All pages
Browse by topic, or use search when you know the term. Every article is also available as Markdown on GitHub.
Start here 12
- Start here
Pick the system or task you're working on, then follow the relevant reading path. This section also explains the terminology, sources and safety labels used in the wiki.
- Build a video integration
Work through camera discovery, media sessions, events and video platform APIs.
- Build an event integration
Work through event fields, MQTT delivery, timestamps and recovery after a connection fails.
- Find the next diagnostic check
Start with the symptom, collect the relevant observations and use them to narrow down the cause.
- Glossary and conventions
A camera vendor, an access control engineer and a developer can use the same word differently. These definitions explain how terms are used throughout the wiki.
- How to use this knowledge base
Start with what you're trying to understand or fix. Follow the links to the relevant specification and product documentation, and check which parts apply to your equipment.
- Learning paths
Choose a reading path for your current task. Each path links the background, protocols and practical checks you need to work through it.
- New to physical security
Start with the main systems, then work through the networking, identity and event handling needed for an integration.
- Review security and readiness
Review the integration's scope, permissions, sources, failure handling and acceptance requirements.
- Scope and boundaries
This wiki covers the software and interfaces used in physical security systems. Installation, site engineering and approvals still require the relevant product instructions and qualified people.
- Understand an access control integration
Work through credentials, readers, controllers and door state, including how access decisions reach the equipment.
- Verification and safety
Software can affect doors, alarms, cameras, gates and emergency workflows. Check the physical outcome, permissions and failure behaviour before making changes to a live system.
Foundations 23
- Foundations
Networking, power, identity, events and system architecture are common to most integrations. These pages explain the basics and link to the relevant protocol references.
- Architecture and layering
Break the system into electrical interfaces, network transport, messages and application decisions. Identifying the layer involved helps you choose the right diagnostic check.
- Credentials and identity media
Follow a credential through issue, use, expiry and revocation. Check how the card, phone or biometric is linked to an identity and an access decision.
- Data models and semantics
Agree on identity, state, timestamps and units before mapping data between systems. Record which system owns each field and how conflicting values are handled.
- Dry contacts and supervised circuits
A dry contact reports an electrical state. Its meaning depends on the wiring, configuration and system design, so record those details before interpreting it as a door event.
- Encoding and serialisation
Validate incoming data before using it. Check its size, encoding, structure and values, including data from devices on a private network.
- Ethernet, PoE, and power budgets
Check the whole power path when planning PoE. Include device startup, cable losses, switch capacity, backup power and shared points of failure.
- Events, state, commands, and time
Events record changes, state describes the current view of a system, and commands request an action. Keep those records distinct when building an integration.
- Identity, authentication, and authorisation
Record the identity, how it is authenticated and which operations it may perform. Apply permissions to the relevant devices, resources and actions.
- Interoperability, conformance, and profiles
Check the exact product, firmware, role, profile and optional features when reviewing compatibility. Keep the supporting documentation with the integration requirements.
- IP addressing, routing, and ports
Record the addresses, routes, ports and connection direction used by each service. Verify the responding device and its identity separately.
- Media streaming fundamentals
Follow the video through capture, encoding, session setup, transport, decoding and storage. Check each stage when investigating playback, quality or recording problems.
- Multicast, discovery, and NAT
Check how discovery traffic crosses the network and how devices are enrolled afterwards. Verify device identity before using an advertised service.
- Networking fundamentals
Video, voice, management and alarm traffic have different network requirements. Plan for each flow's capacity, timing, packet loss and recovery needs.
- Observability and evidence
Useful diagnostics record the source, timestamp and result of each observation. Keep enough context to trace a problem through the devices and services involved.
- Physical security system architecture
Map the devices, services and people involved in each workflow. Record which components observe events, make decisions and control equipment.
- Reliability and failure semantics
A controller may act before its response is lost. Account for uncertain results when setting timeouts, retries and recovery behaviour.
- Secure integration lifecycle
Plan identity, supported versions, failure handling and recovery during design. Assign ownership for the integration after commissioning and through to retirement.
- Serial and field interfaces
Check the electrical interface, bus layout, framing, addressing and application protocol before connecting serial equipment. Record the settings used by both ends.
- Time synchronisation for security systems
Keep device time and receipt time with each event. Use both when investigating delay, clock drift and events that arrive out of order.
- TLS, PKI, and certificates
Check certificate identity, trust, expiry and renewal as part of the connection setup. Include certificate failures and recovery in the operating plan.
- Trust boundaries and segmentation
Mark where ownership, identity, permissions and physical control change across the system. Use those boundaries to plan segmentation and access rules.
- Wireless and radio fundamentals
Radio links depend on range, interference, obstructions and the surrounding environment. Check device authentication and recovery as well as signal quality.
Protocols 68
- Access control protocols and credentials
These pages cover reader communication, credential formats and mobile credential technologies. Use them alongside the access control system references.
- Alarm monitoring protocols
Follow alarm reports from the premises through the receiver to monitoring software. Check message acceptance, supervision and the operator response at each stage.
- Building and industrial protocols
These references cover interfaces used by building and industrial systems. Define the required data exchange and approval for any control functions before planning an integration.
- Interoperability and legacy protocols
These references cover older and less common interfaces. Check the supported version, device role and limitations before using them in an integration.
- Protocol infrastructure
Addressing, identity, time, power and administration support the main application. Use these references when checking the services and interfaces underneath an integration.
- Protocols
Browse the protocols by system or function. Each page explains the interface, common integration requirements, limitations and supporting sources.
- Video and media protocols
Video systems use separate paths for control, media, metadata and events. These references explain the protocols involved in each part.
- Web and messaging protocols
These interfaces carry requests and events between applications. Choose a delivery mechanism, then define message meaning, permissions, retries and recovery.
- AAA and network access
Check network admission and application permissions separately. Record how devices join the network and what each operator or service may access afterwards.
- Ademco Contact ID and SIA DC05
Contact ID represents alarm reports using defined event codes. Record how the account, event, acknowledgement and monitoring response are mapped in your integration.
- AMQP 1.0 messaging
AMQP 1.0 defines messaging, delivery state and flow control. Map its settlement behaviour to how your application stores, processes and acknowledges security events.
- BACnet family
BACnet uses objects and services to exchange building system data. Check the network type, supported device functions and security configuration for the installation.
- BACnet MS/TP
BACnet MS/TP runs over a shared serial bus. Check bus timing, addresses and topology alongside the objects and services used by the application.
- BACnet Secure Connect
BACnet Secure Connect protects BACnet communication using its own connection and certificate model. Plan device identity, certificate management and application permissions together.
- BACnet/IP
BACnet/IP carries BACnet traffic over an IP network. Check discovery, broadcasts and routing alongside the objects, services and access rules your integration needs.
- CAN, CANopen, and SAE J1939
CAN provides the bus, while CANopen and J1939 define additional communication rules. Identify the message model and device profile before interpreting traffic.
- CAP and EDXL emergency messaging
CAP and EDXL exchange warning and emergency information. Check the issuing authority, message lifecycle, recipients and acknowledgement requirements of the receiving workflow.
- CoAP, OSCORE, and Lightweight M2M
CoAP, OSCORE and LwM2M provide different parts of a constrained device system. Document which combination handles transport, message protection and device management.
- Codecs, RTP payloads, and streaming design
Match the codec profile, level and packetisation to the decoder and recording system. Include playback and export when checking compatibility.
- Contactless and smart card standards
Check both the contactless interface and the credential application. Record how identity, authentication and credential management work with the chosen card and reader.
- Credential formats, smart credentials, and mobile credentials
A credential includes its issuer, identity binding, keys and lifecycle. Check how those details are carried between physical cards, phones and access control systems.
- Discovery and addressing
Device discovery, address assignment and identity verification are separate steps. Validate the advertised service information before using it to establish a connection.
- DNP3
DNP3 exchanges point values, events and commands. Check event classes, timestamps, quality flags and the security features supported by each device.
- Enterprise federation with SAML and OpenID Connect
Federation passes authentication information from an identity provider to an application. Check claims, sessions, account changes and the permissions applied by the receiving service.
- EtherNet/IP and CIP
EtherNet/IP uses the CIP object and service model. Identify the required objects, timing and permissions, and separate monitoring from industrial control.
- GB/T 28181 video surveillance networking
GB/T 28181 includes registration, signalling and media exchange. Check the edition, device roles and supported flows for each side of the integration.
- gRPC and serialisation contracts
gRPC uses typed service definitions and serialised messages. Define permissions, deadlines and failure handling for each operation alongside the API schema.
- HTTP and REST API engineering
HTTP provides request and response behaviour for web APIs. Define the resources, permissions and physical effects associated with each operation.
- IEC 60839 alarm transmission systems and IP messaging
The IEC alarm transmission publications cover different parts of the reporting system. Identify the relevant publication for the premises equipment, receiver and message exchange.
- IEC 60870-5-101 and IEC 60870-5-104
The IEC 60870 telecontrol family defines transport and information exchange for operational systems. Check the applicable edition, message objects, timing and control responsibilities.
- IEC 61850
IEC 61850 includes several models and communication services. Identify the service, timing requirements and engineering context before designing a gateway or data consumer.
- IP transport and segmentation
List the endpoints, transports and connection direction your integration requires. Use that list to define routing, segmentation and firewall rules.
