FlowBAT Analysis - Non-Standard Ports Discovering outbound data to applications using nonstandard ports
20
Identifying Services
21
Analyzing PCAP Files PCAPs need to exist on the FlowBAT server
22
Network Flow Automation
23
Flow Plotter
24
Conclusion
Description:
Explore network situational awareness using flow data in this comprehensive conference talk from BSides Augusta 2016. Dive into the comparison between full PCAP and flow data, learning how to build, generate, and collect flow records. Discover various flow data tools, with a focus on SILK and FlowBAT. Follow along with installation processes and practical analysis techniques for both tools. Gain insights into identifying services, analyzing PCAP files, and implementing network flow automation. Conclude with an introduction to Flow Plotter and its applications in enhancing network security monitoring.