The following table gives the codes and descriptions for major categories.
| Category code | Category | Description |
| 001 | Vulnerability | This category includes events triggered by an attempt to exploit a vulnerability in any application, operating system, or networked hardware device. |
| 002 | Malicious Code | This includes events triggered by viruses, worms, Trojans, backdoors, and all manner of blended malware threats. |
| 003 | Distributed Denial of Service (DDoS) | This category includes events triggered by traffic thresholds that indicate an attempt to make a resource unavailable. |
| 004 | Security Policy | This category includes events that indicate an attempt to violate an organization's security policy. It covers P2P, IM, email attachments, IRC, and other network communication types. |
| 005 | Reconnaissance or Suspicious Access | This category includes events that indicate network activity usually associated with common information gathering techniques used by attackers to launch more sophisticated attacks. |
| 006 | Application or Protocol Anomaly | This category includes events that indicate a violation of a protocol or application's RFC. |
| 007 | Traffic Thresholds | This category includes events triggered by predefined thresholds for specific applications or ports. |
| 008 | IP Filters | This category includes events triggered by predefined IP access control lists. |
