Avatar of mo_patel
mo_patel
 asked on

Network Traffic Monitoring/forensics

Hi All,

wondering what other people use for network traffic monitoring / forensics and their recommendations.  Below are some of my requirements

•      Full visibility of the traffic flow incoming/outgoing

•      Be scalable so if we wanted to have a remote sensor in a different location we wouldn’t have 2 systems, instead have all info from remote location displayed on main GUI

•      It does deep packet inspection/Intrusion detection – which is automatically updated with new signatures

•      Has a DB backend which is used to store the data/ does auto archiving/ able to import archives back in if required for historical investigations

•      Integrated with AD so it can show usernames

•      Create scheduled reports

•      Create custom reports

•      Able to monitor SQL DB – Data Modification/ Schema/ statements

•      See all MS file share traffic i.e. Create/Rename/Delete etc by IP and Username by file name and also be able to seach by filename to investigate last accessed/missing files

•      Set up alerts if something happens i.e. a folder deleted/copied

•      Email Header recording so we can see email subjects/ if we can see content even better
•      Internet Traffic recording

•      Bit-Torrent recording

•      Enables us to create trend graphs so we can see spikes in traffic
SecurityDigital ForensicsNetwork ManagementCyber Security

Avatar of undefined
Last Comment
btan

8/22/2022 - Mon
SOLUTION
Confucious2

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
ASKER CERTIFIED SOLUTION
btan

Log in or sign up to see answer
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform
Sign up - Free for 7 days
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
Not exactly the question you had in mind?
Sign up for an EE membership and get your own personalized solution. With an EE membership, you can ask unlimited troubleshooting, research, or opinion questions.
ask a question
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy