version. Picture uploads to the mobile application use separate cloud storage services and are classified separately. |
Web:MYNT | Mynt is a FinTech startup wholly-owned by Globe Telecom. The plugin classifies website traffic. |
Multimedia:I-WANT-TV | IWant TV is an over-the-top content (OTT) platform exclusively available in the Philippines. |
Web:BIGBIGCHANNEL | Big Big Channel is an online video platform operated by TVB. |
Web:NS-SG | Ns.sg is the web portal for the National Service in Singapore. This plugin classifies the website traffic. |
Multimedia:STAN | Stan is an Australian streaming company. Stan is owned by StreamCo. |
Web:DISCOURSE | Discourse is an open source Internet forum and mailing list management software application. |
Infrastructure:HOT-VPN | This protocol plug-in is deprecated. |
Web:JUMPSHARE | Jumpshare is a file sharing service. This plugin classifies traffic generated by the basic offer. |
Multimedia:STREAMCO-MEDIA | StreamCo Media, Ltd., is a streaming media solutions company. |
Web:CAKE-HR | CakeHR is an online HR management software. |
Multimedia:NETFLIX-VIDEO | Classify traffic related to Netflix Streaming service. Most of that traffic goes to Open Connect Appliances (https://openconnect.netflix.com) which are deployed on ISP/IXP side to speed up throughput and so user experience. Fast.com is a Netflix application using the same servers to assess quality of Internet connection to Netflix service. |
Web:MOJOMARKETPLACE | MOJO Marketplace offers themes, plugins and professional services for website creation on wordpress. |
Web:CRYPTO-POOL-FR | Mining pool for cryptocurrency named Monero (blockchain). |
Infrastructure:X-VPN | x-vpn unblock the web securely, privately and anonymously on your Android devices. x-vpn was formely FastLemon VPN |
Messaging:TEXTME | Text Me is an instant messaging application which can make texting and calling to any phone and make national and international calls. |
Infrastructure:ERLANG-DISTRIBUTION | Erlang distribution protocol allows several node to communicate together and exchange information. |
Infrastructure:CISCO-SDAVC | Cisco Software-Defined AVC (SD-AVC) is a component of Cisco Application Visibility and Control (AVC). It works as a centralized network service, operating with specific participating devices in a network. |
Web:HOXX-VPN | Hoxx VPN is a popular anonymizing web proxy. |
Web:CISCO-CORP-TV | Cisco Corporate TV is an interactive web streaming, and live studio shows platform. |
Web:HBO | Home Box Office (or HBO) is an American pay TV channel. This plugin classifies website traffic. |
Infrastructure:IEC61850-SV | IEC 61850 Sampled Measured Values (SMV or SV) is protocol used in Electrical substations to share data between Intelligent Electronic Device (IED) under hard real time constraints (IEC 61850-9-2). |
Multimedia:IFLIX | Iflix is a video streaming application based on the Akamai cloud service. |
Messaging:TIKTOK | TikTok is a social network application acquired by ByteDance and previously known as Musical.ly. It allows its users to share live stream video content. |
Web:TESLA | Tesla, Inc. is an American automotive and energy company. This plugin classifies website traffic. |
Infrastructure:TANIUM | This plugin classifies Tanium Client traffic. Tanium is an Endpoint Detection and Response (EDR) solution. It is Endpoint Management System to protect entreprise against cyber threats. |
Infrastructure:SIGNIANT | Media Shuttle is a cloud based file sharing solution from Signiant targeting high volume transfers. It have enterprise work flows management capabilities. This plugin classifies Signiant web site, MediaShuttle web interface, Signiant file transfer protocol. |
Multimedia:VIU | Viu is an Asian streaming application. |
Web:TIBCO | This protocol is a generic layer used as a base for all the Tibco protocols. |
Infrastructure:EPDG-TUNNEL | This plugin classifies the traffic coming from WLAN between a user equipment (UE) and the ePDG (evolved Packet Data Gateway) in order to access the IMS (IP Multimedia Subsytem). |
Infrastructure:HDFS | Protocol used by Hadoop to store and exchange data across a cluster. |
Infrastructure:UDT | This plugin supports fourth version of UDT (https://tools.ietf.org/html/draft-gg-udt-03) over UDP. This protocol is involved in GridFTP infrastructure. It is a protocol for high performance data transfer with multiplexing and session control. |
Web:DIDI | Didi is a shared transport application. This plugin add classification of traffic generated by Android and iOS platforms. |
Web:GOOGLE-TAKEOUT | Google Takeout allows users of Google products to export their data to a downloadable archive file. The download is classified as gstatic. |
Web:MINERGATE-COM | Mining pool for cryptocurrency named Monero (blockchain). |
Gaming:MOJANG | Mojang is a video game and software development corporation. |
Messaging:CISCO-UCM | Cisco Unified Communication Manager is an IP PBX for enterprises. This plugin classify Cisco specific protocols between Cisco Unified Communication components and devices; and classifies the administration web interface. |
Web:JSFIDDLE | JSFiddle is an Online web tools development. |
Infrastructure:TUNNELBEAR | TunnelBear VPN is a desktop application and browser extension that provide VPN. |
Infrastructure:HBASE | Hbase is a distributed database based on Google Bigtable. |
Messaging:VONAGE-MOBILE | Vonage Mobile is an instant messaging application that provides feature to make landline or international calls. |
Infrastructure:VPN-MASTERPRO | This protocol plug-in is deprecated. |
Web:GOOGLE-API | Google APIs is a set of application programming interfaces (APIs) developed by Google which allow communication with Google Services and their integration to other services. |
Web:PUBNUB | PubNub is a global Data Stream Network. This plugin classifies only website traffic. |
Infrastructure:ANCHORFREE | AnchorFree is an anonymous VPN software released by Betternet (formerly vpnintouch) company. Betternet was bought by AnchorFree in 2015. |
Gaming:UNITY | Unity is a 3D engine supported by more that 25 platforms. This plugin focuses on the video game services. |
Gaming:SOURCE-ENGINE | This plugin classifies online games using Valve's Source engine, such as HalfLife, CounterStrike, TeamFortress. Some game servers will be classified as Steam protocol |
Infrastructure:FTPS-DATA | FTP is a communication protocol made for share files in the network TCP/IP |
Multimedia:CMORE | CMORE is a swedish distributor of paid videos on demand. |
Infrastructure:HIDEMAN-VPN | Hideman VPN is an application and browser extension that provides VPN features. |
Messaging:ALICALL | Alicall is a chinese application that provide International VoIP call feature. |
Gaming:REALVNC | RealVNC is a company that provides remote access software. |
Infrastructure:ACRONIS-BACKUP | Acronis Backup is a backup platform that use cloud or local storage and can save multiple hosts using agents. Online storage is classified as acronis_cloud. |
Infrastructure:SNAP-VPN | This protocol plug-in is deprecated. |
Infrastructure:ANYWHEREUSB | This layer classifies traffic from TCP/3422 related to actual data carried out by AnywhereUSB devices connected to it. Those data are in clear text. |
Messaging:ETISALAT-C-ME | C'Me, developed by Etisalat, is a mobile application offering voice and video calls along with instant messaging. |
Messaging:YAHOO-TOGETHER | Yahoo Together is a group messaging application. Known by its project name Squirrel, it replaces Yahoo web messenger. |
3 updated signatures:
CRITICAL | HTTP:HPE-IMC-EXP-INJ | HTTP: HPE-Intelligent Management Center Remote Code Execution |
MEDIUM | HTTP:SCRIPT-INJ-VUL-117 | HTTP: SCRIPT-INJ Infection-117 |
MEDIUM | SHELLCODE:X86:BUFFER-SHELL | SHELLCODE: X86 Buffer Overflow HTTP-STC |
2 renamed application2 signatures:
Web:Advertisements:google-adservices-ssl | -> | Web:Advertisements:google-ads |
Infrastructure:ge-procify | -> | Infrastructure:ge-proficy |
9 deleted signatures:
HTTP:HPE-CVE-2019-11941-EL | HTTP: HPE Intelligent Management Center CVE-2019-11941 Expression Language Injection |
HTTP:CTS:HPE-IMC-EXP-LANG-INJ | HTTP: HPE IMC CustomReportTemplateSelectBean Expression Language Injection |
HTTP:MISC:HPE-IMC-ELINJ | HTTP: HPE Intelligent Management Center SoapConfigBean Expression Language Injection |
HTTP:CTS-HPE-IMC-RCE | HTTP: HPE Intelligent Management Center iccSelectCommand Expression Language Injection |
HTTP:CTS:HPE-IMC-EXPINJ | HTTP: HPE IMC devGroupSelect Expression Language Injection |
HTTP:HPE-IMCP-URL-RCE | HTTP: HPE Intelligent Management Center PlatNavigationToBean URL Expression Language Injection |
HTTP:HPE-INJECTION-RCE | HTTP: HPE Intelligent Management Center wmiConfigContent Expression Language Injection |
HTTP:CTS:HPE-IMC-FR-EL-CI | HTTP: HPE IMC ForwardRedirect Expression Language Injection |
HTTP:MISC:HPE-IMC-OPETATOR-CE | HTTP: HPE IMC OperatorGroupTreeSelectBean Expression Language Injection |
C'Me, developed by Etisalat, is a mobile application offering voice and video calls along with instant messaging.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
An Expression Language injection vulnerability has been reported in HPE Intelligent Management Center. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server. Successful exploitation results in the execution of arbitrary code under the security context of the SYSTEM user
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, idp-5.0.0, vsrx-17.4, srx-branch-17.4, srx-17.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, isg-3.5.141818, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.0.0, idp-5.1.110170603, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against HPE Intelligent Management Center. A successful attack can lead to command injection and arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against HPE IMC. A successful attack can lead to expression language injection and arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1
This signature scans HTTP data for a x86 shellcode instruction sequence, resulting in buffer overflow exploit.
idp-5.1.110161014, idp-4.1.0, mx-16.1, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, srx-17.4, idp-5.1.110170603, vsrx3bsd-18.2, srx-18.2, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, srx-branch-19.1, vsrx-19.2, srx-19.2, srx-branch-19.2, vsrx3bsd-19.2, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, j-series-9.5, mx-11.4, srx-12.1, srx-branch-12.1, vsrx-12.1, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against HPE IMC. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1
Google Ads is the online ad service from Google.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against HPE Intelligent Management Center. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1
Proficy is a General Electric product for industrial environment allowing monitoring and data management from SCADA network. This plugin classifies traffic related to Proficy Gateway service (PR Gateway) and Proficy Licensing server (PR Licensing)
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This signature detects Graboid, an application that searches the internet for videos and makes it simple to view them as a streaming video.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classify injustice 2 web site. Injustice 2 is an online game edited by NetherRealm Studios and published by Warner Bros.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Hike Messenger is an Indian instant messaging application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Inskin is a media advertising company.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
mobile_legends provide in-App communication cloud services for games.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
League of Legends is a popular Multiplayer Online Battle Arena video game developed by Riot Games.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Youme provides in-App communication cloud services for games.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
FullStory is a digital analytics platform. This plugin classifies website traffic
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
IBM (International Business Machines Corporation) is an American multinational technology company.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
China International Broadcasting Network (CIBN) is an internet TV platform. This plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Gaode Map is a chinese online mapping service. Gaode Map belongs to Alibaba Group which has acquired AutoNavi which offers its map services at Amap.com. It is also known as Gaode in China.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Google Video hosting service provides video streaming to Google Youtube applications (Youtube, Kids, Music and Google Program such Youtube Premium).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Appnext is mobile monetization, app marketing & re-engagement platform.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
CyberGhost is a VPN service used to unblock sites and browse privately and anonymously.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mondia Media is a content and entertainment services provider. This plugin classifies website browsing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Harry Potter: Wizards Unite is an online mobile game developed by Niantic Labs.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
DICOM stands for Digital Imaging and Communications in Medicine, supported traffic on usual TCP port 104, 11112 (decrypted traffic, no support of DICOM-TLS or DICOM-ISCL).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Rakuten Video hosting service provides video streaming to Rakuten TV application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Monday.com is a collaboration solution for enterprise.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tribair is an VoIP application for national and international audio calls.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
blog.google is the public blog of Google (products, news, ...).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Classification of traffic related to cryptocurrency Monero (XMR) mining and web traffic from web site.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mumble is an open source, low-latency, high quality voice chat software primarily intended for use while gaming.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
YOPmail is a disposable email platform. YOPmail provides a fake temporary and anonymous email address.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Coco is an instant messaging application with VoIP feature.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Google One is a service for managing the storage paid plan for Google applications.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
9gag is a humorous website or application based on the sharing of images and videos.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol plug-in is deprecated.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tikl is a simple VoIP push-to-talk communication application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tibbr is a social network for work. This plugin classifies traffic generated by the website browsing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
ICF Technology is a provider of high-definition video streaming and credit card processing services. Numerous adult content services have icf_technology as a subflow.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol plug-in is deprecated.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Apple News is a mobile app and news aggregator developed by Apple Inc.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Age of Magic is a single player video game for mobile platforms.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
DemonWare is a software development company and a subsidiary of Activision Blizzard, Inc.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Cisco IP SLA is used to monitor IP applications by using active traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Standard iOS application to buy, read and manage books and audio books.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Grammarly is a cloud-based English-language writing-enhancement platform.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Splunk Cloud is the data collection, indexing, and visualization service for operational intelligence.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Fuze (formerly known as ThinkingPhones) is a provider of cloud-based Unified Communications as a Service (UCaaS).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
PCCC stands for "Programmable Controller Communication Commands", it is used to control software running in Programmable Logic Controler (PLC). PCCC traffic can be hardware specific, this plugin addresses traffic generated by Rockwell/Allen-Bradley to talk to SLC5, PLC5E and MicroLogix PLC for service.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
OpenSignal is a company that specializes in wireless coverage mapping. This plugin classifies traffic of OpenSignal traffic on iOS and Android platform.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
The Dragon Ball video game series are based on the manga and anime. This plugin classifies traffic generated by DRAGON BALL FighterZ video game.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Lifesize is a video and audio telecommunications company. This plugin classifies traffic generated on Android and Chrome platforms.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol plug-in is deprecated.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Future Plc is a British publisher media company.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mining pool for cryptocurrency named Monero (blockchain).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Vyke is an IM allowing to buy phone number from countries such US, UK, Canada and do VoIP, text messaging (SMS), and usual chat (File transfer/text).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Television Broadcasts Limited is a Hong Kong audio-visual group. This plugin classifies only website browsing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Eproxy is a VPN for forward proxies with custom payload and optional ssh support. This plugin classifies automatically generated fake HTTP headers and the embedded ssh clients.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Discord is a chat, audio and video call application for gaming.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Trello is list making application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
BIGO Technology, a Singapore-based social media company.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tweakware is a vpn application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Classification of traffic related to cryptocurrency Monero (XMR) mining and web traffic from web site.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
HPRC is used between client and NameNode machine.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
DuckDuckGo is an Internet search engine and a web browser for mobile devices
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Call of duty (aka COD) is a video game First Personal Shooter (FPS) available on Xbox, PS4, Microsoft windows and published by Activision. This plugin classifies the World War II edition.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
ByteDance is a Chinese company that publishes several applications including TikTok (aka Musically), BuzzVideo and Vigo Video. This plugin classifies traffic from web site.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Google provides a platform implementing Rich Communication Services (RCS) named Jibe Cloud. This plugin only handles traffic related to web page promoting Jibe Cloud, while Jibe Cloud platform is classified by jibe_cloud plugin.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
WebRtc is a free, open-source project that provides real-time communication (RTC) API for web browsers and mobile applications.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Openload is a file host combined with a streaming site.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Traffic related to Modbus Remote Terminal Unit (RTU), a distributed control system used in industrial process control (Emerson Process Management).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Cisco Connected Mobile Experiences (CMX) Cloud is a cloud-delivered version of the on-premises CMX 10 software. CMX Cloud is used in the delivery of wireless services, integrating with the Cisco wireless infrastructure and creating out-of-the-box capabilities.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Learnet2.ns.sg is an online training website for Singaporean soldiers. This plugin classifies only the SSL traffic on learnet2.ns.sg.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Appliance edited by Barracuda and providing VPN service. This plugin classifies TINA protocol.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies the protocol of CUCAM (Cisco Unified Communications Alert Manager and Collector). This service is used by CUC (Cisco Unified Communications) or the RTMT (Real-Time Monitoring Tool) to provide performance monitoring, data collection, logging, and alerting.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Talkray is an instant messaging application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Opera VPN is a feature provided by Opera Web Browser. This feature provides VPN fonctionalities.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Acronis Cloud is the cloud platform used by Acronis product, including Acronis Backup.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tim is an Italian telecommunication company. This plugin classifies the website browsing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
High throughput distributed messaging system
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Visual IQ is a marketing solution provider.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tenor is a GIF search engine.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Barracuda Networks, Inc. is a company providing security, networking and storage products based on network appliances and cloud services. This plugin classifies traffic related to Barracuda web site and its Could Control service.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Gaana is an application of musical streaming.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
TechRadar is a technology news web site.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Ripple is a cryptocurrency but unlike other cryptocurrencies it is not based on a block chain. RippleNet design is more centralized.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tiange 9158 is a social network that provides streaming and broadcast live video feature. This plugin does not support the traffic of broadcast of live video workflow.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Rockwell Network Applications (RNA) is Rockwell implementation of Windows DNA-M and is used for communication between Rockwell FactoryTalk products.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
textPlus is an instant messaging application which can send and receive sms / text / MMS / group messages to anyone in the US or Canada.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
AWS Console is a web application for managing Amazon Web Services.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies flows related to Acronis products.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Wibu Codemeter is a license server (Software Asset Management). This plugins classifies this product as used in FactoryTalk Activation Manager.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Qualtrics is a major online survey platform. This plugin classifies web site browsing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Ventrilo is a low-latency, encrypted voice chat software primarily intended for use while gaming.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
GVCP stands for Give Vision Control Protocol a standard for industrial cameras supported by several companies. This plugin classifies GVCP traffic related to control and discovery.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Arte TV is a Franco-German television channel. This plugin classifies traffic generated by the website.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Target Corporation is the department store retailer in the United States. This plugin classifies traffic generated by Target website and Android application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Fox Networks Group is a subsidiary of Fox Entertainment Group for television and cable.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
W3Schools is an educational website for learning web technologies online (content includes tutorials and references).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol plug-in classifies traffic related to Warner Bros Interactive Entertainment. Warner Bros. Interactive Entertainment (also known as WB Games) is the video game production arm of Warner Bros.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
