Event Class IDs

The following table describes the meaning of each Event Class ID and the data included in the extension for that event type. For an explanation of how Tenable One OT Exposure uses each of the CEF fields included in the Extensions, see Extension Parameters — CEF Keys.

ID Name Description
0 Unknown Unidentified alert event.
Controller Commands (IDs 1–94)
1 SIMATIC Code Download A code download command sent to a SIMATIC controller.
2 SIMATIC Code Upload A code upload command sent from a SIMATIC controller.
3 SIMATIC Code Delete A code delete command sent to a SIMATIC controller.
4 SIMATIC Hardware Configuration Download A hardware configuration download command sent to a SIMATIC controller.
5 SIMATIC Hardware Configuration Upload A hardware configuration upload command sent from a SIMATIC controller.
6 SIMATIC Firmware Download A firmware download command sent to a SIMATIC controller.
7 SIMATIC Firmware Upload A firmware upload command sent from a SIMATIC controller.
8 SIMATIC PLC Stop A stop command sent to a SIMATIC PLC.
9 SIMATIC PLC Start A start command sent to a SIMATIC PLC.
10 SIMATIC IO Forcing Enable An IO forcing enable command sent to a SIMATIC controller.
11 SIMATIC IO Forcing Disable An IO forcing disable command was sent to a SIMATIC controller.
12 SIMATIC Replace IO Forces A replace IO forces command sent to a SIMATIC controller.
13 SIMATIC Write Tag A tag write command sent to a SIMATIC controller.
14 SIMATIC Firmware Apply A firmware apply command sent to a SIMATIC controller.
15 SIMATIC Go Online A go online command sent to a SIMATIC controller.
16 Modicon PLC Start A start command sent to a Modicon PLC.
17 Modicon PLC Stop A stop command sent to a Modicon PLC.
18 Modicon Firmware Erase A firmware erase command sent to a Modicon controller.
19 Modicon Firmware Download A firmware download command sent to a Modicon controller.
20 Modicon Firmware Upload A firmware upload command sent from a Modicon controller.
21 Modicon Code Download A code download command sent to a Modicon controller.
22 Modicon Code Upload A code upload command sent from a Modicon controller.
23 Modicon Hardware Configuration Download A hardware configuration download command sent to a Modicon controller.
24 Modicon Go Online A Go Online command sent to a Modicon controller.
25 Rockwell PLC Start A start command sent to a Rockwell PLC.
26 Rockwell PLC Stop A stop command sent to a Rockwell PLC.
27 Rockwell Module Restart A module restart command sent to a Rockwell controller.
28 Rockwell PLC Test A test command sent to a Rockwell PLC.
29 Rockwell Go Online A go online command sent to a Rockwell controller.
30 Rockwell Code Upload A code upload command sent from a Rockwell controller.
31 Rockwell Code Download A code download command sent to a Rockwell controller.
32 Rockwell Firmware Download A firmware download command sent to a Rockwell controller.
33 Rockwell Tag Create A tag create command sent to a Rockwell controller.
34 Rockwell Task Create A task create command sent to a Rockwell controller.
35 Rockwell Program Create A program create command sent to a Rockwell controller.
36 Rockwell Routine Create A routine create command sent to a Rockwell controller.
37 Rockwell Tag Delete A tag delete command sent to a Rockwell controller.
38 Rockwell Task Delete A task delete command sent to a Rockwell controller.
39 Rockwell Program Delete A program delete command sent to a Rockwell controller.
40 Rockwell Routine Delete A routine delete command sent to a Rockwell controller.
41 Rockwell Rung Delete A rung delete command sent to a Rockwell controller.
42 Rockwell Rename A rename command sent to a Rockwell controller.
43 Rockwell SFC Forcing Enable An SFC forcing enable command sent to a Rockwell controller.
44 Rockwell SFC Forcing Disable An SFC forcing disable command sent to a Rockwell controller.
45 Rockwell Code Edit A code edit command sent to a Rockwell controller.
46 Rockwell IO Forcing Enable An IO forcing enable command sent to a Rockwell controller.
47 Rockwell IO Forcing Disable An IO forcing disable command sent to a Rockwell controller.
48 Apogee PLC Coldstart A cold start command sent to an Apogee PLC.
49 Apogee Code Download A code download command sent to an Apogee controller.
50 Apogee Code Upload A code upload command sent from an Apogee controller.
51 Apogee Program Report Upload A program report upload command sent from an Apogee controller.
52 Apogee Code Diff Download A code diff download command sent to an Apogee controller.
53 Apogee Set Point Status A set point status command sent to an Apogee controller.
54 GE PLC Stop A stop command sent to a GE PLC.
55 GE PLC Start A start command sent to a GE PLC.
56 GE PLC Clear A clear command sent to a GE PLC.
57 GE Code Download A code download command sent to a GE controller.
58 GE Code Upload A code upload command sent from a GE controller.
59 GE Monitor Mode A monitor mode command sent to a GE controller.
60 GE Programmer Mode A programmer mode command sent to a GE controller.
61 GE Go Online A go online command sent to a GE controller.
62 800xA Code Download A code download command sent to an ABB 800xA controller.
63 800xA Delete Application An application delete command sent to an ABB 800xA controller.
64 800xA Delete Project A project delete command sent to an ABB 800xA controller.
65 800xA Firmware Download A firmware download command sent to an ABB 800xA controller.
66 800xA IO Forcing Enable An IO forcing enable command sent to an ABB 800xA controller.
67 800xA IO Forcing Disable An IO forcing disable command sent to an ABB 800xA controller.
68 800xA Replace IO Forces A replace IO forces command sent to an ABB 800xA controller.
69 800xA Go Online A go online command sent to an ABB 800xA controller.
70 800xA Redundancy Switch Primary A redundancy switch to primary command sent to an ABB 800xA controller.
71 800xA Redundancy Reset Backup A redundancy reset backup command sent to an ABB 800xA controller.
72 800xA Enable Web Server A web server enable command sent to an ABB 800xA controller.
73 800xA Clear Latched Status A clear latched status command sent to an ABB 800xA controller.
74 DeltaV Controller Download A controller download command sent to a DeltaV controller.
75 DeltaV Module Download A module download command sent to a DeltaV module.
76 DeltaV Setup Data Download A setup data download command sent to a DeltaV controller.
77 DeltaV Cold Restart Download A cold restart download command sent to a DeltaV controller.
78 DeltaV Force Transition A force transition command sent to a DeltaV controller.
79 DeltaV Switch Over A switchover command sent to a DeltaV controller.
80 DeltaV Enter Debug Mode A debug mode entry command sent to a DeltaV controller.
81 DeltaV Leave Debug Mode A debug mode exit command sent to a DeltaV controller.
82 DeltaV Run Module A run module command sent to a DeltaV controller.
83 DeltaV Run Module Once A run module once command sent to a DeltaV controller.
84 DeltaV Stop Module A stop module command sent to a DeltaV controller.
85 DeltaV Sequence Start A sequence start command sent to a DeltaV controller.
86 DeltaV Sequence Stop A sequence stop command sent to a DeltaV controller.
87 DeltaV Sequence Reset A sequence reset command sent to a DeltaV controller.
88 DeltaV Step Enable A step enable command sent to a DeltaV controller.
89 DeltaV Step Disable A step disable command sent to a DeltaV controller.
90 DeltaV Step Activate A step activate command sent to a DeltaV controller.
91 DeltaV Step Deactivate A step deactivate command sent to a DeltaV controller.
92 DeltaV PLC Commission A PLC commission command sent to a DeltaV controller.
93 DeltaV PLC Decommission A PLC decommission command sent to a DeltaV controller.
94 DeltaV Firmware Download A firmware download command sent to a DeltaV controller.
New Asset Discovered
95 New Asset Discovered Detected a new asset in the network.
New Module
96 New Module Addition of a new module to a backplane in the network.
IP Conflict
97 IP Conflict Multiple assets in the network use the same IP address.
ARP Scan
98 ARP Scan Detected Detected an Address Resolution Protocol (ARP) scan indicative of reconnaissance activity in the network.
SYN Scan
99 SYN Scan Detected / Port Scan Detected a SYN scan indicative of reconnaissance activity in the network.
Inactive Asset
100 Inactive Asset for 5 Minutes An asset was inactive in the network for 5 minutes.
101 Inactive Asset for 15 Minutes An asset was inactive in the network for 15 minutes.
102 Inactive Asset for 30 Minutes An asset was inactive in the network for 30 minutes.
103 Inactive Asset for 1 Hour An asset was inactive in the network for 1 hour.
104 Inactive Asset for 3 Hours An asset was inactive in the network for 3 hours.
105 Inactive Asset for 12 Hours An asset was not seen in the network for 12 hours.
106 Inactive Asset for 1 Day An asset was inactive in the network for 1 day.
107 Inactive Asset for 1 Week An asset was inactive in the network for 1 week.
Snapshot Mismatch
108 Snapshot Mismatch The latest snapshot differs from the previous snapshot of the same controller.
Unauthorized Conversation
109 Unauthorized Conversation Detected a conversation between specified assets in the network.
Change in State or Version
110 Change in State The controller changed between operational states. For example, running, stopped, test.
111 Change in Key State Detected a change to the controller state by adjusting the physical key position.
112 Change in FW Version Detected a change to the firmware running on the controller.
Unauthorized Tag Write
113 Unauthorized Tag Write Detected an unauthorized CIP (Common Industrial Protocol) write of tag values on a controller.
Open Port
114 Open Port Detected a new open port in your network.
Baseline Deviation
115 Baseline Deviation Detected a new connection between assets that did not communicate with each other during the Network Baseline sampling period.
Module not Seen
116 Module not Seen A previously identified module is no longer detected on its backplane.
RDP Connection
117 RDP Connection With Authentication An RDP connection was made between assets in your network, using authentication credentials.
118 RDP Connection Without Authentication Detected an RDP connection between assets in your network, without using authentication credentials.
Intrusion Detected
119 Intrusion Detected Detected network traffic indicative of intrusion threats based on the Suricata Emerging Threat rules.
Modbus Exception
120 Modbus Exception Occurred: Illegal Function Detected an illegal function error code in the Modbus protocol.
121 Modbus Exception Occurred: Illegal Data Address Detected an illegal data address error code in the Modbus protocol.
122 Modbus Exception Occurred: Illegal Data Value Detected an illegal data value error code in the Modbus protocol.
Traffic Data Spike Detected
123 Traffic Data Spike Detected Detected a dramatic increase in the volume of network traffic.
124 Traffic Conversation Count Spike Detected Detected a dramatic increase in the number of conversations.
Change in Windows USB State
125 Change in Windows USB State Detected a connection to or removal of a USB device from a Windows-based workstation.
Controller Commands (IDs 126–151)