- KNX
KNX exchanges building control information through devices and group addresses. Document what each address means and which components may send or act on it.
- KNX Secure
KNX Secure provides specific protection for KNX communication. Check the secure mode, device support, key management and commissioning process used on the site.
- Legacy reader interfaces: Wiegand and Clock and Data
Wiegand can refer to the electrical interface or the credential bit format. Record both, along with the authentication and protection provided elsewhere in the system.
- Matter
Matter defines device communication, identity and commissioning. Check the required device types and supported features against the exact products involved.
- Modbus family
Modbus exchanges values using function codes and addresses. Use the device's register map to interpret data types, byte order, units and permitted operations.
- Modbus RTU
Modbus RTU uses a serial connection. Check addressing, framing and timing, then use the device's register map to interpret the returned values.
- Modbus Security
Modbus Security adds protected transport and peer identity to Modbus. Apply it alongside the device register map and permissions for each read or write.
- Modbus TCP
Modbus TCP carries Modbus exchanges over IP. Check the register map, network restrictions and permitted operations for the device you're connecting.
- Monitoring and secure administration
Health monitoring and remote administration require different permissions. Separate collection accounts from configuration access and record administrative sessions.
- MQTT 5.0, MQTT 3.1.1, and Sparkplug 3.0
MQTT moves messages between clients through a broker. Define topic meaning, publish and subscribe permissions, retained state and delivery handling in the application.
- NFC, Bluetooth Low Energy, and UWB for access control
NFC, BLE and UWB provide communication or ranging functions. Check how the credential is authenticated and how the access control system uses the result.
- NTP, NTS and PTP time synchronisation
Time services support event ordering, certificate checks and evidence handling. Record the clock source and the application's response to clock faults or outages.
- ONVIF services, profiles, conformance, and security
ONVIF defines services and profiles for devices and clients. Check the registered product, firmware, service capabilities and operations required by your integration.
- OPC Unified Architecture
OPC UA provides information models, services and security policies. Check which ones the server implements and how client identities are authorised.
- OSDP reader and controller protocol
OSDP connects readers and other peripheral devices to a controller. Check Secure Channel support, key setup, supervision and recovery on both ends of the connection.
- Pelco D and Pelco P
Pelco D and P are legacy camera control protocols. Use offline traces to inspect the command set, addressing and response behaviour for the relevant equipment.
- Power, USB, and GPIO
Power, USB and GPIO connections can affect device security and physical behaviour. Check their electrical requirements, exposed functions and control permissions.
- PROFINET
PROFINET connects industrial devices with defined timing and engineering requirements. Record the device roles, configuration and supported traffic before planning an integration.
- PSIA Physical Logical Access Interoperability
PLAI exchanges identity and access information between systems. Track the source identity, destination permissions and enforcement state when checking synchronisation and revocation.
- PSIA specification family
PSIA publishes several interoperability specifications. Identify the relevant specification, product version and supported role before selecting an interface.
- RTSP, RTP, RTCP, and SDP
RTSP controls a media session, SDP describes it, RTP carries the media packets and RTCP reports session information. Check each part when investigating a stream.
- SCIM identity provisioning and reconciliation
SCIM exchanges identity lifecycle information between systems. Track provisioning results and check whether changes have reached dependent credentials and access policies.
- Serial transports
Agree on electrical signalling, framing, timing and addressing before decoding serial messages. Check the settings and supported interfaces at both ends.
- SIA AV01 audio verification and two way voice commands
SIA AV01 covers audio verification for alarm monitoring. Check how its voice and control functions interact with the premises equipment and monitoring workflow.
- SIA DC03 alarm event format
SIA Format describes alarm messages exchanged by transmitters and receivers. Check the message structure, account identity, event mapping and acknowledgement behaviour.
- SIA DC07 receiver to automation interface
SIA DC07 carries information from a receiver to monitoring automation. Check receiver status, event storage and operator handling as separate stages.
- SIA DC09 IP event reporting
SIA DC09 carries alarm reports over IP networks. Check receiver acknowledgement, account identity, security settings and recovery when delivery is uncertain.
- SIP and SRTP for intercom and real time media
SIP manages call signalling while SRTP protects media. Check both paths, and give any door control its own authentication and permissions.
- SOAP, WSDL, XML Schema, and secure XML processing
SOAP, WSDL and XML Schema describe service messages and interfaces. Check parser limits, authentication and operation rules when building a client.
- Sony VISCA and VISCA over IP
VISCA carries camera control commands. Check supported operations, addressing and responses, then confirm how the device reports its final state.
- SRT and RIST contribution streaming
SRT and RIST transport media across networks with packet loss and delay. Check the required protocol, recovery settings and compatible endpoints.
- TLS, PKI, and secure transport
Review TLS settings alongside certificate provisioning, validation, renewal and recovery. Check the identity and trust requirements of each device and service.
- WebAuthn, FIDO, and passkeys
WebAuthn and FIDO provide authentication mechanisms. Check the authenticator, relying party, account recovery and application permissions when using passkeys for administration.
- WebRTC for physical security media
WebRTC provides browser media and data communication. Plan signalling, user identity, permissions and connection setup as part of the application.
- WebSocket, Server Sent Events, and webhooks
WebSocket, SSE and webhooks support different connection directions and lifetimes. Choose the required delivery model, then define ordering, retries, permissions and recovery.
- Wireless and low power links
Check radio performance, power use, device authentication and key management together. Include battery loss, interference and reconnection in the recovery plan.
Systems 39
- Integration platforms
Integration platforms combine information from several systems. Record the owner of each event, decision and control function, and restrict access to the required operations.
- Intercom and emergency communication systems
Intercom and emergency communication systems can share devices and networks. Check the authority, supervision and availability requirements for each service.
- Intrusion and monitoring systems
Intrusion systems detect conditions, report alarms and support a response. These pages follow those stages through the panel, communicator, receiver and monitoring service.
- Perimeter and detection systems
Perimeter systems combine sensors, assessment and response. Keep the source and uncertainty with each detection as it moves through the workflow.
- Physical access control systems
Access control links identities and credentials to decisions made by controllers. These pages cover the readers, doors, permissions and operating conditions involved.
- Physical security systems
These pages explain the equipment and platforms used in physical security. Follow the devices, decisions and dependencies involved in each workflow.
- Video surveillance systems
Follow video from the scene through viewing, recording and export. Check picture quality, storage and retrieval when assessing whether the system meets its purpose.
- Alarm communicators, receivers, and monitoring
Trace the report from the communicator through the receiver to monitoring software. Record what each acknowledgement confirms and how the response is handled.
- Alarm path supervision and verification
Path supervision checks communication availability. Alarm verification gathers information about the reported condition. Record and monitor the results separately.
- ANPR and LPR systems
ANPR and LPR systems interpret number plates from images. Keep the confidence, original observation and matching rule with any resulting access decision.
- Biometric access control systems
Biometric systems compare a sample with a stored reference. Record the match threshold, operating conditions, uncertainty and recovery process used by the application.
- BMS and SCADA integration
Define the data exchanged with building or industrial systems. Check ownership and approval for any controls exposed through the integration.
- Cameras and video encoders
Cameras combine imaging, encoding, services and device management. Check those functions separately when investigating video or integration problems.
- Cloud, mobile, and multi tenant security platforms
Cloud services introduce provider, network and tenant dependencies. Record what runs locally, what relies on the provider and how the site operates during an outage.
- Credential lifecycle systems
Manage credentials through issue, expiry, revocation and replacement. Check how each change reaches controllers, including equipment that is temporarily offline.
- Duress, panic, and fire system boundaries
Duress, panic and fire events require their own response rules. Preserve the original event class and the authorised workflow when mapping them into another system.
- Emergency phones, mass notification, and public address
Emergency phones, mass notification and public address serve different workflows. Check supervision, priority, privacy and availability for the service being provided.
- Gates, barriers, and vehicle access
Gates and barriers involve moving machinery. Access software can request passage, while the approved local controller and safety functions govern movement.
- HR, identity, and visitor integration
HR records, visits and access entitlements have separate owners and lifecycles. Define how changes move between the systems and how conflicts are resolved.
- Intercom call routing, media, and door control
Trace call signalling, media and notifications separately. Give door release its own identity check, permissions and recorded result.
- Intercom system architecture
Break an intercom system into identity, call control, media, notifications and physical outputs. Record which component handles each function.
- Intrusion panels, zones, and sensors
Preserve the panel's zone states, faults and tamper reports when collecting events. Document any mapping or additional context applied by the receiving system.
- Locks, egress, and life safety boundaries
Lock and egress behaviour depends on the opening, failure condition and approved design. Check the requirements for each door with the responsible site professionals.
- Mobile access systems
Mobile access spans the phone, app or wallet, issuer, reader and access control platform. Include lost devices, replacement and account recovery in the design.
- Offline operation and antipassback
Offline controllers may use cached credentials and rules. Document the allowed behaviour during an outage and how credentials, events and occupancy are reconciled afterwards.
- PACS architecture
Identify where access decisions are made and where records are managed. Check how controllers enforce cached rules when the server or network is unavailable.
- Panels, readers, and door I/O
Readers, lock outputs, door contacts and requests to exit report different information. Track access decisions, relay state and door state separately.
