Supported Protocols
The following protocols are supported by the Intelligent Content Extraction (ICE) engine, used by NitroView Application Data Monitor (ADM). Information contained within the following documents may be monitored by NitroView ADM, for improved security and fraud detection.
Protocol Modules
| Protocol Module | Comments |
| AOLMAIL | AOL Webmail |
| DeltaSync | Windows Live Mail over Outlook client |
|
FTP | |
|
Gmail | |
|
Hotmail | |
|
HTTP | |
|
IRC | |
|
MAPI | Microsoft Exchange |
|
MSN | |
|
MS SQL Server | Monitor SQL queries |
|
Network Printers | Print monitor - PJL (postscript, PCL) |
|
NNTP | |
|
OSCAR | ICQ, AOL Instant Messaging |
|
Peer to Peer | Gnutella |
|
POP3 | |
|
SIP | IM / VoIP |
|
SMTP | |
|
SSH | No Decryption |
|
SSL | No Decryption |
|
Telnet | |
|
XMPP | Jabber IM |
|
Yahoomail | Yahoo Webmail |
|
YIM | Yahoo Instant Messaging |
Network Modules
| Network Module | Comments |
| BASE64 | |
|
DNS | IP -> Name Cache for Use by Modules |
|
GZIP | |
|
HU01 | Compression used by windows live mail |
|
IP | IPv4 |
|
KERBEROS | Windows Login Detection |
|
LZFU | Compression used by MAPI / TNEF |
|
MARKUP | Text Extraction from HTML for Indexing |
|
MIME | Email and Web Form Decoding |
|
NBNS | Names for MAC Addresses from Windows |
|
QP | Quoted Printable decoding |
|
RFC822 | Email Decoding |
|
RPC | |
|
RTF | Text Extraction for Indexing |
|
RTP | |
|
SMB | Detection only |
|
SOCKS | Proxy Server |
|
TAR | Archive extraction |
|
TNEF | Winmail.dat files |
|
TCP | |
|
UDP | |
|
ZIP | Archive extraction |
File Transfer Protocol Modules
| FTP | HTTP | SMB¹ | SSL² |
| Display Name | Display Name | Display Name | Display Name |
|
File Name | File Name | File Name | File Name |
|
Host Name | Host Name | Host Name | Host Name |
|
URL | Referer | | |
|
| URL | | |
|
| All HTTP headers | | |
E-Mail Protocol Modules
| DeltaSync | MAPI | NNTP | POP3 | SMTP |
| Bcc³ | Bcc | Bcc³ | Bcc³ | Bcc³ |
| Cc³ | Cc | Cc³ | Cc³ | Cc³ |
| Display Name | Display Name | Display Name | Display Name | Display Name |
| From³ | From | From³ | From³ | From³ |
| Host Name | Host Name | Host Name | Host Name | Domain |
| Subject³ | Subject | Subject³ | Password | Host Name |
| To³ | To | To³ | Subject³ | To³ |
| User Name | | To³ | Subject³ |
| | | User Name | |
Web-Mail Protocol Modules
| AOL | Gmail | Hotmail | Yahoo |
| Attachment Name | Attachment Name | Attachment Name | Attachment Name |
| Bcc³ | Bcc³ | Bcc³ | Bcc³ |
|
Cc³ | Cc³ | Cc³ | Cc³ |
| Display Name | Display Name | Display Name | Display Name |
|
File Name | File Name | File Name | File Name |
|
Host Name | Host Name | Host Name | Host Name |
|
From³ | From³ | From³ | From³ |
|
Subject³ | Subject³ | Subject³ | Subject³ |
|
To³ | To³ | To³ | To³ |
Instant-Messaging Protocol Modules
| AOL | ICQ | Jabber | MSN | SIP | Yahoo |
| Call ID | Call ID | Call ID | Call ID | Call ID | Call ID |
| Client Version | Client Version | Client Version | Client Version | Client Version | Client Version |
| Contact Name | Contact Name | Contact Name | Contact Name | Contact Name | Contact Name |
| Contact Nickname | Contact Nickname | Contact Nickname | Contact Nickname | Contact Nickname | Contact Nickname |
| Display Name | Display Name | Display Name | Display Name | Display Name | Display Name |
| File Name | File Name | File Name | File Name | File Name | File Name |
| User Name | User Name | User Name | User Name | User Name | User Name |
| User Nickname | User Nickname | User Nickname | User Nickname | User Nickname | User Nickname |
Peer To Peer Protocol Modules
| Gnutella | Display Name | File Name | Host Name |
| | | |
Network Printers Protocol Modules
| PJL |
| Auto Continue |
| Auto Select |
| Banner Sheet |
| Comment |
| Copies |
| Message |
| Name |
| Job Name |
| Language |
| User Name |
| Password |
| Start Page |
Shell Access Protocol Modules
| SSH* | Telnet |
| Display Name | Display Name |
| Host Name | Host Name |
VoIP Protocol Modules
| SIP |
| Call ID |
| Client Version |
| Contact Name |
| Contact Nickname |
| Display Name |
| File Name |
| User Name |
| User Nickname |
DB Protocol Modules
| MS SQL Server (TDS) |
| App Name |
| Ctl Internal Name |
| Database |
| Host Name |
| Password |
| Server Name |
| User Name |
Content Extraction Modules
Decompression & Decoding Modules
| BASE64 | GZIP | HU01 | LZFU | MIME | Quoted-Printable | RFC822 |
| | | | | | |
Low-Level & Transport Protocol Modules
| DNS | IPv4 | Kerberos | NBNS | RPC | RTP | SOCKS | TCP | UDP |
| | | | | | | | |
Notes
¹ Detection only
² No decryption, captures X.509 certificates and encrypted data
³ Via RFC822 module
For all protocols we capture source/destination IP and MAC addresses, and Time/Date stamp (msec).
These icons link to social bookmarking sites to help share this content.