Capture, analyze, filter, and respond, real-world network forensics
Detect and analyze a TCP SYN flood attack with spoofed source IPs causing half-open connection exhaustion.
Identify periodic HTTPS C2 beaconing using JA3 fingerprints, timing analysis, and traffic anomalies.
Detect covert data exfiltration through encoded DNS subdomain queries and anomalous TXT record lookups.
Detect ARP cache poisoning enabling a man-in-the-middle attack through gratuitous ARP and MAC address anomalies.
Identify HTTP request smuggling via Content-Length/Transfer-Encoding conflicts that cause front-end and back-end servers to disagree on request boundaries.
Detect TLS downgrade attacks (POODLE/BEAST indicators) where an attacker manipulates cipher negotiation to force weaker encryption protocols.
Detect data exfiltration via ICMP echo request/reply payloads, including oversized packets and encoded data hidden in ping traffic.
Detect SMB relay attacks where NTLM authentication is captured from one host and relayed to gain unauthorized access on a different target server.
Identify 802.11 deauthentication frame floods used to disconnect wireless clients from access points, often as a precursor to evil twin or WPA handshake capture attacks.
Detect port knocking sequences where an attacker sends carefully timed connection attempts to specific ports in order to trigger hidden firewall rules that open access to restricted services.
Detect VoIP eavesdropping through RTP stream capture and SIP signaling interception, where an attacker sniffs unencrypted voice calls on the network.
Detect BGP route hijacking through anomalous route advertisements, AS path manipulation, and prefix hijack indicators in BGP update messages.