- Pedestrian portals, turnstiles, and interlocked doors
Pedestrian portals combine access decisions, movement control and local safety functions. Record the responsibilities and approvals for each part of the passage sequence.
- Perimeter security architecture
Map the perimeter into detection zones and assessment areas. Define the purpose, response path and responsible operator for each sensor layer.
- PSIM and command platforms
PSIM and command platforms bring events and operator workflows together. Keep source information, operator decisions and control permissions visible in the shared interface.
- PTZ and camera device I/O
PTZ movement and device outputs can affect the physical environment. Apply permissions and operating limits separately from access to the video stream.
- Radar, fence, and buried perimeter detection
Radar, fence and buried sensors measure different physical effects. Include installation conditions, environmental effects and uncertainty when interpreting their outputs.
- Recording, storage, and retention
Check recording from capture through storage, indexing, retrieval and playback. Compare the retained footage with the required duration and quality.
- SIEM, SOAR, and case management
SIEM, SOAR and case management systems collect and process security information. Assign ownership for telemetry, investigation records and any automated physical actions.
- Video analytics and metadata systems
Video analytics reports observations from a model operating in a particular scene. Retain the model, confidence and scene context when applying downstream rules.
- Video evidence export and integrity
Keep file hashes, source details, transformations and custody records with video exports. Record what the available evidence establishes about the footage and its timestamps.
- Video system health and service monitoring
Check image freshness, usability and recording as well as camera connectivity. Record which function was tested and when the observation was made.
- Visitor, identity, and elevator integration
Visitor, HR, access control and lift systems own different records and decisions. Define the approved exchange and permissions between them.
- VMS, NVR, and VSaaS platforms
VMS, NVR and cloud video platforms manage different combinations of devices, recording, users and events. Identify the supported interface for the workflow you're building.
Vendor APIs 26
- Access and identity APIs
These references cover identity, credential and event interfaces in access control platforms. Confirm access conditions and product support before implementing a client.
- Device and edge video APIs
Choose between communicating with device services and deploying an application on the device. Check permissions, deployment requirements and product support for that approach.
- Vendor APIs and SDKs
Find the supported API for the exact product and version. These pages cover public documentation, access requirements, licensing and integration checks.
- VMS and cloud video APIs
These references cover video platform interfaces for live media, events, recording, export and administration. Check support for each required workflow.
- 2N HTTP and platform APIs
Check whether the integration uses a 2N device API or a platform service. Apply separate permissions to calls, events, status and relay control.
- Axis VAPIX and ACAP
VAPIX provides device interfaces while ACAP supports applications on Axis devices. Check the model, firmware and capabilities required by the chosen approach.
- Bosch video and device integration
Identify the Bosch product and supported integration method. Check media, device control, events and platform functions against the relevant documentation.
- Brivo Access API
Check the Brivo API workflow, access requirements and supported resources. Map identities, credentials, events and permissions to the needs of your integration.
- Dahua CGI and NetSDK
Check whether the Dahua integration uses CGI or NetSDK. Record supported models, firmware, authentication and callback behaviour before implementing the client.
- Eagle Eye Video API
Check the Eagle Eye API and authentication flow for the required customer scope. Review media access, event retrieval and retention before implementation.
- Gallagher Command Centre integrations
Choose the supported Command Centre interface for the task. Record licensing, product versions and operation permissions before implementing the integration.
- Genetec Security Center SDK and Web API
Choose the appropriate Security Center SDK or web API interface. Check licensing, versions and roles against the functions required by your application.
- Hanwha Vision SUNAPI and Open Platform
SUNAPI provides device access, while Open Platform supports applications on compatible Hanwha devices. Check firmware, supported operations and deployment requirements.
- HID Origo and Mobile Access APIs
Trace the HID service, mobile credential lifecycle and reader interaction. Check provisioning and revocation across the full access path.
- Hikvision ISAPI and HEOP
Choose the appropriate ISAPI or HEOP integration approach. Confirm device and firmware support, API permissions, event handling and application lifecycle requirements.
- Johnson Controls C•CURE integrations
Confirm the C•CURE product version, supported interface and access requirements. Check event behaviour and compatibility against the documentation for that release.
- Kisi API and mobile SDKs
Identify the Kisi resources and permissions needed by the application. Handle account changes, event delivery and physical controls as separate operations.
- LenelS2 OnGuard, OpenAccess, and Elements
Identify the exact OnGuard or Elements platform and supported interface. Check where OpenAccess applies before planning identity, event or control integration.
- Milestone MIP SDK and API Gateway
Compare MIP SDK and API Gateway against the required XProtect workflow. Check supported versions, permissions and deployment before implementing video, event or configuration access.
- Motorola Solutions and Avigilon integration interfaces
Identify the exact Avigilon platform and release. Check its interfaces, access requirements and supported media or event functions.
- Network Optix Nx Meta APIs and SDKs
Choose the Nx interface for server access, client integration, device support or analytics. Record the product version and supported SDK or API capabilities.
- SALTO APIs
Identify the SALTO product family, then check its API, credential model and access requirements. Record the supported operations for the specific platform.
- Suprema BioStar 2 API
Check the BioStar 2 version and supported API path. Review sessions, identity changes and event handling against the device and platform configuration.
- Vendor API selection and capability matrix
Compare APIs against the required workflow. Record product versions, access conditions, identity handling, event support and the operations your application needs.
- Verkada Command APIs
Check the Command API and organisation scope for the integration. Assign separate permissions for credentials, events, media and control operations.
- Zenitel APIs and SDKs
Select the Zenitel interface for the communication workflow. Check product support for call state, media, notifications and any physical control.
Development 31
- Code examples
Small programs for common integration tasks. Download one file, run its demo and inspect the result.
- Development and integration
These pages cover adapter patterns, language choices and implementation examples. Start with the interface requirements, then plan validation, error handling and recovery.
- Integration patterns
These patterns cover retries, stale state, reconnection, schemas and secrets. Apply them consistently across adapters and document the behaviour your application relies on.
- Language guides
Choose a language that suits the interface and deployment. These notes cover validation, resource ownership, cancellation and recovery in each environment.
- Adapters, gateways, and protocol translation
Define whether the component forwards transport data, translates a protocol or maps application meaning. Document the fields and behaviour it changes or preserves.
- C protocol development
C gives direct control over bytes, memory and native interfaces. Check buffer limits, ownership and error paths, then compile and test for the intended target.
- C# protocol development
In C#, check cancellation, asynchronous lifetimes and typed data handling. Define reconnect behaviour and how the application represents uncertain operation results.
- C++ protocol development
Use explicit ownership and resource limits when working with C++ SDKs. Document callback threads, object lifetimes and error handling in the adapter.
- Event API contracts, normalisation, and schema evolution
Use a shared schema while preserving the source event. Keep the raw record, mapping version and any uncertainty with the normalised fields.
- Event trace normalisation
Validate saved JSONL events and convert their occurrence timestamps to UTC.
- Go protocol development
Go supports small integration services with explicit timeouts and cancellation. Define resource ownership and connection settings for each device or API client.
- HTTPS JSON read
Read one HTTPS health endpoint with certificate validation and a bounded JSON response.
- Modbus register read
Read holding or input registers from one authorised Modbus TCP endpoint.
- Modbus RTU frame and CRC
Check the size, fields and CRC of a captured Modbus RTU register response.
- MQTT event validation
Check an MQTT topic and JSON event against a small, explicit application contract.
- Mutual TLS health client
Read a health endpoint using a validated server certificate and your own client certificate.
- Observability and diagnostics
Design logs and metrics around the faults you'll need to investigate. Trace events across the integration while protecting credentials and retaining source context.
- ONVIF device information
Send a read only GetDeviceInformation request to one ONVIF device service over HTTPS.
- Polling, subscriptions, and state reconciliation
Polling and subscriptions provide different views of system changes. Plan gap detection and state reconciliation so the application can recover after missed events.
- Python protocol development
Python suits adapters, offline analysis and small services. Validate incoming data, limit network and file operations, and keep dependencies appropriate to the task.
- Reconnect, backpressure, and queues
Define what happens to queued work during an outage. Limit backlog growth, handle stale events and account for consumers that process messages slowly.
- Retries, timeouts, and idempotency
Plan retries, timeouts and idempotency together. Check whether repeating an operation could repeat a physical action after the original response was lost.
- RTSP and SDP inspection
Inspect the media descriptions in a saved RTSP DESCRIBE response.
- Secrets, certificates, and configuration
Keep credentials and trust settings out of source control, examples and logs. Give deployed configuration an owner, validation rules and a recovery process.
- SQLite event deduplication
Store an event once and detect an identity reused with different content.
- Timestamp normalisation in C#
Keep event occurrence and receipt times separate while converting both to UTC.
- TLS certificate expiry check
Check the certificate presented by one TLS endpoint without bypassing chain or hostname validation.
- TypeScript protocol development
TypeScript describes expected data during development. Validate incoming messages at runtime and manage connection state, permissions and cancellation in the application.
- Video storage calculator
Estimate continuous recording capacity from measured bitrate, retention and free space requirements.
- Webhook signature verification
Verify an HMAC signature over an unchanged request body and its timestamp.
- WebSocket event reader
Read a short stream of door state events over WSS using Node and its native WebSocket API.
Security 15
- Security and assurance
Review the integration from its inputs through to the equipment it can affect. Record permissions, deployed versions, failure cases and the evidence supporting each control.
- API and event security
Check who can publish an event and what the consumer may do with it. Validate the message, its source and its authority before acting.
- Firmware updates and software supply chain
Review an update's origin, supported installation path and effect on the deployed system. Check compatibility and rollback limits before scheduling the change.
- Identity, authentication, and authorisation controls
Review identities, authentication methods and permissions across devices, operators and services. Include credential changes, denied operations and account removal in the checks.
- Logging, time, and evidence integrity
Keep source records, clock information and transformation history together. Record which device produced each event and how the application processed it.
- PKI, certificates, keys, and secrets
Plan how certificates, keys and secrets are issued, stored, renewed and removed. Assign ownership and recovery procedures for each part of the lifecycle.
- Privacy and sensitive data
Video, access and alarm records can contain sensitive information. Limit collection and access to the workflow's needs, and obtain the required privacy and governance review.
- Remote access
Give each remote support session a defined purpose, scope and expiry. Restrict permissions and record administrative actions through the site's approved process.
- Resilience, backup, and recovery
Test restoration of the required system state and plan operation during dependency outages. Include reconciliation of changes made while services were unavailable.
- Secure commissioning and onboarding
Verify device identity, software, configuration and ownership during commissioning. Record the approved settings and recovery process before putting the device into service.
- Secure protocol parsing
Check message size, structure, types and meaning before processing the contents. Apply the same limits to network data, SDK callbacks and saved captures.
- Secure system baselines
Use the relevant product guidance to establish security settings. Record the intended outcome, implemented controls, exceptions and evidence for the deployed configuration.
- Segmentation and conduits
Define the required network flows and permissions between zones. Use segmentation alongside device security, application access rules and monitoring.
- Threat modelling and trust boundaries
Trace events and commands through the system. Assess forged, delayed, duplicated and lost messages, including their possible effects on physical equipment.
- Vulnerability management and disclosure
Map vulnerability findings to the installed version, configuration and exposure. Use that context to plan remediation, approvals and the change window.
Operations 11
- Operations and lifecycle
These pages cover the work after development: inventory, commissioning, monitoring, updates, recovery and retirement. Assign an owner for each operating task.
- Asset and configuration inventory
Record device versions, identities, owners and dependencies in the inventory. Include the recovery information needed to assess changes and investigate incidents.
- Certificate and account lifecycle
Maintain records for certificates, service accounts, operators and physical credentials. Assign owners, review triggers and removal processes for each.
- Change, firmware, and patching
Check updates against the interfaces your integration uses. Review authentication, events, codecs, storage, timing and rollback before deploying a new version.
- Commissioning and acceptance
Collect acceptance evidence from the installed system. Include normal operation, denied requests, degraded conditions and recovery after failures.
- Decommissioning and disposal
Revoke device identities, cloud claims, credentials and integrations during retirement. Handle stored data and backups through the approved disposal process.
- Incident response and evidence
Assess the impact on physical security while investigating an incident. Preserve evidence and obtain approval before isolating equipment or changing a live service.
- Monitoring and health
Monitor the function each service provides, including video freshness, event delivery and controller state. Record connectivity separately from those functional checks.
- Operational runbooks
Write runbooks with the symptom, checks, expected results and escalation point. Keep live changes tied to the site's approved procedures.
- Requirements and procurement
Write requirements that can be tested against a product and version. Specify the required profiles, operations, failure behaviour and acceptance evidence.
- Site survey and design records
Record layout, power, network routes, interfaces, ownership and dependencies during the survey. Mark uncertain assumptions for confirmation before implementation.
Defensive labs 17
- Defensive labs
Practise using synthetic traces, sanitised configurations and tabletop scenarios. The exercises stay offline and separate from operational devices, real credentials and physical controls.
- Camera and controller hardening review
Compare a sanitised configuration with the matching product documentation. Record the supported controls, missing evidence and items requiring further review.
- Certificate rotation and restore tabletop
Work through certificate renewal and restoration on paper. Identify owners, dependencies and recovery steps for expiry and broken trust relationships.
- Lab authorisation, topology, and safety
Set the scope before starting a lab. Use the supplied synthetic or sanitised records, calculations and local simulations, with no connection to operational equipment.
- Modbus and BACnet interpretation
Interpret synthetic Modbus values and BACnet objects using the supplied definitions. Record uncertain mappings and keep the exercise separate from building equipment.
- MQTT TLS and ACL review
Review broker trust and topic permissions in a synthetic design. Check publisher and subscriber access, retained messages and replay handling.
- Offline packet and trace reading
Read an offline trace with a specific question in mind. Record the observed bytes, supported conclusions and information missing from the capture.
