Caver Docs
← All docs
Compatibility

Works with Caver

What it reads, what it sends, and what it will not touch. Caver reads published standards rather than building one connector per vendor, which is why this list is shorter than you expect and covers more than you expect.

160+
Content packs shipped
7
Industrial protocols decoded
3
EHR audit standards read
0
Medical images ever read
In Caver receives. Nothing is sent back to that system. Out Caver sends findings out. Both Caver can act, in one place, only where you enable it.
Industry
Category
Direction
37 of 37 shown
System ▲▼ Category ▲▼ How it reaches Caver Direction ▲▼
Epic EHR / EMR Its own security and privacy feed, emitted natively as CEF, LEEF or RFC 5424 syslog. Or the Clarity access-log extract In
Oracle Health (Cerner) EHR / EMR P2Sentinel Listener, which exists to forward Millennium audit events to an outside system In
Meditech Expanse EHR / EMR Audit Trail settings and the MIS Dictionary audit log, via FHIR, HL7 or web services In
Altera (Allscripts), NextGen, Greenway, athenahealth, eClinicalWorks EHR / EMR Audit trail via API or database extract. No published security feed, so the route is confirmed per site In
Any standards-based EHRstandard EHR / EMR IHE ATNA audit records over syslog (RFC 3881), or FHIR AuditEvent In
HL7 v2, all message typesstandard Clinical messaging Read from a mirror of the traffic. Caver is not in the message path In
Mirth Connect, Rhapsody, Cloverleaf Clinical messaging The interface traffic plus the engine's own logs. Caver learns each interface's normal and reports the one that quietly stopped In
FHIRstandard Clinical messaging AuditEvent for access, plus resource traffic where it is exposed In
GE HealthCare, Siemens Healthineers, Philips, Canon Medical, Fujifilm, Samsung, Hologic, Konica Minolta, Carestream, Mindray Imaging DICOM association and query/retrieve activity. The parser stops at the pixel data In
Sectra, Agfa, Fujifilm Synapse, GE Centricity, Philips Vue, Merative, Hyland, Intelerad Imaging Same DICOM conversation. Retrieves to an unrecognized destination lead the alert list In
Any DICOM-conformant device or archivestandard Imaging DICOM on the wire. No vendor cooperation required In
Infusion pumps: Baxter, BD (Alaris), ICU Medical, Smiths Medical, Fresenius Kabi, B. Braun Medical devices Passive. Learns the drug-library server it talks to In
Patient monitors: Philips, GE HealthCare, Dräger, Mindray, Welch Allyn, Nihon Kohden Medical devices Passive. Learns its telemetry gateway In
Ventilators: Dräger, Getinge, Medtronic, Hamilton, Vyaire Medical devices Passive In
Dialysis: Fresenius, Baxter, B. Braun, Nikkiso Medical devices Passive In
Lab analyzers: Roche, Abbott, Siemens Healthineers, Beckman Coulter, Sysmex Medical devices HL7 on the interface, plus network behavior In
Dispensing cabinets: Omnicell, BD Pyxis, Swisslog, ARxIUM Medical devices HL7 and their own logs where available In
Nurse call, tube, tracking: Rauland, Hillrom, Swisslog, CenTrak, Sonitor Medical devices Passive, plus their logs where they keep them In
Siemens, Johnson Controls, Honeywell, Schneider Electric, Trane, Automated Logic, Delta Controls Building automation BACnet. Room pressure and air changes judged against ASHRAE 170 and FGI, with the citation on the finding In
Rockwell Automation: Allen-Bradley ControlLogix, CompactLogix, MicroLogix Industrial control EtherNet/IP and CIP, passively. Vendor profile shipped In
Siemens SIMATIC: S7-300, S7-400, S7-1200, and S7-1500 in compatibility mode Industrial control S7comm, passively. Vendor profile shipped. S7-1500 speaking S7CommPlus natively is a separate decoder, not this one In
Schneider Electric: Modicon controllers Industrial control Modbus/TCP, passively. Vendor profile shipped In
ABB: 800xA and connected controllers Industrial control Vendor profile shipped, plus the protocols its controllers speak In
Honeywell: process and building controllers Industrial control Vendor profile shipped, plus the protocols its controllers speak In
SEL, GE, Hitachi Energy, Eaton, Emerson, Yokogawa, Mitsubishi, Omron, WAGO, Phoenix Contact, Beckhoffstandard Industrial control Recognized by the protocol its equipment speaks: DNP3, IEC 60870-5-104 or Modbus/TCP In
OPC UA Industrial control Decoded passively. Clear under SecurityPolicy None; under Sign or SignAndEncrypt when you provide the key material. Caver does not defeat the security of your deployment In
SCADA and HMI hosts Industrial control Their Windows event logs, correlated with the control traffic they generate In
Dragos, Claroty OT security Their findings, correlated with the rest of the estate In
Microsoft Entra ID, Okta, Duo, JumpCloud, OneLogin, Auth0, Keycloak Identity API or log feed In
CrowdStrike Falcon, SentinelOne, Microsoft Defender, Carbon Black, Trend Micro Vision One, Wazuh, osquery, Sysmon Endpoint API or log feed In
AWS CloudTrail and GuardDuty, Microsoft 365 and Sentinel, Google Workspace, Kubernetes, Snowflake, MongoDB Atlas Cloud Native audit trail In
Cisco Meraki and Umbrella, Cloudflare, Tailscale, NetFlow, SNMP, firewall syslog Network Log feed or flow record In
Windows Security and System event logs, Linux auditd, SSH, RDP, PowerShell script blocks Servers Agent or forwarder In
Salesforce, ServiceNow, Atlassian, GitHub, GitLab, Slack, Zoom, Box, Dropbox, Stripe, HubSpot SaaS and business Audit API In
Managed model providers, self-hosted inference, agent frameworks, MCP, vector databases, coding assistants AI estate Gateway, proxy or provider audit log In
Ticketing, chat and paging: webhook, Slack, email, on-call Outbound Caver pushes findings out. Nothing coming back changes what Caver decided Out
Your network edge, only if you enable it Outbound The one place Caver acts: block and unblock a source address, behind an approval gate, a never-block list, and an automatic refusal for any address on a clinical or control network Both
Nothing matches that yet. It does not mean Caver cannot read it. Anything with a log, an API, or traffic you can mirror to us is in scope, and custom collectors are ordinary onboarding work rather than a change order. Ask us about it.