RockYou is a full-service entertainment and media company.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Ubisoft is an online Game software editor and publisher (Far Cry, Assasin's Creed, Watchdogs...).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies website traffic of RingCentral, an application for video/audio conferencing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Prezi is a presentation software. This plugin classifies traffic generated by Individual Premium features.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tim Vision is a smartphone application and web application provided by TIM (Italian telecom company).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Yandex Taxi is a Russian online transportation network company which connects smartphone consumers looking for a trip with drivers. Yandex Taxi and Uber in Russia and East European countries had merged in 2017.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Libon is an application that provides international audio call feature. This application is owned by Orange.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
MyTV SUPER is an online video platform operated by TVB. This plugin classifies only website browsing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Starz is an American cable and satellite television network. This plugin classifies traffic generated by Starz which is a website and mobile app that featured original programming and feature film content from Starz available for streaming.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Apache Hadoop is an open source tool that enables distributed parallel processing of huge amounts of data across servers that both store and process the data.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
hexatech is a vpn to unblock anonymously any site or app.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
4Sync is a cloud storage service.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Alibaba Group Holding Limited is a Chinese multinational conglomerate specializing in e-commerce, retail, Internet, AI and technology. This plugin is the default classification of domain names owned by Alibaba Group.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This layer classifies only a limited number of protocols known to be used by Toyo hardware (PLC).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
On-line file storage and sharing web-service by Google. Important: most of the traffic is encrypted with generic Google certificates. The classification of this service then needs non-encrypted traffic to be injected. Classification is also correct for traffic under a proxy and some limited workflows.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
A free Wiki website hosting service.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Vungle is a mobile advertising platform.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
The DNScrypt protocol is used to translate FQDN (Fully Qualified Domain Name) into address IP and vice versa with encrypted communication
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Line2 (formerly Toktumi) is a telecommunication company that provides a second phone number for USA or Canada.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
IronSource is a digital content company.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Simpli.fi is an advertising technology company.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Kodi (formerly XBox Media Center) is a free media player sofware application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Gov.sg is the web portal for Singapore Government. This plugin classifies the website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Bluehost is a website hosting providers. This plugin classifies web site management traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Medium is an online publishing platform.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Cisco Systems, Inc. is an American multinational technology. This plugin classifies the website browsing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
HOOQ is a video on demand streaming service deployed in Asia (2018).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tim Music is a smartphone application and web application provided by TIM (Italian telecom company).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Globe Telecom is a provider of telecommunications services in the Philippines. The plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Evozi is an apk downloader website and also a mobile apps developer. This plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Moodle is an open-source learning platform (MOOC). This plugin classifies Moodle website, Moodle cloud instances and HTTP only local instances.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mining pool for cryptocurrency named Monero (blockchain).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Alibaba Cloud, also known as Aliyun, is a Chinese cloud computing company, a subsidiary of Alibaba Group.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
OptimiCDN pilots multiple CDNs in an All-in-One Multi CDN service for optimized web performances & enhanced User Experience.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
ExpressVPN is a provider of VPN tunnels with servers located in over 140 countries, a wide range of supported clients, and several standards or obfuscated protocols. This plugin classifies the website, the provided software, and manual setups using the ExpressVPN's provided configuration file.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies traffic generated by e-book reader applications Litres Audio and Listres Listen.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol is used for data exchange between the Cisco Mobility Service Engine (MSE) and the Cisco Wireless LAN Controller (WLC).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies ProtonMail website, webmail and mail applications.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
HTTP Injector is a VPN tool. This plugin classifies the ssh tunneling. high_entropy plugin must be enabled to get shadowsocks classification.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Wish is an e-commerce website and application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies traffic relative to VPN applications distributed by SpringTech company (namely Guangzhou Quanyong Information Technology Company), like Hot VPN, Turbo VPN, VPN Robot, Snap VPN, VPN Master Pro, VPN Monster, VPN Master.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Windscribe is a desktop application and browser extension that provide VPN and Ad blocker features.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
KeKu provides virtual phone numbers to make and receive calls, send and receive SMS.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Netigate is an enterprise feedback management platform. This plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Rakuten TV is a video-on-demand (VOD) streaming service. This plugin classifies traffic for Europe and Japan.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Brawlhalla is a free to play battle arena on-line multiplayer game edited by Blue Mammoth Games and plublished by Ubisoft.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Air Watch is a Mobile Device Management solution (MDM). This plugin classifies traffic generated by the cloud solution.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Easy Anti-Cheat is an anti-cheat service for multiplayer PC games.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Fast is a web service allowing to assess Internet throughput. This service is provided by Netflix.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Patreon is a crowdfunding platform.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Account Kit is a product of Facebook that lets people quickly register for and log in to some registered apps by using just their phone numbers or email addresses without needing a password.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
