# bittorrent\_tracker\_internal\_external

**Explanation**

The bittorrent\_tracker\_internal\_external NDM uses threat intelligence to detect traffic to external hosts running BitTorrent tracker servers. BitTorrent clients will almost always use BitTorrent trackers to find files to download as well as advertise files available for upload. If you are not concerned with the presence of BitTorrent client software this alert can safely be ignored, and will still contribute to detection of file transfers over the BitTorrent protocol.

**What to Look For**

While IPs hosting BitTorrent trackers often also host other services we only consider traffic on ports commonly used by tracker software. Even so, there may be some false positives for detections of “Low” severity due to trackers running alongside non BitTorrent HTTP servers. At the “Medium” and “High” severity thresholds, these false positives should be very uncommon.

Please refer to the [bittorrent](/detection-models/library/operational-governance/bittorrent.md) detection for further guidance.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.fusion.vectra.ai/detection-models/library/operational-governance/bittorrent_tracker_internal_external.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
