What are the Different Netconn Actions and What Do They Mean?
book
Article ID: 291321
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Carbon Black Cloud Enterprise EDR
Issue/Introduction
What different actions can netconns have and what do they mean?
Environment
- Carbon Black Cloud: All Supported Versions
Resolution
- ACTION_CONNECTION_CREATE: When a connection has been attempted to be created between two points.
- ACTION_CONNECTION_ESTABLISHED - This means that a connection was established between the endpoint and something else.
- ACTION_CONNECTION_CREATE_FAILED - Creating the connection failed.
- ACTION_BROWSER_CONNECT - this communicates information about a network connection in the application layer.
- ACTION_CONNECTION_DISCOVERED - discovered/heart beat connection info // Potential alert triggered by packet inspection performed by an IDS module.
Additional Information
More information can be found here.
Feedback
thumb_up
Yes
thumb_down
No