Windows sensors are reporting ICMP traffic to the console with port numbers of 135 and 136 for IPv6 or 0 and 8 for IPv4 traffic.
For example:
Type 0 | Echo Reply |
Type 8 | Echo |
Type 135 | Neighbor Solicitation |
Type 136 | Neighbor Advertisement |
Windows reports ICMP traffic as a "type" and the sensor reports this data as the port seen.
The value can be ignored as ICMP does not have a port, however the sensor should report that ICMP traffic.
Future enhancement tracking: