iSID Analyst Knowledge Base

Definitions, and additional context on iSID alerts along with helpful recommendations

S7 Siemens, Write area

A S7 operation was performed - write action

CVE detected

Device has the potential to be vulnurable to a CVE or several CVE's

Device Became Inactive

A device that wasn't communicating recently and according to the iSID now is defined as inactive- can define in the isid the time frame of no communication in order to get as inactive.

New Protocol Detected

new protocol that was discovered in an existing link (source and destination that already discovered in another protocol)

New Link Detected

link refers to source and destination and port. a new link will appear when a source and destination that haven't spoken before will speak for the first time