Event Class IDs
The following table describes the meaning of each Event Class ID and the data included in the extension for that event type. For an explanation of how Tenable One OT Exposure uses each of the CEF fields included in the Extensions, see Extension Parameters — CEF Keys.
| ID | Name | Description |
|---|---|---|
| 0 | Unknown | Unidentified alert event. |
| Controller Commands (IDs 1–94) | ||
| 1 | SIMATIC Code Download | A code download command sent to a SIMATIC controller. |
| 2 | SIMATIC Code Upload | A code upload command sent from a SIMATIC controller. |
| 3 | SIMATIC Code Delete | A code delete command sent to a SIMATIC controller. |
| 4 | SIMATIC Hardware Configuration Download | A hardware configuration download command sent to a SIMATIC controller. |
| 5 | SIMATIC Hardware Configuration Upload | A hardware configuration upload command sent from a SIMATIC controller. |
| 6 | SIMATIC Firmware Download | A firmware download command sent to a SIMATIC controller. |
| 7 | SIMATIC Firmware Upload | A firmware upload command sent from a SIMATIC controller. |
| 8 | SIMATIC PLC Stop | A stop command sent to a SIMATIC PLC. |
| 9 | SIMATIC PLC Start | A start command sent to a SIMATIC PLC. |
| 10 | SIMATIC IO Forcing Enable | An IO forcing enable command sent to a SIMATIC controller. |
| 11 | SIMATIC IO Forcing Disable | An IO forcing disable command was sent to a SIMATIC controller. |
| 12 | SIMATIC Replace IO Forces | A replace IO forces command sent to a SIMATIC controller. |
| 13 | SIMATIC Write Tag | A tag write command sent to a SIMATIC controller. |
| 14 | SIMATIC Firmware Apply | A firmware apply command sent to a SIMATIC controller. |
| 15 | SIMATIC Go Online | A go online command sent to a SIMATIC controller. |
| 16 | Modicon PLC Start | A start command sent to a Modicon PLC. |
| 17 | Modicon PLC Stop | A stop command sent to a Modicon PLC. |
| 18 | Modicon Firmware Erase | A firmware erase command sent to a Modicon controller. |
| 19 | Modicon Firmware Download | A firmware download command sent to a Modicon controller. |
| 20 | Modicon Firmware Upload | A firmware upload command sent from a Modicon controller. |
| 21 | Modicon Code Download | A code download command sent to a Modicon controller. |
| 22 | Modicon Code Upload | A code upload command sent from a Modicon controller. |
| 23 | Modicon Hardware Configuration Download | A hardware configuration download command sent to a Modicon controller. |
| 24 | Modicon Go Online | A Go Online command sent to a Modicon controller. |
| 25 | Rockwell PLC Start | A start command sent to a Rockwell PLC. |
| 26 | Rockwell PLC Stop | A stop command sent to a Rockwell PLC. |
| 27 | Rockwell Module Restart | A module restart command sent to a Rockwell controller. |
| 28 | Rockwell PLC Test | A test command sent to a Rockwell PLC. |
| 29 | Rockwell Go Online | A go online command sent to a Rockwell controller. |
| 30 | Rockwell Code Upload | A code upload command sent from a Rockwell controller. |
| 31 | Rockwell Code Download | A code download command sent to a Rockwell controller. |
| 32 | Rockwell Firmware Download | A firmware download command sent to a Rockwell controller. |
| 33 | Rockwell Tag Create | A tag create command sent to a Rockwell controller. |
| 34 | Rockwell Task Create | A task create command sent to a Rockwell controller. |
| 35 | Rockwell Program Create | A program create command sent to a Rockwell controller. |
| 36 | Rockwell Routine Create | A routine create command sent to a Rockwell controller. |
| 37 | Rockwell Tag Delete | A tag delete command sent to a Rockwell controller. |
| 38 | Rockwell Task Delete | A task delete command sent to a Rockwell controller. |
| 39 | Rockwell Program Delete | A program delete command sent to a Rockwell controller. |
| 40 | Rockwell Routine Delete | A routine delete command sent to a Rockwell controller. |
| 41 | Rockwell Rung Delete | A rung delete command sent to a Rockwell controller. |
| 42 | Rockwell Rename | A rename command sent to a Rockwell controller. |
| 43 | Rockwell SFC Forcing Enable | An SFC forcing enable command sent to a Rockwell controller. |
| 44 | Rockwell SFC Forcing Disable | An SFC forcing disable command sent to a Rockwell controller. |
| 45 | Rockwell Code Edit | A code edit command sent to a Rockwell controller. |
| 46 | Rockwell IO Forcing Enable | An IO forcing enable command sent to a Rockwell controller. |
| 47 | Rockwell IO Forcing Disable | An IO forcing disable command sent to a Rockwell controller. |
| 48 | Apogee PLC Coldstart | A cold start command sent to an Apogee PLC. |
| 49 | Apogee Code Download | A code download command sent to an Apogee controller. |
| 50 | Apogee Code Upload | A code upload command sent from an Apogee controller. |
| 51 | Apogee Program Report Upload | A program report upload command sent from an Apogee controller. |
| 52 | Apogee Code Diff Download | A code diff download command sent to an Apogee controller. |
| 53 | Apogee Set Point Status | A set point status command sent to an Apogee controller. |
| 54 | GE PLC Stop | A stop command sent to a GE PLC. |
| 55 | GE PLC Start | A start command sent to a GE PLC. |
| 56 | GE PLC Clear | A clear command sent to a GE PLC. |
| 57 | GE Code Download | A code download command sent to a GE controller. |
| 58 | GE Code Upload | A code upload command sent from a GE controller. |
| 59 | GE Monitor Mode | A monitor mode command sent to a GE controller. |
| 60 | GE Programmer Mode | A programmer mode command sent to a GE controller. |
| 61 | GE Go Online | A go online command sent to a GE controller. |
| 62 | 800xA Code Download | A code download command sent to an ABB 800xA controller. |
| 63 | 800xA Delete Application | An application delete command sent to an ABB 800xA controller. |
| 64 | 800xA Delete Project | A project delete command sent to an ABB 800xA controller. |
| 65 | 800xA Firmware Download | A firmware download command sent to an ABB 800xA controller. |
| 66 | 800xA IO Forcing Enable | An IO forcing enable command sent to an ABB 800xA controller. |
| 67 | 800xA IO Forcing Disable | An IO forcing disable command sent to an ABB 800xA controller. |
| 68 | 800xA Replace IO Forces | A replace IO forces command sent to an ABB 800xA controller. |
| 69 | 800xA Go Online | A go online command sent to an ABB 800xA controller. |
| 70 | 800xA Redundancy Switch Primary | A redundancy switch to primary command sent to an ABB 800xA controller. |
| 71 | 800xA Redundancy Reset Backup | A redundancy reset backup command sent to an ABB 800xA controller. |
| 72 | 800xA Enable Web Server | A web server enable command sent to an ABB 800xA controller. |
| 73 | 800xA Clear Latched Status | A clear latched status command sent to an ABB 800xA controller. |
| 74 | DeltaV Controller Download | A controller download command sent to a DeltaV controller. |
| 75 | DeltaV Module Download | A module download command sent to a DeltaV module. |
| 76 | DeltaV Setup Data Download | A setup data download command sent to a DeltaV controller. |
| 77 | DeltaV Cold Restart Download | A cold restart download command sent to a DeltaV controller. |
| 78 | DeltaV Force Transition | A force transition command sent to a DeltaV controller. |
| 79 | DeltaV Switch Over | A switchover command sent to a DeltaV controller. |
| 80 | DeltaV Enter Debug Mode | A debug mode entry command sent to a DeltaV controller. |
| 81 | DeltaV Leave Debug Mode | A debug mode exit command sent to a DeltaV controller. |
| 82 | DeltaV Run Module | A run module command sent to a DeltaV controller. |
| 83 | DeltaV Run Module Once | A run module once command sent to a DeltaV controller. |
| 84 | DeltaV Stop Module | A stop module command sent to a DeltaV controller. |
| 85 | DeltaV Sequence Start | A sequence start command sent to a DeltaV controller. |
| 86 | DeltaV Sequence Stop | A sequence stop command sent to a DeltaV controller. |
| 87 | DeltaV Sequence Reset | A sequence reset command sent to a DeltaV controller. |
| 88 | DeltaV Step Enable | A step enable command sent to a DeltaV controller. |
| 89 | DeltaV Step Disable | A step disable command sent to a DeltaV controller. |
| 90 | DeltaV Step Activate | A step activate command sent to a DeltaV controller. |
| 91 | DeltaV Step Deactivate | A step deactivate command sent to a DeltaV controller. |
| 92 | DeltaV PLC Commission | A PLC commission command sent to a DeltaV controller. |
| 93 | DeltaV PLC Decommission | A PLC decommission command sent to a DeltaV controller. |
| 94 | DeltaV Firmware Download | A firmware download command sent to a DeltaV controller. |
| New Asset Discovered | ||
| 95 | New Asset Discovered | Detected a new asset in the network. |
| New Module | ||
| 96 | New Module | Addition of a new module to a backplane in the network. |
| IP Conflict | ||
| 97 | IP Conflict | Multiple assets in the network use the same IP address. |
| ARP Scan | ||
| 98 | ARP Scan Detected | Detected an Address Resolution Protocol (ARP) scan indicative of reconnaissance activity in the network. |
| SYN Scan | ||
| 99 | SYN Scan Detected / Port Scan | Detected a SYN scan indicative of reconnaissance activity in the network. |
| Inactive Asset | ||
| 100 | Inactive Asset for 5 Minutes | An asset was inactive in the network for 5 minutes. |
| 101 | Inactive Asset for 15 Minutes | An asset was inactive in the network for 15 minutes. |
| 102 | Inactive Asset for 30 Minutes | An asset was inactive in the network for 30 minutes. |
| 103 | Inactive Asset for 1 Hour | An asset was inactive in the network for 1 hour. |
| 104 | Inactive Asset for 3 Hours | An asset was inactive in the network for 3 hours. |
| 105 | Inactive Asset for 12 Hours | An asset was not seen in the network for 12 hours. |
| 106 | Inactive Asset for 1 Day | An asset was inactive in the network for 1 day. |
| 107 | Inactive Asset for 1 Week | An asset was inactive in the network for 1 week. |
| Snapshot Mismatch | ||
| 108 | Snapshot Mismatch | The latest snapshot differs from the previous snapshot of the same controller. |
| Unauthorized Conversation | ||
| 109 | Unauthorized Conversation | Detected a conversation between specified assets in the network. |
| Change in State or Version | ||
| 110 | Change in State | The controller changed between operational states. For example, running, stopped, test. |
| 111 | Change in Key State | Detected a change to the controller state by adjusting the physical key position. |
| 112 | Change in FW Version | Detected a change to the firmware running on the controller. |
| Unauthorized Tag Write | ||
| 113 | Unauthorized Tag Write | Detected an unauthorized CIP (Common Industrial Protocol) write of tag values on a controller. |
| Open Port | ||
| 114 | Open Port | Detected a new open port in your network. |
| Baseline Deviation | ||
| 115 | Baseline Deviation | Detected a new connection between assets that did not communicate with each other during the Network Baseline sampling period. |
| Module not Seen | ||
| 116 | Module not Seen | A previously identified module is no longer detected on its backplane. |
| RDP Connection | ||
| 117 | RDP Connection With Authentication | An RDP connection was made between assets in your network, using authentication credentials. |
| 118 | RDP Connection Without Authentication | Detected an RDP connection between assets in your network, without using authentication credentials. |
| Intrusion Detected | ||
| 119 | Intrusion Detected | Detected network traffic indicative of intrusion threats based on the Suricata Emerging Threat rules. |
| Modbus Exception | ||
| 120 | Modbus Exception Occurred: Illegal Function | Detected an illegal function error code in the Modbus protocol. |
| 121 | Modbus Exception Occurred: Illegal Data Address | Detected an illegal data address error code in the Modbus protocol. |
| 122 | Modbus Exception Occurred: Illegal Data Value | Detected an illegal data value error code in the Modbus protocol. |
| Traffic Data Spike Detected | ||
| 123 | Traffic Data Spike Detected | Detected a dramatic increase in the volume of network traffic. |
| 124 | Traffic Conversation Count Spike Detected | Detected a dramatic increase in the number of conversations. |
| Change in Windows USB State | ||
| 125 | Change in Windows USB State | Detected a connection to or removal of a USB device from a Windows-based workstation. |
| Controller Commands (IDs 126–151) | ||
| 126 | Yokogawa Centum Code Download | A code download command sent to a Yokogawa Centum controller. |
| 127 | Yokogawa DCS Pause | A DCS pause command sent to a Yokogawa controller. |
| 128 | Yokogawa DCS Step | A DCS step command sent to a Yokogawa controller. |
| 129 | Yokogawa DCS Start | A DCS start command sent to a Yokogawa controller. |
| 130 | Yokogawa DCS Stop | A DCS stop command sent to a Yokogawa controller. |
| 131 | Yokogawa Tag Write | A tag write command sent to a Yokogawa controller. |
| 132 | Yokogawa Function Block Change | A function block change command sent to a Yokogawa controller. |
| 133 | Yokogawa Snapshot Save | A snapshot save command sent to a Yokogawa controller. |
| 134 | Yokogawa Snapshot Load | A snapshot load command sent to a Yokogawa controller. |
| 135 | ABB Advant Code Download | A code download command sent to an ABB Advant controller. |
| 136 | ABB Advant Code Upload | A code upload command sent from an ABB Advant controller. |
| 137 | ABB Advant Session Connect | A session established with an ABB Advant controller. |
| 138 | IEC-104 Start Data Transfer | A start data transfer command sent using the IEC-104 protocol. |
| 139 | IEC-104 Stop Data Transfer | A stop data transfer command sent using the IEC-104 protocol. |
| 140 | IEC-104 Interrogation Command | An interrogation command sent using the IEC-104 protocol. |
| 141 | IEC-104 Counter Interrogation Command | A counter interrogation command sent using the IEC-104 protocol. |
| 142 | IEC-104 Clock Synchronization Command | A clock synchronization command sent using the IEC-104 protocol. |
| 143 | IEC-104 Reset Process Command | A reset process command sent using the IEC-104 protocol. |
| 144 | IEC-104 Test Command With Time Tag | A test command with time tag sent using the IEC-104 protocol. |
| 145 | Toyopuc PLC Start | A start command sent to a Toyopuc PLC. |
| 146 | Toyopuc PLC Reset Start | A reset start command sent to a Toyopuc PLC. |
| 147 | Toyopuc PLC Stop | A stop command sent to a Toyopuc PLC. |
| 148 | Toyopuc Code Download | A code download command sent to a Toyopuc controller. |
| 149 | Toyopuc Code Upload | A code upload command sent from a Toyopuc controller. |
| 150 | Melsec Q Code Download | A code download command sent to a Melsec Q controller. |
| 151 | Melsec Q Code Upload | A code upload command sent from a Melsec Q controller. |
| DNP3 | ||
| 152 | DNP3 command - Select | A Select command sent using the DNP3 protocol. |
| 153 | DNP3 command - Operate | An Operate command sent using the DNP3 protocol. |
| 154 | DNP3 command - Direct Operate | A Direct Operate command sent using the DNP3 protocol. |
| 155 | DNP3 command - Direct Operate No Response | A Direct Operate No Response command sent using the DNP3 protocol. |
| 156 | DNP3 command - Cold Restart | A Cold Restart command sent using the DNP3 protocol. |
| 157 | DNP3 command - Warm Restart | A Warm Restart command sent using the DNP3 protocol. |
| 158 | DNP3 command - Initialize Data | An Initialize Data command sent using the DNP3 protocol. |
| 159 | DNP3 command - Initialize Application | An Initialize Application command sent using the DNP3 protocol. |
| 160 | DNP3 command - Start Application | A Start Application command sent using the DNP3 protocol. |
| 161 | DNP3 command - Stop Application | A Stop Application command sent using the DNP3 protocol. |
| 162 | DNP3 command - Enable Unsolicited Responses | An Enable Unsolicited Responses command sent using the DNP3 protocol. |
| 163 | DNP3 command - Disable Unsolicited Responses | A Disable Unsolicited Responses command sent using the DNP3 protocol. |
| 164 | DNP3 command - Open File | An Open File command sent using the DNP3 protocol. |
| 165 | DNP3 command - Close File | A Close File command sent using the DNP3 protocol. |
| 166 | DNP3 command - Delete File | A Delete File command sent using the DNP3 protocol. |
| 167 | DNP3 command - Authenticate File | An Authenticate File command sent using the DNP3 protocol. |
| 168 | DNP3 command - Activate Configuration | An Activate Configuration command sent using the DNP3 protocol. |