24SevenOffice is a web-based Enterprise resource planning (ERP) systems.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
HYPERS is a chinese cloud platform. This plugin classifies only website browsing.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Jibe Cloud is a platform implementing Rich Communication Services (RCS) distributed by google to telecom operators integrating RCS.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
TalkBox is a mobile group chat application from Hong Kong with support for voice messages.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Firefox Private Network is a Firefox extension which provides a secure and encrypted tunnel.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies the Rockwell Automation websites and related API.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plug-in classifies some web sites developped with go language (https://golang.org/)
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Fox Plus is a streaming platform that let people watch Fox Networks' group latest TV series, documentaries, Hollywood & Asian movies.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mining pool for cryptocurrency named Monero (blockchain).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Couchbase Server is a distributed, open source NoSQL database engine, storing key/values or JSON documents.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Yolo is an application to send questions and answers to Snapchat users. Currently only available on iOS.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This are packets sent by Cisco PfRv3 enabled routers to measure link quality.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Megaphone provides podcast technology for publishers and advertisers. This plugin classifies only website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
vpn1.com is a website hosting two popular anonymizing web proxies: Hoxx VPN and setupvpn.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
DAZN is a video streaming service for sports.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Grab Taxi is a company offering ride hailing service in South East of Asia.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Google News is a news aggregator and application developed by Google.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
CodePen is an online community for testing and showcasing user-created HTML, CSS and JavaScript code snippets. This plugin classifies only traffic generated by the free plan.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Voxer is an instant messaging application that provides voice, text, photo, and video with walkie talkie messaging (Push-to-talk PTT) features in a secure messaging app.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Inmoji provides advertising emojis. This plugin classifies traffic generated by the web site.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
JsCount is a real-time website monitoring service for web server performance measurement. This plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mining pool for cryptocurrency named Monero (blockchain).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mtalk is an instant messaging application that can provide a landline phone number.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Playkot Ltd. is a mobile apps developer company
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Symantec Endpoint Protection, developed by Symantec, is a security software suite, which consists of anti-malware, intrusion prevention and firewall features for servers and desktops. It has the largest market-share of any product for endpoint security.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Cognito is an Amazon AWS server allowing to keep track of user.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Apple Remote Desktop allows to manage Mac computers remotely.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Redis is a data structure server. It is open-source, networked, in-memory, and stores keys with optional durability.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
OTO Global is an instant messaging application that provides feature to make landline or international calls.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Quickplay is a video service provider for IP connected devices.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
FreePP is an instant messaging application, that provides domestic and international calls feature. This plugin only classifies the instant messaging traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Moonton is a video game editor.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
AnonyTun is an android VPN client offering to their users to customize a few parameters related to tunnel.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Storebuff tests and analyzes network traffic from a given URL. This plugin classifies traffic from web site.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Gcash is a mobile payment application. The plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol plug-in is deprecated.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
FaceApp is a mobile application to transform faces in photographs. This plugin classifies traffic from free version. Picture uploads to the mobile application use separate cloud storage services and are classified separately.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mynt is a FinTech startup wholly-owned by Globe Telecom. The plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
IWant TV is an over-the-top content (OTT) platform exclusively available in the Philippines.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Big Big Channel is an online video platform operated by TVB.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Ns.sg is the web portal for the National Service in Singapore. This plugin classifies the website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Stan is an Australian streaming company. Stan is owned by StreamCo.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Discourse is an open source Internet forum and mailing list management software application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol plug-in is deprecated.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Jumpshare is a file sharing service. This plugin classifies traffic generated by the basic offer.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
StreamCo Media, Ltd., is a streaming media solutions company.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
CakeHR is an online HR management software.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Classify traffic related to Netflix Streaming service. Most of that traffic goes to Open Connect Appliances (https://openconnect.netflix.com) which are deployed on ISP/IXP side to speed up throughput and so user experience. Fast.com is a Netflix application using the same servers to assess quality of Internet connection to Netflix service.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
MOJO Marketplace offers themes, plugins and professional services for website creation on wordpress.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mining pool for cryptocurrency named Monero (blockchain).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
x-vpn unblock the web securely, privately and anonymously on your Android devices. x-vpn was formely FastLemon VPN
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Text Me is an instant messaging application which can make texting and calling to any phone and make national and international calls.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Erlang distribution protocol allows several node to communicate together and exchange information.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Cisco Software-Defined AVC (SD-AVC) is a component of Cisco Application Visibility and Control (AVC). It works as a centralized network service, operating with specific participating devices in a network.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Hoxx VPN is a popular anonymizing web proxy.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Cisco Corporate TV is an interactive web streaming, and live studio shows platform.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Home Box Office (or HBO) is an American pay TV channel. This plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
IEC 61850 Sampled Measured Values (SMV or SV) is protocol used in Electrical substations to share data between Intelligent Electronic Device (IED) under hard real time constraints (IEC 61850-9-2).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Iflix is a video streaming application based on the Akamai cloud service.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
TikTok is a social network application acquired by ByteDance and previously known as Musical.ly. It allows its users to share live stream video content.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Tesla, Inc. is an American automotive and energy company. This plugin classifies website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies Tanium Client traffic. Tanium is an Endpoint Detection and Response (EDR) solution. It is Endpoint Management System to protect entreprise against cyber threats.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Media Shuttle is a cloud based file sharing solution from Signiant targeting high volume transfers. It have enterprise work flows management capabilities. This plugin classifies Signiant web site, MediaShuttle web interface, Signiant file transfer protocol.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Viu is an Asian streaming application.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol is a generic layer used as a base for all the Tibco protocols.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies the traffic coming from WLAN between a user equipment (UE) and the ePDG (evolved Packet Data Gateway) in order to access the IMS (IP Multimedia Subsytem).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Protocol used by Hadoop to store and exchange data across a cluster.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin supports fourth version of UDT (https://tools.ietf.org/html/draft-gg-udt-03) over UDP. This protocol is involved in GridFTP infrastructure. It is a protocol for high performance data transfer with multiplexing and session control.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Didi is a shared transport application. This plugin add classification of traffic generated by Android and iOS platforms.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Google Takeout allows users of Google products to export their data to a downloadable archive file. The download is classified as gstatic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mining pool for cryptocurrency named Monero (blockchain).
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Mojang is a video game and software development corporation.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Cisco Unified Communication Manager is an IP PBX for enterprises. This plugin classify Cisco specific protocols between Cisco Unified Communication components and devices; and classifies the administration web interface.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
JSFiddle is an Online web tools development.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
TunnelBear VPN is a desktop application and browser extension that provide VPN.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Hbase is a distributed database based on Google Bigtable.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Vonage Mobile is an instant messaging application that provides feature to make landline or international calls.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol plug-in is deprecated.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Google APIs is a set of application programming interfaces (APIs) developed by Google which allow communication with Google Services and their integration to other services.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
PubNub is a global Data Stream Network. This plugin classifies only website traffic.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
AnchorFree is an anonymous VPN software released by Betternet (formerly vpnintouch) company. Betternet was bought by AnchorFree in 2015.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Unity is a 3D engine supported by more that 25 platforms. This plugin focuses on the video game services.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This plugin classifies online games using Valve's Source engine, such as HalfLife, CounterStrike, TeamFortress. Some game servers will be classified as Steam protocol
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
FTP is a communication protocol made for share files in the network TCP/IP
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
CMORE is a swedish distributor of paid videos on demand.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Hideman VPN is an application and browser extension that provides VPN features.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Alicall is a chinese application that provide International VoIP call feature.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
RealVNC is a company that provides remote access software.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
Acronis Backup is a backup platform that use cloud or local storage and can save multiple hosts using agents. Online storage is classified as acronis_cloud.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This protocol plug-in is deprecated.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This layer classifies traffic from TCP/3422 related to actual data carried out by AnywhereUSB devices connected to it. Those data are in clear text.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against Adobe Acrobat and Reader. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.1.0, mx-16.1, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, srx-17.4, idp-5.1.110170603, vsrx3bsd-18.2, srx-18.2, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, srx-branch-19.1, vsrx-19.2, srx-19.2, srx-branch-19.2, vsrx3bsd-19.2, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, j-series-9.5, mx-11.4, srx-12.1, srx-branch-12.1, vsrx-12.1, vsrx-15.1
Yahoo Together is a group messaging application. Known by its project name Squirrel, it replaces Yahoo web messenger.
