Works with Caver
What it reads, what it sends, and what it will not touch. Caver reads published standards rather than building one connector per vendor, which is why this list is shorter than you expect and covers more than you expect.
| System ▲▼ | Category ▲▼ | How it reaches Caver | Direction ▲▼ |
|---|---|---|---|
| Epic | EHR / EMR | Its own security and privacy feed, emitted natively as CEF, LEEF or RFC 5424 syslog. Or the Clarity access-log extract | In |
| Oracle Health (Cerner) | EHR / EMR | P2Sentinel Listener, which exists to forward Millennium audit events to an outside system | In |
| Meditech Expanse | EHR / EMR | Audit Trail settings and the MIS Dictionary audit log, via FHIR, HL7 or web services | In |
| Altera (Allscripts), NextGen, Greenway, athenahealth, eClinicalWorks | EHR / EMR | Audit trail via API or database extract. No published security feed, so the route is confirmed per site | In |
| Any standards-based EHRstandard | EHR / EMR | IHE ATNA audit records over syslog (RFC 3881), or FHIR AuditEvent | In |
| HL7 v2, all message typesstandard | Clinical messaging | Read from a mirror of the traffic. Caver is not in the message path | In |
| Mirth Connect, Rhapsody, Cloverleaf | Clinical messaging | The interface traffic plus the engine's own logs. Caver learns each interface's normal and reports the one that quietly stopped | In |
| FHIRstandard | Clinical messaging | AuditEvent for access, plus resource traffic where it is exposed | In |
| GE HealthCare, Siemens Healthineers, Philips, Canon Medical, Fujifilm, Samsung, Hologic, Konica Minolta, Carestream, Mindray | Imaging | DICOM association and query/retrieve activity. The parser stops at the pixel data | In |
| Sectra, Agfa, Fujifilm Synapse, GE Centricity, Philips Vue, Merative, Hyland, Intelerad | Imaging | Same DICOM conversation. Retrieves to an unrecognized destination lead the alert list | In |
| Any DICOM-conformant device or archivestandard | Imaging | DICOM on the wire. No vendor cooperation required | In |
| Infusion pumps: Baxter, BD (Alaris), ICU Medical, Smiths Medical, Fresenius Kabi, B. Braun | Medical devices | Passive. Learns the drug-library server it talks to | In |
| Patient monitors: Philips, GE HealthCare, Dräger, Mindray, Welch Allyn, Nihon Kohden | Medical devices | Passive. Learns its telemetry gateway | In |
| Ventilators: Dräger, Getinge, Medtronic, Hamilton, Vyaire | Medical devices | Passive | In |
| Dialysis: Fresenius, Baxter, B. Braun, Nikkiso | Medical devices | Passive | In |
| Lab analyzers: Roche, Abbott, Siemens Healthineers, Beckman Coulter, Sysmex | Medical devices | HL7 on the interface, plus network behavior | In |
| Dispensing cabinets: Omnicell, BD Pyxis, Swisslog, ARxIUM | Medical devices | HL7 and their own logs where available | In |
| Nurse call, tube, tracking: Rauland, Hillrom, Swisslog, CenTrak, Sonitor | Medical devices | Passive, plus their logs where they keep them | In |
| Siemens, Johnson Controls, Honeywell, Schneider Electric, Trane, Automated Logic, Delta Controls | Building automation | BACnet. Room pressure and air changes judged against ASHRAE 170 and FGI, with the citation on the finding | In |
| Rockwell Automation: Allen-Bradley ControlLogix, CompactLogix, MicroLogix | Industrial control | EtherNet/IP and CIP, passively. Vendor profile shipped | In |
| Siemens SIMATIC: S7-300, S7-400, S7-1200, and S7-1500 in compatibility mode | Industrial control | S7comm, passively. Vendor profile shipped. S7-1500 speaking S7CommPlus natively is a separate decoder, not this one | In |
| Schneider Electric: Modicon controllers | Industrial control | Modbus/TCP, passively. Vendor profile shipped | In |
| ABB: 800xA and connected controllers | Industrial control | Vendor profile shipped, plus the protocols its controllers speak | In |
| Honeywell: process and building controllers | Industrial control | Vendor profile shipped, plus the protocols its controllers speak | In |
| SEL, GE, Hitachi Energy, Eaton, Emerson, Yokogawa, Mitsubishi, Omron, WAGO, Phoenix Contact, Beckhoffstandard | Industrial control | Recognized by the protocol its equipment speaks: DNP3, IEC 60870-5-104 or Modbus/TCP | In |
| OPC UA | Industrial control | Decoded passively. Clear under SecurityPolicy None; under Sign or SignAndEncrypt when you provide the key material. Caver does not defeat the security of your deployment | In |
| SCADA and HMI hosts | Industrial control | Their Windows event logs, correlated with the control traffic they generate | In |
| Dragos, Claroty | OT security | Their findings, correlated with the rest of the estate | In |