| 169 | DNP3 Error - IIN status: Not Implemented | Detected a DNP3 IIN error indicating an unsupported function code. |
| 170 | DNP3 Error - IIN status: Object Unknown | Detected a DNP3 IIN error indicating an unknown object was referenced. |
| 171 | DNP3 Error - IIN status: Parameter Error | Detected a DNP3 IIN error indicating an invalid parameter was used. |
| 172 | DNP3 Error - IIN status: Buffer Overflow | Detected a DNP3 IIN error indicating a buffer overflow condition. |
| 173 | DNP3 Error - IIN status: Already Executing | Detected a DNP3 IIN error indicating the requested operation is already in execution. |
| 174 | DNP3 Error - IIN status: Corrupt Config | Detected a DNP3 IIN error indicating an invalid configuration. |
| Honeywell | ||
| 175 | Honeywell PLC Cold Restart | A cold restart command sent to a Honeywell PLC. |
| 176 | Honeywell PLC Warm Restart | A warm restart command sent to a Honeywell PLC. |
| 177 | Honeywell PLC Stop | A stop command sent to a Honeywell PLC. |
| 200 | Honeywell Code Download | A code download command sent to a Honeywell controller. |
| 201 | Honeywell Code Upload | A code upload command sent from a Honeywell controller. |
| 202 | Honeywell Force Enable | A force enable command sent to a Honeywell controller. |
| 203 | Honeywell Force Disable | A force disable command sent to a Honeywell controller. |
| FTP | ||
| 178 | FTP successful login | Detected a successful login using the FTP protocol. |
| 179 | FTP failed login | A failed login attempt using the FTP protocol. |
| Telnet | ||
| 180 | Telnet successful login | Detected a successful login using the Telnet protocol. |
| 181 | Telnet failed login | Detected a failed login attempt using the Telnet protocol. |
| 182 | Telnet login attempt | Detected a login attempt using the Telnet protocol. |
| Saia | ||
| 183 | Saia PLC Start | A start command sent to a Saia PLC. |
| 184 | Saia PLC Cold Restart | A cold restart command sent to a Saia PLC. |
| 185 | Saia PLC Stop | A stop command sent to a Saia PLC. |
| 186 | Saia Code Download | A code download command sent to a Saia controller. |
| 187 | Saia Code Upload | A code upload command sent from a Saia controller. |
| Controller Commands (IDs 188–194) | ||
| 188 | Bachmann Application Run | A run command sent to a Bachmann application. |
| 189 | Bachmann Application Stop | A stop command sent to a Bachmann application. |
| 190 | Bachmann Application Code Download | A code download command sent to a Bachmann application. |
| 191 | Bosch PSI Connect | A connect command sent to a Bosch PSI controller. |
| 192 | Bosch PSI Disconnect | A disconnect command sent to a Bosch PSI controller. |
| 193 | Bosch PSI Download Config | A configuration download command sent to a Bosch PSI controller. |
| 194 | Bosch PSI Reset | A reset command sent to a Bosch PSI controller. |
| MMS Define Variable List | ||
| 195 | MMS Define Named Variable List | A command sent to define a Manufacturing Message Specification (MMS) named variable list. |
| 196 | MMS Delete Named Variable List | A command sent to delete an MMS named variable list. |
| ICCP | ||
| 197 | ICCP Create Data Set | A create data set command sent using the Inter-Control Center Communications Protocol (ICCP). |
| 198 | ICCP Bilateral Table Exchange | A bilateral table exchange command sent using the ICCP. |
| Rediscovered Asset | ||
| 199 | Rediscovered Asset | Rediscovered a previously known asset in the network. |
| IEC 61850 | ||
| 204 | IEC-61850 Subscription Failure | Detected a failure in an IEC-61850 subscription. |
| 205 | IEC-61850 Unauthorized write command | Detected an unauthorized write command using the IEC-61850 protocol. |
| 206 | IEC 61850 - GOOSE Sequence Number (sqNum) Mismatch | Detected a mismatch in the GOOSE message sequence number (sqNum), indicating a possible packet loss. |
| 207 | IEC 61850 - Unexpected GOOSE stNum/Payload Mismatch | Detected an unexpected GOOSE state number (stNum) or payload mismatch. |
| 208 | IEC 61850 - GOOSE Configuration Revision (confRev) Change | Detected a change in the GOOSE configuration revision (confRev), indicating a configuration update. |