mx-11.4, srx-12.1, srx-branch-12.1, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against Adobe Acrobat and Reader. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.1.0, mx-16.1, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, srx-17.4, idp-5.1.110170603, vsrx3bsd-18.2, srx-18.2, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, srx-branch-19.1, vsrx-19.2, srx-19.2, srx-branch-19.2, vsrx3bsd-19.2, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, j-series-9.5, mx-11.4, srx-12.1, srx-branch-12.1, vsrx-12.1, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against Adobe Acrobat and Reader. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.1.0, mx-16.1, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, srx-17.4, idp-5.1.110170603, vsrx3bsd-18.2, srx-18.2, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, srx-branch-19.1, vsrx-19.2, srx-19.2, srx-branch-19.2, vsrx3bsd-19.2, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, j-series-9.5, mx-11.4, srx-12.1, srx-branch-12.1, vsrx-12.1, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against HPE Intelligent Management Center. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against HPE Intelligent Management Center. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against Microsoft Win32k Kernel Driver. A successful attack can lead to elevation of privilege and arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, idp-5.0.0, vsrx-17.4, srx-branch-17.4, srx-17.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, isg-3.5.141818, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.0.0, idp-5.1.110170603, vsrx-15.1
This signature detects an attempt to download exploits from malicious exploit kits that may compromise a computer through various vendor vulnerabilities. Exploit kits are very specific type of toolkits which are being used by cybercriminals to deliver other pieces of malware.
srx-17.3, vsrx-17.4, srx-17.4, vsrx3bsd-18.2, srx-18.2, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, vsrx-19.2, srx-19.2, vsrx3bsd-19.2, srx-19.4, vsrx3bsd-19.4, vsrx-19.4, vsrx-15.1, srx-12.1
This signature detects attempts to exploit a known vulnerability against Microsoft Windows DirectX Kernel Driver. A successful attack can lead to elevation of privilege and arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, idp-5.0.0, vsrx-17.4, srx-branch-17.4, srx-17.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, isg-3.5.141818, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.0.0, idp-5.1.110170603, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against Intel Active Management Technology and Intel Standard Manageability. A successful attack can lead to elevation of privilege and arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, srx-17.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, idp-5.1.110170603, vsrx-15.1
This signature detects an attempt to download exploits from malicious exploit kits that may compromise a computer through various vendor vulnerabilities. Exploit kits are very specific type of toolkits which are being used by cybercriminals to deliver other pieces of malware.
srx-17.3, vsrx-17.4, srx-17.4, vsrx3bsd-18.2, srx-18.2, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, vsrx-19.2, srx-19.2, vsrx3bsd-19.2, srx-19.4, vsrx3bsd-19.4, vsrx-19.4, vsrx-15.1, srx-12.1
This signature detects attempts to exploit a known vulnerability against HPE Intelligent Management Center. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1
This signature detects attempts to exploit a known vulnerability against HPE Intelligent Management Center. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1
This signature detects an attempt to download exploits from malicious exploit kits that may compromise a computer through various vendor vulnerabilities. Exploit kits are very specific type of toolkits which are being used by cybercriminals to deliver other pieces of malware.
srx-17.3, vsrx-17.4, srx-17.4, vsrx3bsd-18.2, srx-18.2, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, vsrx-19.2, srx-19.2, vsrx3bsd-19.2, srx-19.4, vsrx3bsd-19.4, vsrx-19.4, vsrx-15.1, srx-12.1
This signature detects attempts to exploit a known vulnerability against HPE Intelligent Management Center. A successful attack can lead to arbitrary code execution.
idp-5.1.110161014, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, mx-16.1, idp-4.2.0, srx-17.3, vmx-17.4, isg-3.5.141818, vsrx-17.4, srx-branch-17.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, vsrx3bsd-18.2, isg-3.5.0, srx-19.1, vsrx3bsd-19.1, vsrx-19.1, j-series-9.5, vsrx-19.2, srx-19.2, srx-branch-19.2, idp-4.2.110100823, srx-19.4, vsrx3bsd-19.4, srx-branch-19.4, vsrx-19.4, vmx-19.4, mx-19.4, idp-4.2.110101203, idp-5.1.0, srx-branch-19.1, idp-4.1.110110609, idp-4.1.110110719, mx-11.4, vsrx3bsd-19.2, idp-5.0.0, srx-18.2, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, srx-17.4, idp-5.1.110170603, vsrx-15.1