| Microsoft Entra ID, Okta, Duo, JumpCloud, OneLogin, Auth0, Keycloak | Identity | API or log feed | In |
| CrowdStrike Falcon, SentinelOne, Microsoft Defender, Carbon Black, Trend Micro Vision One, Wazuh, osquery, Sysmon | Endpoint | API or log feed | In |
| AWS CloudTrail and GuardDuty, Microsoft 365 and Sentinel, Google Workspace, Kubernetes, Snowflake, MongoDB Atlas | Cloud | Native audit trail | In |
| Cisco Meraki and Umbrella, Cloudflare, Tailscale, NetFlow, SNMP, firewall syslog | Network | Log feed or flow record | In |
| Windows Security and System event logs, Linux auditd, SSH, RDP, PowerShell script blocks | Servers | Agent or forwarder | In |
| Salesforce, ServiceNow, Atlassian, GitHub, GitLab, Slack, Zoom, Box, Dropbox, Stripe, HubSpot | SaaS and business | Audit API | In |
| Managed model providers, self-hosted inference, agent frameworks, MCP, vector databases, coding assistants | AI estate | Gateway, proxy or provider audit log | In |
| Ticketing, chat and paging: webhook, Slack, email, on-call | Outbound | Caver pushes findings out. Nothing coming back changes what Caver decided | Out |
| Your network edge, only if you enable it | Outbound | The one place Caver acts: block and unblock a source address, behind an approval gate, a never-block list, and an automatic refusal for any address on a clinical or control network | Both |
If your vendor is not on this list
It is very likely already covered, and the names above are not the mechanism. Caver reads the published standard, not the badge on the cabinet. A controller nobody here has heard of that speaks Modbus/TCP, DNP3, IEC 60870-5-104, EtherNet/IP, S7comm, BACnet or OPC UA is decoded the day it appears on the network. An EHR nobody has heard of that emits FHIR AuditEvent or IHE ATNA works on day one. Any imaging device or archive that is DICOM-conformant is seen without its vendor being involved at all.
That is the whole reason this list is shorter than you expect: a vendor connector has to be written once per vendor, and it breaks the first time a product is renamed.
And where something genuinely is not covered, it gets built. Custom collectors are ordinary work here rather than a special request. If a system matters to you and nothing off the shelf reads it, say so during the trial.
OPC UA
Caver consumes OPC UA. How much of a session it can read depends on how that session is secured, and it is worth stating precisely because the claim is made loosely across this market.
Under SecurityPolicy None the traffic is in the clear and decodes like any other protocol. Under Sign or SignAndEncrypt the message bodies are protected, and Caver reads them when you provide the key material, the same arrangement any passive decoder needs for an encrypted session. Nothing here defeats the security of your OPC UA deployment, and no vendor should tell you otherwise: a passive tool either has the keys or it does not.
Without keys, the session itself is still visible and still useful: endpoints, certificate exchange, the policy in force, and the shape and timing of the conversation. Caver states which of the two it got rather than presenting partial visibility as complete, and it treats a session running SecurityPolicy None as a finding in its own right, because on a plant network that is exactly what it is.
Two things Caver will not do, and one it cannot
It will not write to a medical device or a control system. Not as an advanced option, not with a waiver, not when an operator asks it to. Three independent mechanisms enforce that, because the failure mode is an infusion pump or a ventilator: the response engine refuses any address on a clinical or control network before a request is built; the analysis code for that equipment is forbidden by an automated test from importing a network package at all; and the protocol decoders have no transmit path, also asserted by test. Some products in this space advertise that they flag or optionally correct. We deliberately do not.
It will not read an image. Caver reads the DICOM conversation, not the picture. The parser stops at the pixel data, which is both a privacy decision and the reason imaging monitoring costs no meaningful storage.
It cannot invent the care relationship. The most valuable field in an EHR audit record is the recorded reason an access was legitimate. CEF, LEEF and IHE ATNA have no field for it. FHIR AuditEvent can carry it, and only does when the sending system populates it. Where it is missing, behavioral detection degrades to counting, and Caver reports that it degraded rather than presenting a confident number.
How collection works · caver-industrial · Talk to us about your estate