If your vendor is not on this list

It is very likely already covered, and the names above are not the mechanism. Caver reads the published standard, not the badge on the cabinet. A controller nobody here has heard of that speaks Modbus/TCP, DNP3, IEC 60870-5-104, EtherNet/IP, S7comm, BACnet or OPC UA is decoded the day it appears on the network. An EHR nobody has heard of that emits FHIR AuditEvent or IHE ATNA works on day one. Any imaging device or archive that is DICOM-conformant is seen without its vendor being involved at all.

That is the whole reason this list is shorter than you expect: a vendor connector has to be written once per vendor, and it breaks the first time a product is renamed.

And where something genuinely is not covered, it gets built. Custom collectors are ordinary work here rather than a special request. If a system matters to you and nothing off the shelf reads it, say so during the trial.

OPC UA

Caver consumes OPC UA. How much of a session it can read depends on how that session is secured, and it is worth stating precisely because the claim is made loosely across this market.

Under SecurityPolicy None the traffic is in the clear and decodes like any other protocol. Under Sign or SignAndEncrypt the message bodies are protected, and Caver reads them when you provide the key material, the same arrangement any passive decoder needs for an encrypted session. Nothing here defeats the security of your OPC UA deployment, and no vendor should tell you otherwise: a passive tool either has the keys or it does not.

Without keys, the session itself is still visible and still useful: endpoints, certificate exchange, the policy in force, and the shape and timing of the conversation. Caver states which of the two it got rather than presenting partial visibility as complete, and it treats a session running SecurityPolicy None as a finding in its own right, because on a plant network that is exactly what it is.

Two things Caver will not do, and one it cannot

It will not write to a medical device or a control system. Not as an advanced option, not with a waiver, not when an operator asks it to. Three independent mechanisms enforce that, because the failure mode is an infusion pump or a ventilator: the response engine refuses any address on a clinical or control network before a request is built; the analysis code for that equipment is forbidden by an automated test from importing a network package at all; and the protocol decoders have no transmit path, also asserted by test. Some products in this space advertise that they flag or optionally correct. We deliberately do not.

It will not read an image. Caver reads the DICOM conversation, not the picture. The parser stops at the pixel data, which is both a privacy decision and the reason imaging monitoring costs no meaningful storage.

It cannot invent the care relationship. The most valuable field in an EHR audit record is the recorded reason an access was legitimate. CEF, LEEF and IHE ATNA have no field for it. FHIR AuditEvent can carry it, and only does when the sending system populates it. Where it is missing, behavioral detection degrades to counting, and Caver reports that it degraded rather than presenting a confident number.

How collection works · caver-industrial · Talk to us about your estate