Checks

脚本 类型 可用性 hooks 过滤器 过滤 Tot Exec Time 操作
countries_contacts 主机 Community min 0
custom_host_lua_script 主机 Community min 0
dangerous_host 主机 Community min 0
dns_contacts 主机 Community min 0
domain_names_contacts 主机 Community min 0
external_host_script 主机 Community min 0
flow_flood 主机 Community min 0
icmp_flood 主机 Community min 0
ntp_contacts 主机 Community min 0
remote_connection 主机 Community min 0
scan 主机 Enterprise M 5mins 0
smtp_contacts 主机 Community min 0
suspicious_domain_scan 主机 Enterprise M hour 0
unexpected_gateway 主机 Community min 0
dropped_alerts 接口 Community min 0
ghost_networks 接口 Community min 0
no_if_activity 接口 Community min 0
no_probe_or_exporter_activity 接口 Community min 0
periodic_activity_not_executed 接口 Community min 0
slow_periodic_activity 接口 Community min 0
too_many_drops 接口 Community min 0
broadcast_domain_too_large 网络 Community min 0
flow_flood_victim 网络 Community min 0
ip_reassignment 网络 Community min 0
network_discovery 网络 Community min 0
network_issues 网络 Community min 0
syn_scan_victim 网络 Community min packet_interface 0
binary_application_transfer Community 0 6.55 ms
blacklisted Community 0 2.5 ms
blacklisted_client_contact Community 0 4.22 ms
blacklisted_server_contact Community 0 2.39 ms
broadcast_non_udp_traffic Community 0 7.55 ms
country_check Community 0 < 1 ms
custom_lua_script Community 0 < 1 ms
device_protocol_not_allowed Community 0 10.37 ms
external_alert_check Community 0 5.61 ms
iec_invalid_command_transition Community packet_interface 0 < 1 ms
iec_invalid_transition Community packet_interface 0 < 1 ms
iec_unexpected_type_id Community packet_interface 0 < 1 ms
known_proto_on_non_std_port Community 0 1.84 ms
low_goodput Community packet_interface, nedge=false 0 9.95 ms
ndpi_anonymous_subscriber Community 0 1.81 ms
ndpi_binary_data_transfer Community 0 1.02 ms
ndpi_clear_text_credentials Community 0 1.74 ms
ndpi_desktop_or_file_sharing_session Community 0 1.07 ms
ndpi_dns_fragmented Community 0 1.63 ms
ndpi_dns_large_packet Community 0 1.68 ms
ndpi_dns_suspicious_traffic Community 0 1.05 ms
ndpi_error_code_detected Community 0 < 1 ms
ndpi_http_crawler_bot Community 0 < 1 ms
ndpi_http_obsolete_server Community 0 < 1 ms
ndpi_http_suspicious_content Community 0 1.1 ms
ndpi_http_suspicious_header Community 0 < 1 ms
ndpi_http_suspicious_url Community 0 1.07 ms
ndpi_http_suspicious_user_agent Community 0 < 1 ms
ndpi_invalid_characters Community 0 1.0 ms
ndpi_malformed_packet Community 0 < 1 ms
ndpi_malicious_fingerprint Community 0 < 1 ms
ndpi_malicious_sha1_certificate Community 0 < 1 ms
ndpi_malware_host_contacted Community 0 1.09 ms
ndpi_minor_issues Community 0 < 1 ms
ndpi_mismatching_protocol_with_ip Community 0 < 1 ms
ndpi_numeric_ip_host Community 0 23.02 ms
ndpi_obfuscated_traffic Community 0 < 1 ms
ndpi_periodic_flow Community 0 < 1 ms
ndpi_possible_exploit Community 0 < 1 ms
ndpi_probing_attempt Community 0 < 1 ms
ndpi_punicody_idn Community 0 < 1 ms
ndpi_risky_asn Community 0 1.31 ms
ndpi_risky_domain Community 0 1.12 ms
ndpi_smb_insecure_version Community 0 < 1 ms
ndpi_ssh_obsolete_client Community 0 1.29 ms
ndpi_ssh_obsolete_server Community 0 1.04 ms
ndpi_suspicious_dga_domain Community 0 < 1 ms
ndpi_suspicious_entropy Community 0 3.78 ms
ndpi_tcp_issues Community 0 < 1 ms
ndpi_tls_alpn_sni_mismatch Community 0 < 1 ms
ndpi_tls_certificate_about_to_expire Community 0 < 1 ms
ndpi_tls_fatal_alert Community 0 1.87 ms
ndpi_tls_missing_sni Community 0 < 1 ms
ndpi_tls_not_carrying_https Community 0 3.05 ms
ndpi_tls_suspicious_extension Community 0 1.84 ms
ndpi_tls_uncommon_alpn Community 0 1.74 ms
ndpi_unidirectional_traffic Community 0 2.89 ms
ndpi_unsafe_protocol Community 0 < 1 ms
ndpi_url_possible_rce_injection Community 0 1.59 ms
ndpi_url_possible_sql_injection Community 0 1.72 ms
ndpi_url_possible_xss Community 0 < 1 ms
not_purged Community 0 3.1 ms
rare_destination Community packet_interface, nedge=false 0 2.38 ms
remote_access Community 0 2.28 ms
remote_to_local_insecure_flow Community 0 3.04 ms
remote_to_remote Community 0 < 1 ms
tcp_flow_reset Community 0 < 1 ms
tcp_no_data_exchanged Community packet_interface 0 3.47 ms
unexpected_dhcp Community 0 < 1 ms
unexpected_dns Community 0 < 1 ms
unexpected_ntp Community 0 < 1 ms
unexpected_smtp Community 0 < 1 ms
vlan_bidirectional_traffic Community 0 < 1 ms
web_mining Community 0 2.79 ms
zero_tcp_window Community packet_interface 0 4.16 ms
dropped_alerts 系统 Community min 0
exporters_limit_exceeded 系统 Community min 0
ids_ips_log 系统 Community min 0
periodic_activity_not_executed 系统 Community min 0
redis_reads_writes_exceeded 系统 Community day 0
slow_periodic_activity 系统 Community min 0
system_error 系统 Community min 0
host_log Syslog Community handleEvent 0
nbox Syslog Community handleEvent 0
suricata Syslog Community handleEvent nedge=false 0