D
DioIPS

Event Types

Technical

Event type definitions and categories used in DioIPS.

Event Categories

CategoryID RangeSource
Process0x0100 - 0x01FFKernel
Network0x0200 - 0x02FFWFP / NDIS
Registry0x0300 - 0x03FFKernel
File0x0400 - 0x04FFKernel
Image0x0500 - 0x05FFKernel
Injection0x0600 - 0x06FFKernel
Hypervisor0x0700 - 0x07FFHypervisor
USB0x0800 - 0x08FFKernel

Process Events

IDName
0x0101ProcessCreate
0x0102ProcessExit
0x0103ThreadCreate
0x0104ThreadExit

Network Events

IDName
0x0201TcpConnect
0x0202TcpAccept
0x0203UdpSend
0x0204UdpRecv
0x0205DnsQuery
0x0206IcmpSend
0x0210NdisPacket
0x0211ArpSpoof

Registry Events

IDName
0x0301RegCreateKey
0x0302RegOpenKey
0x0303RegSetValue
0x0304RegDeleteKey
0x0305RegDeleteValue

Injection Events

IDName
0x0601RemoteThread
0x0602ProcessHandle
0x0603ThreadHandle
0x0701HvVmWrite