Netflows as a source of forensic information
In his presentation Yann Berthier introduces Netflows as an information source for network forensics.
In his presentation Yann Berthier introduces Netflows as an information source for network forensics.
Tcpxtract is a carver for network traffic, which means it extracts files out of captured data. In order to determine start and end positions of a file it searches for certain byte sequences. This procedure was inspired by foremost, a carver for filesystem data.
This blog is a project of
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
Germany
impressum@forensikblog.de
Copyright © 2005-2010 by
Andreas Schuster
All rights reserved.