11

I have been using FlowMatrix. What do others do on the cheap?

Scott Pack
  • 15,167
  • 5
  • 61
  • 91
Tate Hansen
  • 13,714
  • 3
  • 40
  • 83
  • I was thinking more of tools to analyze netflow traffic, I guess saying "network flows" made the question ambiguous. – Tate Hansen Nov 14 '10 at 18:05

3 Answers3

6

WireShark is a free tool you can use to monitor network traffic. Excellent tool to see if a hidden keylogger is trying to email and /or FTP logs because it usually has the address and password in the wireshark log.

Jeremy
  • 291
  • 2
  • 4
4

I just saw a talk at Shmoocon about the YaF and SiLK tools that looked really good. YaF is a flow collector (which can collect other interesting data as well), and SiLK is an analysis package for them. There's even a nice GUI called iSiLK.

Bill Weiss
  • 777
  • 3
  • 15
3

OSSIM has an Anomalies tab that uses Ntop and can be configured with similar data.

When I did this stuff in the past, I used Ourmon.

atdre
  • 18,885
  • 6
  • 58
  • 107