In an infrastructure it is often necessary to use a probe to analyze the traffic flowing on the network. In general it is a good server with big disks and a tcpdump, Wireshark a or another. A shot ntop over there and talk about it more.
But here is a new beast. His name? NetWitness Investigator Software v8.6.4.9 . Some data? While the program:
- Capture Ethernet or Wireless
- 25 instances in simultaneous 1 GB each
- analysis possible until level 7 of the OSI model
- IPv6 Support Import / Export format pcap
- Decrypting SSL certificate
- Summaries and interactive whiteboards
- Hash PCAP files for export
- Tutorials on YouTube:)
- ... That
- free version on Windows (Linux version)
- It takes a pretty tough setup (Dual-core 2GHz, 2GHz RAM)
- IE 6.x or 7.x
Links:
Source :: Hack
NetWitness: site
NetWitness Investigator Software: download
Tutorials: YouTube
A blog about it: TaoSecurity