What are the Different Netconn Actions and What Do They Mean?
search cancel

What are the Different Netconn Actions and What Do They Mean?

book

Article ID: 291321

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR

Issue/Introduction

What different actions can netconns have and what do they mean?

Environment

  • Carbon Black Cloud: All Supported Versions

Resolution

  • ACTION_CONNECTION_CREATE: When a connection has been attempted to be created between two points.
  • ACTION_CONNECTION_ESTABLISHED - This means that a connection was established between the endpoint and something else.
  • ACTION_CONNECTION_CREATE_FAILED - Creating the connection failed.
  • ACTION_BROWSER_CONNECT - this communicates information about a network connection in the application layer.
  • ACTION_CONNECTION_DISCOVERED - discovered/heart beat connection info // Potential alert triggered by packet inspection performed by an IDS module.

Additional Information

More information can be found here.