Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 32 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Resourcesarrow Toolsarrow NetWitness Investigator Version 9 Released
EH-Net
May 23, 2013, 04:46:32 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: NetWitness Investigator Version 9 Released  (Read 5102 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4167


Editor-In-Chief


View Profile WWW
« on: December 08, 2009, 01:00:28 PM »



NetWitness® Investigator is the award-winning interactive threat analysis application of the NetWitness NextGen product suite. Investigator provides security operations staff, auditors, and fraud and forensics investigators the power to perform unprecedented free-form contextual analysis of raw network data.

You need to always know what is really happening on your network and have the power to drill into network and application layer session attributes on the fly. NetWitness Investigator is the only product that gives you the deep knowledge contained in full packet capture and session analysis and the capability to move mountains of data in just a few easy clicks.

Get started with an introduction to NetWitness Investigator on our YouTube channel, or click here to watch it all in HD.

Also view a FREE Advanced Training Webcast to learn about the latest features and advanced capabilities like FlexParse. Click here to watch the training Webcast.

NetWitness Investigator now supports NetWitness® Live, an online, 24x7 data service that provides immediate access to real-time threat-intelligence. Freeware users are provided access to daily threat intelligence from the SANS Internet Storm Center , the Department of Treasury and select NetWitness content helpful in identifying the latest network threats. For more information about NetWitness Live and the additional threat feed sources available visit www.netwitness.com.

Product Features:

- New! 802.11 support
- New! Right-click custom actions
- New! Windows 7 support
- Captures raw packets live from most wired or wireless interfaces
- Imports packets from any open-source, home-grown and commercial packet capture system (e.g. .pcap file import)
- License supports 25 simultaneous 1GB captures - far exceeding data manipulation capabilities of packet tools like Wireshark
- Real-time, patented layer 7 analytics
     – Effectively analyze data starting from application layer entities like users, email, address, files , and actions.
     – Infinite, free-form analysis paths
     – Content starting points
     – Patented port agnostic service identification
- Extensive network and application layer filtering (e.g. MAC, IP, User, Keywords, Etc.)
- IPv6 support
- Full content search, with Regex support
- Exports data in .pcap format
- Bookmarking & history tracking
- Integrated GeoIP for resolving IP addresses to city/county, supporting Google® Earth visualization
- SSL Decryption (with server certificate)
- Interactive time charts, and summary view
- Interactive packet view and decode
- Hash PCAP on Export
- Supports Org, Domain, and ISP databases
- Supports NetWitness Live Threat Intelligence
- Supports VLAN meta tagging
- Supports IP Tunnel(i.e. GRE) meta tagging


Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.058 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.