Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, August 23, 2009

Network Capture Tools and Utilities

Posted on 7:49 PM by Unknown

At a conference this week, we had quite a section regarding network captures.

The instructor was going on about how you can try to sort out users and what they are doing via Wireshark with the packet captures.  He was really wanting to figure out who the largest users were and what they were doing to saturate the bandwidth.

I politely asked if he was familiar with NetworkMiner Network Forensic Analysis Tool (NFAT) and Packet Sniffer.  He was not.  So I asked if I could come up and demo the one I had stowed on my USB stick.

The rest of the lesson was filled with throwing the packet capture files he had brought at NetworkMiner and carving out the results.  The instructor was amazed and grateful for the power that this tool was going to give him.  I passed the download link around to the class attendees quite liberally afterward.  It is an amazing tool.

It was quite fun and informative for all.

Later I saw (by chance) the Tools for extracting files from pcaps post at the ISC-SANS Handler’s Diary.  It was filled with quite a number of other great suggestions for carving information out of pcap files.

I’ve also downloaded NetWitness Investigator Software (free) which I understand has quite a collection of features as well.  Registration is required to get it working so that will need to wait until tomorrow.

Most of the ISC-SANS items are *nix based.  I’m mostly (with the exception of Linux forensics LiveCD’s) Windows based exclusively.  However, the packet analysis tool Xplico - Internet Traffic Decoder really seems outstanding and up my alley for needs.  Fortunately, it is included in the DEFT Linux - Computer Forensics live cd.

In addition to Wireshark, I generally keep a few other packet capture tools on my laptops, just in case.  Most are pretty tiny and light for super-fast and flexible captures.

One of those other larger tools for packet captures that I have installed is Microsoft Network Monitor 3.3.

I hadn’t realized that it has arrived fairly recently, but that link has some more feature details.

In addition, while reading the Network Monitor development blog I was pleased to find that there are some specialized plug-ins for it that might be darn useful:

  • TCP Analyzer Expert: Make Your Network Run Faster – For Microsoft Network Monitor 3.3
  • Top Users Expert for Network Monitor 3.3 – For Microsoft Network Monitor 3.3

The first is a post describing the tool which can analyze and suggest issues with your network based on packet capture data.  The second provides a report on which users are eating up all the bandwidth.

Both are pretty cool.  Check them out.

Of course, you could also try a tool like ZNetWatch 1.01 (freeware) which also specifically sniffs network traffic and rats out who the biggest users are.  While this could be caused by users looking at the latest YouTube videos or streaming radio (against network policy usage perhaps) it could also be caused by virus or malware command and control communications.

As I said, it was a lot of fun tossing Network Miner at the packet capture sample files.  If you don’t have any handy, but want to really test out these (or other) tools that can read and parse that data, here are two great starting places to get some pcap files of your own to play with.

SampleCaptures - The Wireshark Wiki

SourceForge.net: Publicly available PCAP files – networkminer

Cheers.

--Claus V.

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in networking, utilities | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Utility Gumbo
    There’s a lot in this pot.  Probably something everyone can find to enjoy. I’m serving it up tonight out of the back of the truck on the s...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • Interesting Malware in Email Attempt - URL Scanner Links
    Last weekend I spent some time with extended family helping confirm for them that their on-line email account got hacked and had been used t...
  • Windows 8 Linkage: A Bit Behind the Ball
    CC attribution: behind the eight ball by Ed Schipul on flickr . OK. Confession time. I’m more than a bit exhausted this weekend. Besides a...
  • Lego MiniFig Extravaganza
    picture clipped from Wired’s clip from Gizmodo clip… Thanks in no small part to the Windows 7 RC release, XPM mode research, and a big “l...
  • This Week in Security and Forensics: Beware the cake!
    Cube Party! image used with permission from John Walker at "rockpapershotgun.com" Yeah, the cake is a Portal thing.  Let’s d...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ►  2013 (83)
    • ►  November (8)
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ▼  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ▼  August (21)
      • Utility & Miscellany
      • Network Capture Tools and Utilities
      • Java Silent Install Notes
      • Utility Gumbo
      • Rapid-Fire Security and Response Linkpost
      • Inspiring Designs #2
      • GSD Hurricane Tracking Links – 2009
      • Search & Acquire by File Type Solutions
      • QuickPost: Bootable USB Stick
      • Devio: Remote drive access and acquisition
      • Tip: Managing Flash Cookies
      • Tip: Add Google’s Beta Search to browsers
      • Adobe Tip: Add filename to footer
      • Focus on Forensics Linkfest
      • Blog reboot – version 4.0
      • Around the (MS) Office pool
      • Drop-Dead-Quick Blue Screen of Death Diagnosis Uti...
      • Windows Linkfest Mowdown
      • Browser Linkfest Blowout
      • Mounting VHD files in Windows for fun and exploration
      • Virtual PC and XP Mode Linkage
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile