12.07.2015 Views

2013-12-05_tcpflow-and-BE-update

2013-12-05_tcpflow-and-BE-update

2013-12-05_tcpflow-and-BE-update

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>tcpflow</strong> can run batch or live-captureBatch operation is typical forensics:filename1.pcapfilename2.pcapfilename3.pcapfile.pcap.rarfile.pcap.gzfile.pcap.zipTCPflowconnection1connection1-HTTP-file.jpegconnection2connection3connection4...Live-capture is useful for testing & stunts• Run with ‘-c’ console output to see content of TCP connections as they go by.• Output to file system <strong>and</strong> read ‘report.xml’ or use alert_fd <strong>and</strong> process each file as it isclosed.4

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!