Professional Documents
Culture Documents
Netmon Supported Applications: Application Exploration Dashboard
Netmon Supported Applications: Application Exploration Dashboard
Netmon Supported Applications: Application Exploration Dashboard
January 6, 2020
Overview
This document lists the applications supported by the latest release of LogRhythm NetMon, along with family and
tag categorizations used to classify traffic. An application can be a website that generates traffic (for example,
Google or Gmail) or it can be the underlying protocol of the traffic (for example, IP or TCP).
You can perform in-depth analysis of specific application traffic in the NetMon interface. With this valuable data,
you can locate suspicious data transfers, network policy violations, and advanced attacks.
The following applications are listed by application code as defined in the NetMon application. For detailed
instructions on how to search for, select, filter, and analyze traffic from specific applications, see the NetMon
online Help.
NOTE: Some applications captured by NetMon do not include family or tag metadata because these flows are
not fully classified—for example, a TCP application could belong to several families. To determine
which applications are classified, select the FlowClassified field and look for “FlowClassified=true.”
Family Description
Antivirus Antivirus update
Application Service Background service
Audio/Video Protocol/application used to transport audio or video content
Authentication Protocol used for authentication purposes
Behavioral Protocol classified by non-deterministic criteria based on statistical analysis of packet form
and session behavior
Compression Compression layers
Custom Custom family
Database Protocol used for database remote queries
Encrypted Encryption protocol
ERP Enterprise Resource Planning application
File Server File transfer protocol
File Transfer Protocol used for user-to-user file transfers via Instant-Messaging applications
Forum Web forum
Game Gaming protocol
Instant Messaging Instant messaging application
Mail Email exchange protocol
Microsoft Office Microsoft office sub-protocol
Middleware Platform protocol for remote procedure calls
Network Management Protocol used for IT management
Network Service Low level network protocol
Peer to Peer Peer to peer application
Printer Printer communication protocol
Routing Network routing protocol
Security Service Workstation security application
Standard Basic layers defined by Qosmos
Telephony Telephony core network protocol
Terminal Remote terminal protocol
Thin Client Remote control protocol
Tunneling Tunneling protocol
Wap Mobile specific transport protocol
Web Generic web traffic
Webmail Web email application
Tag Description
aaa Protocol/application used for AAA (Authentification, Authorization and Accounting) purposes
adult_content Adult content
advertising Advertising networks and applications
analytics user-analytics and statistics
anonymizer Traffic-anonymization protocol/application
audio_chat Protocol/application used for Audio Chat
basic Covers all protocols required for basic classification, including most networking protocols as
well as standard protocols like HTTP
blog Blogging platform
cdn Protocol/application used for Content-Delivery Networks
chat Protocol/application used for Text Chat
classified_ads Protocol/application used for Classified ads
cloud_services SaaS and/or PaaS cloud-based services
db Database-specific protocols
dea_mail Service offering Disposable Email Accounts (DEA). DEA is a technique to share temporary
email addresses between many users.
email Native email protocol
enterprise Protocol/application used in an enterprise network
file_mngt Protocol/application designed specifically for file management and exchange. This can
include bona fide network protocols (like SMB) as well as web/cloud services (like Dropbox).
file_transfer Protocol that offers file transferring as a secondary feature. This typically includes IM,
WebMail, and other protocols that allow file transfers in addition to their principal function.
forum Online forum
gaming Protocol/application used by games
im_mc Protocol/application used for Instant messaging or multiconferencing
iot Internet of Things protocol/application
mm_streaming Protocol/application used for multimedia streaming
mobile Mobile-specific protocol/application
networking Protocol used for (inter) networking purpose
news_portal Protocol/application used for News Portals
p2p Protocol/application used for Peer-to-peer purposes
remote_access Protocol/application used for remote access
scada SCADA (Supervisory control and data acquisition) protocols, all generations
social_network Social networking application
standardized Protocol issued from standardized bodies such as IETF, ITU, IEEE, ETSI, OIF
update Auto-update protocol
video_chat Protocol/application used for Video Chat
voip Application used for Voice over IP
vpn_tun Protocol/application used for VPN or tunneling purposes
web Application based on HTTP/HTTPS
web_ecom Protocol/application used for E-commerce websites
web_search Protocol/application used for Web search portals
Supported Applications
The following table contains NetMon supported application names (sorted alphabetically) and descriptions.
Application Description
_01net 01net website, a French high-tech news site.
_050plus 050 plus is a Japanese embedded smartphone application dedicated to audio-
conferencing.
_0zz0 0zz0 is an online solution to store, send and share files
_10050net China Railcom group web portal.
_10086cn This protocol plug-in classifies the http traffic to the host 10086.cn. It also classifies the ssl
traffic to the Common Name 10086.cn.
_104com Web site dedicated to job research.
_1111tw Website dedicated to job research in Taiwan.
_114la Chinese web portal operated by YLMF Computer Technology Co.
_115com Chinese cloud storing system of the 115 website. It is operated by YLMF Computer
Technology Co.
_118114cn Chinese booking and reservation portal.
_11st Korean shopping website 11st. It is operated by SK Planet Co.
_123people This protocol plug-in classifies the http traffic to the host 123people.com. Deprecated.
_1337x Bittorrent tracker search engine
_139mail 139mail is a chinese webmail powered by China Mobile.
_15min Lithuanian news portal
_163com Chinese web portal 163. It is operated by NetEase, a company which pioneered the
development of Internet in China.
_17173com Website distributing Chinese games.
_17u Chinese online travel booking website.
_20min 20 minutes is a free, daily newspaper available in France, Spain and Switzerland. This
plugin classifies websites.
_24h Vietnamese news portal
_24ora Aruban news portal
_24sata Croatian news portal
_24sevenoffice 24SevenOffice is a web-based Enterprise resource planning (ERP) systems.
_24ur Slovenian news portal
_2ch Japanese adult videos web site
_2shared 2shared is an online space for sharing and storage.
_3366_com 3366.com is an online secure flash game website.
_360buy This protocol plug-in classified the http traffic to the host 360buy.com. Deprecated.
_360cn Chinese web portal featuring a search engine and security-oriented software services.
_3Com Ethernet Type 3Com
_3Com_Corp Ethernet Type 3Com_Corp
_3Com_NBP Ethernet Type 3Com_NBP
Disclaimer
The information contained in this document is subject to change without notice. LogRhythm, Inc. makes no warranty of any kind with respect to this information.
LogRhythm, Inc. specifically disclaims the implied warranty of merchantability and fitness for a particular purpose. LogRhythm, Inc. shall not be liable for any direct,
indirect, incidental, consequential, or other damages alleged in connection with the furnishing or use of this information.
Trademark
LogRhythm is a registered trademark of LogRhythm, Inc. All other company or product names mentioned may be trademarks, registered trademarks, or service
marks of their respective holders.