« Home | EnCase memory acquisition not forensically sound » | Behind every avatar is a real person » | Ignorance is bliss » | New release of the OWASP Testing Guide » | Nigerian Defense » | InfoSec lesson by Dilbert » | Dear Santa, how did you develop your love of compu... » | Throwing out the governement with the hard disk? » | Network forensics beyond Wireshark » | Europe goes anti-cybercrime »

Network forensics with NetworkMiner

Via the Irongeek website I found NetworkMiner today. In a way, it does not seem as advanced as Xplico and ClearSight Analyzer, but it may be sufficient for what you use it and thus a very good idea to have it in your toolkit anyway. Whereas Xplico is a freeware *nix application and ClearSight Analyzer is a commercial Windows program, NetworkMiner is a freeware Windows application. In my opinion it is usually a good idea to have a mix of commercial and freeware software, and both *nix and Windows platforms to use them on.

Update: Coincidentally while I was writing this article, an anonymous reader pointed me to a post on the When Puffy Meets RedDevil blog about the very same subject. Thanks for the heads up!

Update 2: Russ McRee from HolisticInfoSec.org was kind enough to drop me an email with some more information on NetworkMiner, including a link to an article he wrote about the application. It is a really nice rundown of NetworkMiner, and set me to think that I should play around some more with it. I'm beginning to get the impression that I seriously underestimated its possibilities, which I failed to see behind the minimalistic looking GUI.

Labels:

Post a Comment

About me

  • I'm An Hilven
  • My CV
  • me

Interesting News

My Library


    Shelfari

Disclaimer