The Power of NetIntercept's Network Analysis
With NetIntercept:
- Dramatically Increase Network Security -
Promote understanding of the content travelling over your corporate network.
Inappropriate network content and user misbehavior become hard to miss; setting and
enforcing policy becomes easy.
- Proactively Mitigate Liability -
Expose legal and regulatory infractions committed via the corporate network.
Armed with the facts from NetIntercept, you can readily address infractions and
prevent recurrence.
- Maintain Service Levels -
Detect network problems before they disrupt the company's day-to-day work. Routine
deep-traffic analysis with NetIntercept ensures finding potential points of failure
early.
- Accelerate Development Cycles -
Efficiently debug networked applications under development. NetIntercept's easy access to
session- and packet-level analysis quickly remedies misbehaving network applications and
protocols. CASE STUDY
- Manage Network Forensic Evidence -
The Investigator's Notebook helps you to document and store entries for a single incident or establish an on-going incident log.
NetIntercept silently captures and archives network traffic, giving you all the data needed
to analyze problems on a moment's notice.
NetIntercept lets you look back in time, keeping hours, days or
weeks of captured traffic immediately available. NetIntercept's deep
heuristic stream recognition, analysis and data mining capabilities
let you identify and study important connections efficiently, focusing
on fixing the problems, not just finding them.
Sandstorm provides powerful technology and cost-effective solutions to network problems.
US Patent 7,242,681: System and method
for intercepting and authenticating packets during one or more communication sessions and automatically
recognizing content.
New Features in NetIntercept 4.1
- Investigator's Notebook
- The ultimate in time stamped "chain of custody" evidentiary data.
- New application allows users to store entries related to the investigation of a single incident, or establish an ongoing incident log
- Entries can contain links to NI database objects
Connections, images, bookmarked items, full databases
- Click to open linked database and objects in NI GUI
- Drag & Drop NI objects and bookmarks into the Investigator's Notebook
- Each entry can be associated with one or more detailed notes
- Report feature allows text, HTML or CSV export of entire notebook or selected entries
- Support for 8-bit universal search strings
- Microsoft Word, Microsoft Powerpoint, Microsoft Excel, PDF, RTF and Plain Text parse modules have been updated to produce UTF-8 output, with conversion from character sets.
- New iCalendar file recognizer/harvester
- Icon (.ico) file recognizer
- Allows users to search for non-ASCII strings using FINDWORD, FINDPHRASE
- Full UTF-8 support, with conversion from many character sets
- Need to add something about "improved export management"
- FINDBYTES module to search for hex sequences in file objects
- Enhanced "Copy to Clipboard" support
- Allows customers to copy and paste NI windows and panes onto the clipboard and into applications on their local system
- Copy images, list views, host map, traffic map, labels and table rows
- TCP parse module handles ahead-of-sequence data
- New Automatic Operations (autoops) features - nicmd_mail and nicmd_note
- SIP and RTP connections are now established.
- RTP can now save file objects.
- New modules now save VCard files, PGP-encrypted files and other objects in the ELF format.
- New SSN modules recognizes US Social Security Numbers in text objects and generates alerts if found.
- Kerberos authentication traffic is now recognized.
- Upgraded operating system to FreeBSD 7.1-RELEASE.
Features added in prior releases of NetIntercept
|