Omni 平臺實現了從單一控制臺進行全網範圍的分析與故障診斷,包括廣域網、無線網路。
OmniPeek 是一個理想的對網路進行透視的工具。網路產品研發人員可以採用OmniPeek作為研發輔助的測試、檢驗工具,也可以用來學習網路知識。此產品中已經包含了基本的故障診斷分析功能,因此可以用來與OmniPeek Workgroup協同工作,例如可以採用OmniPeek Personal在部分網路位置捕獲,將保存下來的 Trace File交由 OmniPeek Workgroup進行更深度分析。Omni平臺非常容易進行部署、管理、擴展,是企業值得擁有的網路分析與故障診斷的解決方案。
特色功能
• 基於資訊包流的專家分析系統和應用分析
• 互動式節點圖
• 完整的七層協議解碼
• 應用回應時間(ART)分析
• 安全功能
• 監控與報表
• RMON分散式分析
OmniPeek 新版特色
View File Content - Reconstructs files by extracting data from reassembled HTTP payloads. This is performed automatically when a packet file is opened, and provides critical information about file content.
Security Events from Snort and Suricata - Ability to import analytical results from Snort and Suricata, and overlay the resulting security alerts against the packet data for immediate, detailed analysis of any suspected breaches.
Investigation Overview - Provides summary level information about the entire packet file under analysis, enabling a rapid transition to any time segment.
Savvius Omnipliance Status - Notifies administrators immediately, via syslog and/or email, if a Savvius Omnipliance drive goes down or a network capture stops.
Customize Packet Decode Views - Creates unique packet decode columns based on any information within packets, making it easy to find and compare packets that contain elements under investigation.
Filter Files to Maximize Computing Bandwidth - Filters packet files before loading packets for analysis, using parameters such as IP addresses and/or port ranges, significantly increasing analysis performance on computers with limited resources.
Faster Forensic Searches - Significantly increases the speed of packet data retrieval from disk, making post-capture analysis much more efficient.
OmniPeek Enterprise 系統需求
Supported Operating Systems and Browser
Windows 10
Windows 8.1 (64-bit)
Windows 7 (32-bit/64-bit)
Windows Server 2016
Windows Server 2012
Windows Server 2012 R2
Windows Server 2008 (64-bit)
Important Notes:
All operating systems require Internet Explorer 9.0 or later and Adobe Flash Player for Internet Explorer 20.0.0.272 or later
The only wireless drivers that include 64-bit support are the Ralink and Atheros drivers.
Recommended System
Intel Core i3 or higher Processor, 4G RAM, 20GB available HD Space
Minimum System Requirements
Omnipeek supports most rack mount, desktop and portable computers as long as the basic system requirements needed to run the operating systems are met. Depending on traffic and the particular usage of Omnipeek the requirements may be substantially higher.
He...
Colasoft公司的Colasoft nChrons是分散式和追溯網路分析解決方案,為高性能和關鍵的企業網路設計。它結合了nChronos控制台和nChronos伺服器提供7 * 24小時連續資料包捕獲,存儲無限的資料,高效的資料採擷能力和深入的流量分析。它由nChronos控制台和nChronos伺服器組成;
nChronos控制台提供快速訪問所有分散式部署nChronos伺服器存儲資料包它作為企業網路的管理,這是能夠視覺化企業的整體網路活動的中心,下鑽來隔離性能問題和故障排除高優先順序和關鍵網路問題。
nChronos伺服器進行7 * 24即時資料包捕獲並不斷硬碟存儲,用於快速資料包和統計檢索。憑藉靈活的和非侵入性的部署,與標準的網路鏡像埠或鏈路挖掘技術,它提供了控制台走在時間和完整的追溯網路分析本地的資料包。
nChrons可以幫助IT專業人員
回顧性分析網絡流量的歷史
主動網絡監控和符合成本效益的網絡化管理
有效的精確截取數據和索引
提供取證分析,並降低安全風險
分佈式LAN / WAN網絡管理的遠端訪問
系統需求:
System Requirments for nChronos Server
Operating system:
Windows Server 2003 64-bit
Windows Server 2008 64-bit
Windows Server 2012 64-bit
CPU: 4-core processor (two 4-core processors recommended)
RAM: 8GB (16GB recommended)
HD space: 100GB Minimum
Capture interface: Independent network adapter
Management interface: Independent network adapter
RAID storage:
RAID level: RAID 5
RAID Controller: Stand-alone(not built-in)
RAID r/w performance: >250MB/s
System Requirments for nChronos Console
Operating system:
Windows XP (SP3 or later)
Windows Vista
Windows 7
Windows Server 2003
Windows Server 2008
Windows Server 2012
CPU: Dual-core processor (4-core processor recommended)
RAM: 4GB
Management interface: Independent network adapter
Belkasoft Evidence Center 數位證據採集分析、網路安全、電腦鑑識 最佳軟體工具
讓調查員容易去搜索、分析、儲存及共享,在硬碟或電腦的揮發性記憶體(volatile memory)所發現到的數位證據。Evidence Center 將幫助調查員快速地定位分析在社群網路的殘留、即時通訊日誌、網際網路瀏覽器紀錄、受歡迎的電子郵件信箱、點對點對等數據、多玩家遊戲的聊天紀錄、辦公室文件、圖片、影片、加密檔案、手機備份、系統及註冊檔案。
隨著智慧型手機普及和廣泛的使用,促使發展手機的數位鑑證分析,Belkasoft Evidence Center 可從Windows 作業系統、Linux、MacOS X、以及智慧型手機 iOS 、Android、Windows Phone 和黑莓機 Blackberry 提取資料數據,有效協助鑑識人員進行數位證據資料的採集分析。
Evidence Center 2017 新版特色
Mobile and Computer device examination. Supporting all major desktop and mobile operating systems, Belkasoft Evidence Center is suitable for mobile and computer forensics. It can parse real and logical drives and drive images, virtual machines, mobile device backups, UFED images, JTAG and chip-off dumps.
Smart and Comprehensive Analysis. The product looks everywhere on the device completely automatically and can successfully identify over 700 types of digital artifacts. Convenient Evidence Search feature helps to narrow down the findings using filters, pre-defined search, or other options.
Powerful Carving. Data carving allows to locate evidence that was deleted, destroyed, or never stored on the hard drive at all (page file, hibernation file, RAM contents). Besides, advanced carving mode called BelkaCarving™ is available, making it possible to reconstruct fragmented chunks into contiguous pieces of information that would otherwise not be accessible at all.
Native SQLite Parsing. Recovers corrupted and incomplete SQLite databases, restores deleted records and cleared history files. Prosesses freelists, write-ahead logs and journal files, and SQLite unallocated space.
Live RAM Analysis. Evidence Center can extract potentially crucial information from volatile memory, such as: in-private browsing and cleared browser histories, online chats and social networks, cloud service usage history, and much more. Belkasoft Live RAM Capturer is a powerful tool for creating memory dumps, and it is complimentary.
Handy Built-in Tools. PList, Registry, and SQLite viewers allow you to work more thoroughly with particular types of data and find even more evidence than automatic search was able to discover.
Low-level Investigations. Equipped with File System Explorer, Hex Viewer, and Type Converter, Belkasoft Evidence Center will allow you to perform deep examination of the contents of files and folders on the device.
Extendable with BelkaScript. Free scripting module allows user to write their own custom scripts in order to automate some of the routine and further extend the product's functionality.