126 Yokogawa Centum Code Download A code download command sent to a Yokogawa Centum controller.
127 Yokogawa DCS Pause A DCS pause command sent to a Yokogawa controller.
128 Yokogawa DCS Step A DCS step command sent to a Yokogawa controller.
129 Yokogawa DCS Start A DCS start command sent to a Yokogawa controller.
130 Yokogawa DCS Stop A DCS stop command sent to a Yokogawa controller.
131 Yokogawa Tag Write A tag write command sent to a Yokogawa controller.
132 Yokogawa Function Block Change A function block change command sent to a Yokogawa controller.
133 Yokogawa Snapshot Save A snapshot save command sent to a Yokogawa controller.
134 Yokogawa Snapshot Load A snapshot load command sent to a Yokogawa controller.
135 ABB Advant Code Download A code download command sent to an ABB Advant controller.
136 ABB Advant Code Upload A code upload command sent from an ABB Advant controller.
137 ABB Advant Session Connect A session established with an ABB Advant controller.
138 IEC-104 Start Data Transfer A start data transfer command sent using the IEC-104 protocol.
139 IEC-104 Stop Data Transfer A stop data transfer command sent using the IEC-104 protocol.
140 IEC-104 Interrogation Command An interrogation command sent using the IEC-104 protocol.
141 IEC-104 Counter Interrogation Command A counter interrogation command sent using the IEC-104 protocol.
142 IEC-104 Clock Synchronization Command A clock synchronization command sent using the IEC-104 protocol.
143 IEC-104 Reset Process Command A reset process command sent using the IEC-104 protocol.
144 IEC-104 Test Command With Time Tag A test command with time tag sent using the IEC-104 protocol.
145 Toyopuc PLC Start A start command sent to a Toyopuc PLC.
146 Toyopuc PLC Reset Start A reset start command sent to a Toyopuc PLC.
147 Toyopuc PLC Stop A stop command sent to a Toyopuc PLC.
148 Toyopuc Code Download A code download command sent to a Toyopuc controller.
149 Toyopuc Code Upload A code upload command sent from a Toyopuc controller.
150 Melsec Q Code Download A code download command sent to a Melsec Q controller.
151 Melsec Q Code Upload A code upload command sent from a Melsec Q controller.
DNP3
152 DNP3 command - Select A Select command sent using the DNP3 protocol.
153 DNP3 command - Operate An Operate command sent using the DNP3 protocol.
154 DNP3 command - Direct Operate A Direct Operate command sent using the DNP3 protocol.
155 DNP3 command - Direct Operate No Response A Direct Operate No Response command sent using the DNP3 protocol.
156 DNP3 command - Cold Restart A Cold Restart command sent using the DNP3 protocol.
157 DNP3 command - Warm Restart A Warm Restart command sent using the DNP3 protocol.
158 DNP3 command - Initialize Data An Initialize Data command sent using the DNP3 protocol.
159 DNP3 command - Initialize Application An Initialize Application command sent using the DNP3 protocol.
160 DNP3 command - Start Application A Start Application command sent using the DNP3 protocol.
161 DNP3 command - Stop Application A Stop Application command sent using the DNP3 protocol.
162 DNP3 command - Enable Unsolicited Responses An Enable Unsolicited Responses command sent using the DNP3 protocol.
163 DNP3 command - Disable Unsolicited Responses A Disable Unsolicited Responses command sent using the DNP3 protocol.
164 DNP3 command - Open File An Open File command sent using the DNP3 protocol.
165 DNP3 command - Close File A Close File command sent using the DNP3 protocol.
166 DNP3 command - Delete File A Delete File command sent using the DNP3 protocol.
167 DNP3 command - Authenticate File An Authenticate File command sent using the DNP3 protocol.
168 DNP3 command - Activate Configuration An Activate Configuration command sent using the DNP3 protocol.
169 DNP3 Error - IIN status: Not Implemented Detected a DNP3 IIN error indicating an unsupported function code.
170 DNP3 Error - IIN status: Object Unknown Detected a DNP3 IIN error indicating an unknown object was referenced.
171 DNP3 Error - IIN status: Parameter Error Detected a DNP3 IIN error indicating an invalid parameter was used.
172 DNP3 Error - IIN status: Buffer Overflow Detected a DNP3 IIN error indicating a buffer overflow condition.
173 DNP3 Error - IIN status: Already Executing Detected a DNP3 IIN error indicating the requested operation is already in execution.
174 DNP3 Error - IIN status: Corrupt Config Detected a DNP3 IIN error indicating an invalid configuration.
Honeywell
175 Honeywell PLC Cold Restart A cold restart command sent to a Honeywell PLC.
176 Honeywell PLC Warm Restart A warm restart command sent to a Honeywell PLC.
177 Honeywell PLC Stop A stop command sent to a Honeywell PLC.
200 Honeywell Code Download A code download command sent to a Honeywell controller.
201 Honeywell Code Upload A code upload command sent from a Honeywell controller.
202 Honeywell Force Enable A force enable command sent to a Honeywell controller.
203 Honeywell Force Disable A force disable command sent to a Honeywell controller.
FTP
178 FTP successful login Detected a successful login using the FTP protocol.
179 FTP failed login A failed login attempt using the FTP protocol.
Telnet
180 Telnet successful login Detected a successful login using the Telnet protocol.
181 Telnet failed login Detected a failed login attempt using the Telnet protocol.
182 Telnet login attempt Detected a login attempt using the Telnet protocol.
Saia
183 Saia PLC Start A start command sent to a Saia PLC.
184 Saia PLC Cold Restart A cold restart command sent to a Saia PLC.
185 Saia PLC Stop A stop command sent to a Saia PLC.
186 Saia Code Download A code download command sent to a Saia controller.
187 Saia Code Upload A code upload command sent from a Saia controller.
Controller Commands (IDs 188–194)
188 Bachmann Application Run A run command sent to a Bachmann application.
189 Bachmann Application Stop A stop command sent to a Bachmann application.
190 Bachmann Application Code Download A code download command sent to a Bachmann application.
191 Bosch PSI Connect A connect command sent to a Bosch PSI controller.
192 Bosch PSI Disconnect A disconnect command sent to a Bosch PSI controller.
193 Bosch PSI Download Config A configuration download command sent to a Bosch PSI controller.
194 Bosch PSI Reset A reset command sent to a Bosch PSI controller.
MMS Define Variable List
195 MMS Define Named Variable List A command sent to define a Manufacturing Message Specification (MMS) named variable list.
196 MMS Delete Named Variable List A command sent to delete an MMS named variable list.
ICCP
197 ICCP Create Data Set A create data set command sent using the Inter-Control Center Communications Protocol (ICCP).
198 ICCP Bilateral Table Exchange A bilateral table exchange command sent using the ICCP.
Rediscovered Asset
199 Rediscovered Asset Rediscovered a previously known asset in the network.
IEC 61850
204 IEC-61850 Subscription Failure Detected a failure in an IEC-61850 subscription.
205 IEC-61850 Unauthorized write command Detected an unauthorized write command using the IEC-61850 protocol.
206 IEC 61850 - GOOSE Sequence Number (sqNum) Mismatch Detected a mismatch in the GOOSE message sequence number (sqNum), indicating a possible packet loss.
207 IEC 61850 - Unexpected GOOSE stNum/Payload Mismatch Detected an unexpected GOOSE state number (stNum) or payload mismatch.
208 IEC 61850 - GOOSE Configuration Revision (confRev) Change Detected a change in the GOOSE configuration revision (confRev), indicating a configuration update.