Network Services
Services related to network infrastructure and proxy functionality:socksTraffic related to the SOCKS protocol, often used for proxy servicesproxyCommunication involving proxy servers, intermediaries that facilitate network connectionsrouterActivity associated with routers, devices directing traffic between networksvpnInteractions with Virtual Private Network services
Database Services
Database systems and data storage services:redisInteractions with Redis, an open-source, in-memory data structure storemongodbTraffic related to MongoDB, a NoSQL databaseelasticsearchActivity involving Elasticsearch, a distributed search and analytics enginemssqlTraffic associated with Microsoft SQL Server or MySQL databasesmysqlMySQL database servicespostgresqlTraffic related to PostgreSQL database servicescouchdbActivities associated with CouchDB, a NoSQL databasedb2Traffic associated with IBM Db2 database services
File/Directory Services
File transfer, synchronization, and directory services:portmapperCommunication with portmapper services, facilitating RPC-based interactionstftpTraffic related to Trivial File Transfer Protocol, a simple file transfer protocolftpCommunication involving File Transfer Protocol for file exchangesrsyncTraffic related to rsync, a file synchronization toolsmbInteractions with Server Message Block protocol for file and printer sharingafpTraffic associated with Apple Filing Protocol, used for Mac file servicesdirectory_listingTraffic related to directory listing services
Remote Access Services
Remote access and administration protocols:rdpActivities associated with Remote Desktop Protocol for remote accessvncTraffic involving Virtual Network Computing for remote desktop accesstelnetCommunication with Telnet services for remote command-line accesssshCommunication involving Secure Shell protocol for secure accessradminTraffic related to Radmin, a remote administration softwarecitrixCommunication with Citrix servers for virtualization and remote access
Web/HTTP Services
Web servers and HTTP-related services:httpCommunication involving Hypertext Transfer Protocol for web servicesapache_serverActivities associated with Apache web serverssslTraffic related to secure communication using SSL/TLS protocolstlsTraffic related to secure communication using SSL/TLS protocols
Mail Services
Email servers and mail protocols:mail_serverTraffic involving mail servers for email communicationimapInteractions with IMAP or POP3 protocols for email retrievalpop3Interactions with IMAP or POP3 protocols for email retrieval
DNS Services
Domain Name System resolution services:dns_resolverCommunication with DNS resolvers for domain name resolutionmdns_resolverInteractions with mDNS resolvers, facilitating device discovery
Management/Monitoring Services
Network management and monitoring protocols:snmpTraffic associated with Simple Network Management Protocol, used for network monitoringipmiTraffic related to Intelligent Platform Management Interface, used for server managementldapInteractions with Lightweight Directory Access Protocol servicescwmpActivities associated with CPE WAN Management Protocol for device management
Industrial/IoT Services
Industrial control systems and Internet of Things protocols:icsTraffic involving Industrial Control Systems protocolsmodbusTraffic involving Modbus protocol for industrial communicationbacnetTraffic related to BACnet protocol for building automation and control networkscoapTraffic related to Constrained Application Protocol for IoTmqttTraffic involving MQTT, a lightweight messaging protocol for IoT
Network Time
Time synchronization services:ntpInteractions with Network Time Protocol servers, synchronizing system clocks
Media/Messaging Services
Multimedia and messaging protocols:netbiosCommunication with NetBIOS services, often used for file sharingsipCommunication involving Session Initiation Protocol for multimedia sessionsstunInteractions with Session Traversal Utilities for NAT protocolsamqpInteractions with Advanced Message Queuing Protocol services
Specialized Services
Enterprise applications, development tools, and specialized protocols:ardCommunication with Apple Remote Desktop servicesippActivities involving Internet Printing Protocol for printer communicationxdmcpActivities related to X Display Manager Control Protocol for remote displayadbActivities involving Android Debug Bridge for Android device interactionschargenTraffic related to the Character Generator ProtocolmemcachedInteractions with Memcached, an in-memory caching systemnatpmpCommunication with NAT Port Mapping Protocol for network address translationqotdTraffic related to the Quote of the Day ProtocolssdpInteractions with Simple Service Discovery Protocol for device discoveryisakmpActivities associated with Internet Security Association and Key Management ProtocolhadoopCommunication with Hadoop services for distributed storage and processingcisco_smart_installActivities related to Cisco Smart Install protocolgrafanaInteractions with Grafana, an open-source analytics and monitoring platformbitbucketCommunication with Bitbucket servers for source code managementgitlab_serverTraffic involving GitLab servers for source code managementubiquitiInteractions with Ubiquiti network devicessmiActivities associated with Structure of Management Information protocolbosmonTraffic related to BosMon, a monitoring system for emergency servicesms_exchangeCommunication with Microsoft Exchange servers for email servicesms_sharepointCommunication with Microsoft SharePoint serversms_rpcMicrosoft RPC servicessecvest_alarm_systemActivities involving Secvest Alarm System protocolskubernetes_api_serverCommunication with Kubernetes API serversepmdInteractions with Erlang Port Mapper Daemon servicesquicCommunication involving QUIC (Quick UDP Internet Connections) protocoldockerTraffic related to Docker, a containerization platformdvrActivities related to Digital Video Recorder serviceshp_iloCommunication with Hewlett Packard Integrated Lights-Out managementsmarter_mail_serverInteractions with SmarterMail servers for email serviceslog4jTraffic related to Log4j, a Java-based logging utilityzimbra_serverCommunication with Zimbra Collaboration Suite serverssapActivities involving SAP (Systems, Applications, and Products) servicesqnapCommunication with QNAP network-attached storage devicesconfluenceInteractions with Confluence servers for collaboration and documentationsophosTraffic involving Sophos security solutionsh2_web_consoleCommunication with H2 Database web consolesfortigateInteractions with Fortigate, a network security applianceivantiActivities associated with Ivanti endpoint management solutionsmc_sqlrActivities associated with Microsoft SQL Server