- ONVIF discovery and media flow reasoning
Map a fictional ONVIF device through discovery, services, media and events. Use the supplied offline material to follow each stage.
- OSDP and Wiegand offline decoding
Decode synthetic reader messages locally. Compare electrical framing, payload interpretation and authentication without using real credentials or hardware.
- Physical security incident response tabletop
Use a fictional incident to practise evidence collection, approvals and service continuity decisions. Record the proposed response without making changes to live systems.
- RTSP, RTP, RTCP, and SDP trace analysis
Follow session setup and packet flow in a synthetic media trace. Use the observations to identify which protocol layer needs further investigation.
- SIA DC09 validation planning
Plan an alarm reporting test using a fictional system. Specify evidence for message acceptance, supervision and monitoring response without generating a real alarm.
- SNMP and syslog health correlation
Compare synthetic SNMP and syslog records for the same components. Keep identity and clock context with each observation when assessing service health.
- Time drift and event correlation
Use synthetic timestamps to distinguish clock drift from delivery delay. Compare device time, receipt time and the expected event order.
- TLS certificate chain review
Inspect an offline certificate chain against its intended identity. Check trust, names and validity, and record the reason for each result.
- Video bandwidth and storage calculation
Calculate a fictional video recording budget. State the bitrate, retention, overhead and failure capacity assumptions so the result can be checked.
- WebSocket event flow review
Follow a synthetic WebSocket event through validation, processing and recovery. Check connection loss and repeated messages without contacting a production service.
Reference 18
- Reference
Look up matrices, field guides and checklists here. Follow the linked topic pages for the explanation and sources behind each entry.
- Acronyms and initialisms
Look up acronyms used in the wiki and follow the relevant topic when you need more detail.
- Cabling, power, and distance caveats
Check cable, equipment, distance and power requirements against the actual installation. Have the responsible qualified person confirm the design and applicable requirements.
- Code example index
Find a runnable program by task.
- Credential technology comparison
Compare credential technologies across issue, authentication, storage, recovery and revocation. Include the reader and access control platform in the assessment.
- Diagram index
Find diagrams of system components, responsibilities and data flows. These support the explanations in the wiki and require site specific engineering before installation use.
- Discovery and multicast
Check the scope of discovery and multicast traffic. Verify the identity and advertised services of a device before using the returned addresses.
- Event normalisation field guide
Map event identity, time, state and source information into a consistent schema. Retain the original record and document any changes made during normalisation.
- Glossary
Look up the terms used across the wiki. Follow the linked references for definitions that depend on a particular system or protocol.
- Integration readiness checklist
Review the supported interface, permissions, failure handling and recovery before accepting an integration. Record the test results and unresolved requirements.
- Media bandwidth and storage
Calculate network capacity and recording capacity separately. State bitrate, retention and overhead assumptions so the result can be reviewed.
- Ports, transports, and protection
Use this reference to look up common ports, transports and protection options. Confirm the configured service and identity on the actual endpoint.
- Protocol layer and role matrix
Look up a technology's layer and role before comparing interfaces. Use the linked pages for the relevant protocol, codec, profile or system details.
- Protocol security comparison
Compare transport protection, peer identity, permissions, replay handling and key management separately. Check the supported configuration for the specific product.
- Safety impact checklist
Identify the equipment affected by a control change and the person authorised to approve it. Review the physical consequences through the site's safety process.
- Standards and profile status
This is a dated record of standards and profile status. Confirm the current edition and lifecycle information with the original publisher before using it.
- System to protocol matrix
Find the interfaces commonly involved in each system workflow. Follow the linked references to check what information or control each one carries.
- Vendor API capability matrix
Use this matrix when discussing an integration with a vendor. Confirm product versions, licensing, access programmes and supported operations for the intended deployment.
Sources and scope 6
- Sources and scope
How to read the references, check product support and report a correction.
- Authorised and safe use
Use the wiki for reading and approved offline exercises. Live system work requires its own authorisation, procedures and safety review.
- Coverage limits
Where the reference stops and product documentation or an authorised test is needed.
- Source corrections, 29 September 2026
Scoped evidence for corrected source identities, publication status and moved documentation links.
- Source policy
Use original specifications and product documentation for technical claims. Record the edition, access date and limits of the source.
- Verification and testing
Source checks, software tests and equipment tests answer different questions.
About the project 4
- Security Technician Wiki
A practical reference for security technicians, integrators and developers working with cameras, access control, alarms and connected systems.
- MIT licence
MIT License
- Security policy
Report vulnerabilities privately and understand the boundaries of the static website, local builder and example programs.
- The physical security protocol map
Find protocols by the task they perform, then follow the detailed references for each family.