troubleshooting Question

Network Traffic Monitoring/forensics

Avatar of mo_patel
mo_patel asked on
SecurityNetwork ManagementDigital ForensicsCyber Security
2 Comments2 Solutions860 ViewsLast Modified:
Hi All,

wondering what other people use for network traffic monitoring / forensics and their recommendations.  Below are some of my requirements

•      Full visibility of the traffic flow incoming/outgoing

•      Be scalable so if we wanted to have a remote sensor in a different location we wouldn’t have 2 systems, instead have all info from remote location displayed on main GUI

•      It does deep packet inspection/Intrusion detection – which is automatically updated with new signatures

•      Has a DB backend which is used to store the data/ does auto archiving/ able to import archives back in if required for historical investigations

•      Integrated with AD so it can show usernames

•      Create scheduled reports

•      Create custom reports

•      Able to monitor SQL DB – Data Modification/ Schema/ statements

•      See all MS file share traffic i.e. Create/Rename/Delete etc by IP and Username by file name and also be able to seach by filename to investigate last accessed/missing files

•      Set up alerts if something happens i.e. a folder deleted/copied

•      Email Header recording so we can see email subjects/ if we can see content even better
•      Internet Traffic recording

•      Bit-Torrent recording

•      Enables us to create trend graphs so we can see spikes in traffic
ASKER CERTIFIED SOLUTION
btanExec Consultant
Join our community to see this answer!
Unlock 2 Answers and 2 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 2 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros