NetIntercept User Manual


E Keyboard Equivalents

E.1 Section 508 Compliance

NetIntercept provides alternative keyboard navigation in compliance with section 508 of the Rehabilitation Act of 1973 (also known as Section 508), which is currently in force in the United States.

"Section 508 requires that when Federal agencies develop, procure, maintain, or use electronic and information technology, Federal employees with disabilities have access to and use of information and data that is comparable to the access and use by Federal employees who are not individuals with disabilities, unless an undue burden would be imposed on the agency." (from Subpart A § 1194.1).
"When software is designed to run on a system that has a keyboard, product functions shall be executable from a keyboard where the function itself or the result of performing a function can be discerned textually." (from Subpart B § 1194.21)

E.2 Keyboard Navigation in NI

Note: When an arrow key is used, it is abbreviated by its direction (e.g., [Left]).

E.2.1 Manipulating Keyboard Focus

In general, the [Tab] key is used throughout the interface to move the focus from field to field, and [Space] is used to simulate a left-button click. In the Image sub-tab of the Views tab, the focus is shown as a small square dot to the left of the item that has the focus. In the Host Map sub-tab of the Views tab, the focus is shown as a pointer above and to the left of the selected host node.

E.2.2 Selecting Traffic

In the Traffic tab, you can use the keyboard to make a selection on the network traffic chart by pressing [Space] or [Enter] when the chart has the focus. The selection can be expanded to the right by using [Right] and to the left by using [Left]. Similarly, the selection can be contracted on the left by using [Shift+Right] and on the right by using [Shift+Left].

E.2.3 Navigating Tabs and Lists

Within a set of tabs, [Right] and [Left] are used to navigate from tab to tab.

In lists, [Up] and [Down] are used to scroll vertically, and [Shift+Left] and [Shift+Right] are used to scroll horizontally. [Space] is used to select a list item. [Shift+Space] will perform range selects, and [Ctrl+Space] will perform non-contiguous selects.

In hierarchical lists, [Up] and [Down] are used to scroll through the list. When the focus is on a list item that can be expanded, [Right] expands the list, and [Left] collapses it.

E.2.4 Closing Dialogs and Windows

Press [Esc] to dismiss any dialog (such as those that appear via the Open or Delete commands). Press [Ctrl+q] to close any View windows (such as the Connection View or the Web View).

E.3 Equivalents for NI Menus and Toolbar Buttons

E.3.1 Menu Access

Keys
Menu/Button
Description
[Ctrl+n] File | New Create new database, immortalize data, or show packets in selection
[Ctrl+o] File | Open Open database or raw packet dataset
[Ctrl+Shift+r] File | Rename Rename a database or raw packet dataset
[Ctrl+z] File | Analyze Parse raw or sessionized packet dataset
[Ctrl+d] File | Delete Delete database, transferred files, reports, sessionized dump files, or raw dump files
[Ctrl+p] File | Print Print summary information
[Ctrl+i] File | Import Import dump files
[Ctrl+e] File | Export Export dump files, databases, file objects and other files chosen by the user
[Ctrl+Shift+#] File | Find # Find Connection by Number
[Ctrl+k] File | Mask Create, modify, delete, and set netmasks
[Ctrl+y] File | Time Limit data shown by time range
[Ctrl+b] File | Bookmarks Show Bookmark window
[Ctrl+q] File | Exit Quit NI
[Ctrl+1] Forensics | MAC Group Display MAC forensics criteria
[Ctrl+2] Forensics | IP Group Display IP forensics criteria
[Ctrl+3] Forensics | TCP/UDP Group Display Ports forensics criteria
[Ctrl+4] Forensics | Email Group Display Email forensics criteria
[Ctrl+5] Forensics | File Name Display Filename forensics criteria
[Ctrl+6] Forensics | Xfer Method Display File Transfer Method criteria
[Ctrl+7] Forensics | User Name Display Username forensics criteria
[Ctrl+8] Forensics | Content Type Display Content Type forensics criteria
[Ctrl+0] Forensics | All Views Display all criteria columns
none View | Button Text Toggle text display on NI toolbar and Forensics column buttons
none View | Summary Charts Toggle display of charts for data on the Summary | Top 40 | Hosts sub-tabs
[Ctrl+Shift+a] Options | Font Change the fonts used throughout NI
none Window | Cascade Arrange all NI windows in a stack starting at the top left corner of the desktop
none Window | Close All Close all NI windows
none Window | <windowname> Bring the named window to the foreground
[F1] Help | Help Show help files
[Shift+F1] Help | What's This Shows a descriptive tooltip about the selected interface item
[Ctrl+a] Help | About Show program version information
[Ctrl+m] Help | Manifest Show manifest of program files
[Ctrl+h] Help | Hardware Info Show NI hardware information

E.3.2 NI Toolbar

Keys
Menu/Button
Description
[Ctrl+o] Open button Open database or raw packet dataset
[Ctrl+Shift+r] Rename button Rename a database or raw packet dataset
[Ctrl+z] Analyze button Parse raw or sessionized packet dataset
[Ctrl+d] Delete button Delete database, transferred files, reports, sessionized dump files, or raw dump files
[Ctrl+p] Print button Print summary information
[Ctrl+i] Import button Import dump files
[Ctrl+e] Export button Export dump files, databases, file objects and other files chosen by the user
[Ctrl+Shift+#] Find # button Find Connection by Number
[Ctrl+k] Mask button Create, modify, delete, and set netmasks
[Ctrl+y] Time button Limit data shown by time range
[Ctrl+s] Save button Save configuration changes
[Ctrl+t] Revert button Revert to previously-saved configuration
[Ctrl+b] Bookmark button Show Bookmark window
none Schedule button Run the Scheduler interface to schedule automatic operations scripts
[Shift+F1] What's This button Shows a descriptive tooltip about the selected interface item

E.3.3 Traffic Toolbar

Keys
Menu/Button
Description
none Time button Change the time scale displayed on the traffic chart
none Zoom button (linear scale only) Enlarge the traffic shown in the traffic chart
none Configure button Set configuration options for the traffic chart
[Ctrl+n] New button Create new database, immortalize data, or view packets in selection
none Filter button Set a filter to reduce the amount of traffic saved to disk (see Section 4.1.3 for more information)

E.3.4 Forensics Toolbar

Keys
Menu/Button
Description
none Save button Save a query constructed by selecting items from the Forensics columns
none Load button Load a saved forensics query
none Delete button Delete a saved forensics query
[Ctrl+c] Clear All button Clear all selections from columns
none Balance Columns button Balance all visible columns
none Criteria button See Forensics menu items in Section E.3.1.
[Ctrl+f] Find Connections button Show a Connection List window for the connection(s) returned from the forensics criteria chosen

E.3.5 Session List and Connection View Window

Keys
Menu/Button
Description
[Space] File | View Highlighted Connection Show a Connection window for the connection selected
[Ctrl+d] File | Toggle DNS Names / IP Addresses Toggle display of hostnames and IP addresses in the SRC/DST IP columns
[Ctrl+f] File | Find in SRC/DST IP Columns Open a search dialog to find IP addresses or host names in this window
[Ctrl+i] File | Display Highlighted Connection Info Display a dialog containing information on the highlighted connection
[Ctrl+c] File | Save to CSV File Save list to CSV file
[Ctrl+t] File | Transfer Dump Files Save all connections shown to archive media or another machine
[Ctrl+j] File | Transfer File Objects Save file objects for all connections in the list to archive media or another machine
[Ctrl+q] File | Close Close Connection List window.
[Ctrl+1] View | CONNECTION NUMBER Show CONNECTION NUMBER column
[Ctrl+2] View | SRC {IP, HOST} Show SRC IP column (or SRC HOST column if DNS name display is selected)
[Ctrl+Shift+2] View | DST {IP, HOST} Show DST IP column (or DST HOST column if DNS name display is selected)
[Ctrl+3] View | SRC BYTES Show SRC BYTES column
[Ctrl+Shift+3] View | DST BYTES Show DST BYTES column
[Ctrl+4] View | IP PROTOCOL Show IP PROT column
[Ctrl+5] View | SRC PORT Show SRC PORT column
[Ctrl+Shift+5] View | DST PORT Show DST PORT column
[Ctrl+6] View | START Show START column
[Ctrl+Shift+6] View | STOP Show STOP column
[Ctrl+7] View | SRC PKTS Show SRC PKTS column
[Ctrl+Shift+7] View | DST PKTS Show DST PKTS column
[Ctrl+8] View | SRC MAC Show SRC MAC column
[Ctrl+Shift+8] View | DST MAC Show DST MAC column
[Ctrl+9] View | Connection View Pane Toggles the display of an all-in-one Session List + Connection View pane or a Session List and separate Connection View window.
[F1] Help | Help Show help files
[Shift+F1] Help | What's This Shows a descriptive tooltip about the selected interface item

Connection Detail and Connection Window

Note: The File menu is called the Connection menu when connection detail data is displayed within the Session List window.

Keys
Menu/Button
Description
[Ctrl+Shift+f] File | Search Traffic Search contents of Traffic Session tab
[Ctrl+s] File | Save Traffic Session Save the Traffic Session tab contents to disk
[Ctrl+Shift+s] File | Save Traffic Session to [Media] Save the Traffic Session tab contents to archive media
[Ctrl+Shift+d] File | Save Dump File Save the sessionized tcpdump-format file for this connection to disk
[Ctrl+w] File | Save Captured File Save the selected file object to disk
[Ctrl+Shift+w] File | Save Captured File To [Media] Save the selected file object to archive media
[Ctrl+x] File | Export One Captured File Export the selected file object to another machine
[Ctrl+Shift+j] File | Transfer All Captured Files Save file objects for this connection to archive media or another machine
[Ctrl+p] File | Print Print connection information
[Ctrl+b] File | Bookmark, Bookmark icon Bookmark this connection
[Ctrl+v] File | Packet View, Packets icon Show packet information for this connection.
[Ctrl+q] File | Close (Only in Connection window) Close the Connection window.
[Ctrl+m] Traffic Format | HTML Stream Fixed Format the traffic as HTML, Stream fixed
[Ctrl+y] Traffic Format | HTML Packet Bytes Printable Format the traffic as HTML, Packet Bytes Printable
[Ctrl+n] Traffic Format | HTML Packet Bytes Non-Printable Format the traffic as HTML, Packet Bytes Non- printable
[Ctrl+h] Traffic Format | HTML Packet Headers And Bytes Format the traffic as HTML, Packet Headers and Bytes
[Ctrl+Shift+m] Traffic Format | Text Stream Fixed Format the traffic as Text, Stream fixed
[Ctrl+Shift+y] Traffic Format | Text Packet Bytes Printable Format the traffic as Text, Packet Bytes Printable
[Ctrl+Shift+n] Traffic Format | Text Packet Bytes Non-Printable Format the traffic as Text, Packet Bytes Non- printable
[Ctrl+Shift+h] Traffic Format | Text Packet Headers And Bytes Format the traffic as Text, Packet Headers and Bytes
[Ctrl+Shift+r] Traffic Format | Font Set font for Traffic Session text
[Ctrl+Shift+c] Traffic Format | Colors | Client Set color for client side of traffic session
[Ctrl+Shift+v] Traffic Format | Colors | Server Set color for server side of traffic session
[F1] Help | Help (Only in Connection window) Show help files
[Shift+F1] Help | What's This (Only in Connection window) Shows a descriptive tooltip about the selected interface item

E.3.6 Packet View and Toolbar

Keys
Menu/Button
Description
[Ctrl+o] File | Open Dump File, Open icon Load a dump file
[Ctrl+s] File | Save Packet Queue to File, Save icon Save a dump file
[Ctrl+p] File | Print, Print icon Print packet information
[Ctrl+q] File | Close Close the Packet View window
[;] Edit | Insert Comment Allow the user to insert a comment
[e] View | List, List icon Show a list of packets in the file
[Shift+e] View | Summary View, Summary icon Show a list of packets in the file, plus a summary of the current packet header
[Ctrl+e] View | Detail View, Detail icon Show a summary of the current packet header, and the current packet
[Ctrl+a] View | All Panes, View All icon Show a list of the packets in the file, a summary of the current packet header, and the current packet
[Enter] View | Switch Pane View Cycle among List, Summary, Detail, and All Panes views
[g] Navigate | Go To Line Move to the packet number specified
[Shift+g] Navigate | Go To Selected Scroll the packet view to show the selected packet
[Ctrl+Home] Navigate | Beginning of File Move to the beginning of the dump file
[Ctrl+End] Navigate | End of File Move to the end of the dump file
[Ctrl+Left] Navigate | Previous Marker Move to the previous marker
[Ctrl+Right] Navigate | Next Marker Move to the next marker
[Ctrl+Up] Navigate | First Marker Move to the first marker
[Ctrl+Down] Navigate | Last Marker Move to the last marker
[m] Navigate | Toggle Marker Turn the marker off or on for the selected packet
[Shift+m] Navigate | Mark This Connection Mark all packets belonging to the same connection as the current packet
[Ctrl+m] Navigate | Clear Markers Clear all markers
[Ctrl+n] Filter | New Filter, New icon Create a new filter
[Ctrl+k] Filter | New Filter from Packet, New From Packet icon Create a filter from the current packet
[Ctrl+l] Filter | List Filters, List icon Show a list of existing filters
none Filter | Modify Filter, Modify icon Modify an existing filter
none Filter | Delete Filter, Delete icon Delete an existing filter
none Filter | Copy Filter, Copy icon Make a copy of an existing filter
[n] Filter | Next Match, Next icon Move to the next packet matching the active Forward filter
[p] Filter | Previous Match, Previous icon Move to the previous packet matching the active Reverse filter
none Options | Display Set options for the Packet View display
none Options | Font Set the font used in the Packet View window
[+] Options | Increase Font Size Increase the font size in the window
[-] Options | Decrease Font Size Decrease the font size in the window
none Options | Toolbar Show or hide the Packet View toolbar
none Options | Status Bar Show or hide the status bar on the Packet View window

E.3.7 Web View and Toolbar

Keys
Menu/Button
Description
[Ctrl+p] File | Print, Print icon Print web view information
[Ctrl+]] File | Increase Font Size, Zoom In icon Increase the size of the text on the Web Page tab
[Ctrl+[] File | Decrease Font Size, Zoom Out icon Decrease the size of the text on the Web Page ta
[Ctrl+f] File | Find Text, Find icon Find text in web pages or source HTML
[Ctrl+Shift+f] File | Find Text Again, Find Again icon Repeat the previous find operation
[Ctrl+b] File | Bookmark, Bookmark icon Bookmark this web view
[Ctrl+q] File | Close Close the Web View window.
[Ctrl+Left] Scroll | Left Scroll left on web pages or source HTML
[Ctrl+Right] Scroll | Right Scroll right on web pages or source HTML
[Ctrl+Up] Scroll | Up Scroll up on web pages or source HTML
[Ctrl+Down] Scroll | Down Scroll down on web pages or source HTML
[Ctrl+Home] Scroll | Diagonal Up / Left Scroll up and to the left on web pages or source HTML
[Ctrl+Page Up] Scroll | Diagonal Up / Right Scroll up and to the right on web pages or source HTML
[Ctrl+End] Scroll | Diagonal Down / Left Scroll down and to the left on web pages or source HTML
[Ctrl+Page Down] Scroll | Diagonal Down / Right Scroll down and to the right on web pages or source HTML
[F1] Help | Help Show help files
[Shift+F1] Help | What's This, What's This icon Shows a descriptive tooltip about the selected interface item

E.3.8 Image View and Toolbar

Keys
Menu/Button
Description
[Ctrl+p] File | Print, Print icon Print image view information
[Ctrl+w] File | Write to [Media], Disc icon Save the image file to archive media
[Ctrl+s] File | Save as Image Save the image file to the chosen file type
[Ctrl+b] File | Bookmark, Bookmark icon Bookmark this image
[Ctrl+q] File | Close Close the Image View window
[Ctrl+1] Image | Enlarge | 25% Expand the image by 25%
[Ctrl+2] Image | Enlarge | 50% Expand the image by 50%
[Ctrl+3] Image | Enlarge | 100% Expand the image by 100%
[Ctrl+4] Image | Enlarge | 250% Expand the image by 250%
[Ctrl+5] Image | Enlarge | 500% Expand the image by 500%
[Ctrl+Shift+1] Image | Reduce | 25% Reduce the image by 25%
[Ctrl+Shift+2] Image | Reduce | 50% Reduce the image by 50%
[Ctrl+Shift+3] Image | Reduce | 75% Reduce the image by 75%
[Ctrl+o] Image | Original Size Return the image to its original size
Scroll menu items See options on Web View menus in Section E.3.7
[F1] Help | Help Show help files
[Shift+F1] Help | What's This, What's This icon Shows a descriptive tooltip about the selected interface item

E.3.9 Email View and Toolbar

Keys
Menu/Button
Description
[Ctrl+p] File | Print, Print icon Print image view information
[Ctrl+b] File | Bookmark, Bookmark icon Bookmark this image
[Ctrl+q] File | Close Close the Image View window
[F1] Help | Help Show help files
[Shift+F1] Help | What's This, What's This icon Shows a descriptive tooltip about the selected interface item

E.3.10 Report View and Toolbar

Keys
Menu/Button
Description
[Ctrl+f] File | Find Text, Find icon Find text in report
[Ctrl+Shift+f] File | Find Text Again, Find Again icon Repeat the previous find operation
[Ctrl+p] File | Print, Print icon Print report.
[Ctrl+w] File | Write to [Media], Disc icon Save report to archive media.
[Ctrl+o] File | Open Open another file in this Report window.
[Ctrl+q] File | Close Close the Report window.
[F1] Help | Help Show help files
[Shift+F1] Help | What's This, What's This icon Shows a descriptive tooltip about the selected interface item

E.3.11 Bookmark List Window

Keys
Menu/Button
Description
[Ctrl+l] File | Delete All Delete all the bookmarks shown.
[Ctrl+r] File | Reload Table Refresh the bookmark data shown.
none File | Transfer... Transfer file objects associated with the highlighted bookmark.
[Ctrl+q] File | Close Close the Bookmark List window.
[Ctrl+g] Bookmark | Goto Go back to the original item you bookmarked.
[Ctrl+e] Bookmark | Edit Note Edit the note associated with the bookmark.
[Ctrl+d] Bookmark | Delete Delete the highlighted bookmark.
[F1] Help | Help Show help files
[Shift+F1] Help | What's This Shows a descriptive tooltip about the selected interface item

E.3.12 Help View and Toolbar

Keys
Menu/Button
Description
[Ctrl+b] File | Back, Back icon Go to previous help page.
[Ctrl+h] File | Home, Home icon Go to help table of contents.
[Ctrl+o] File | Open Open another file in this Help window
[Ctrl+f] File | Find Text, Find icon Find text in help pages
[Ctrl+Shift+f] File | Find Text Again, Find Again icon Repeat the previous find operation
[Ctrl+q] Close Close the Help window

©1998 - 2008 Sandstorm Enterprises, Inc. The Sandstorm logo, LANWatch®, NetIntercept®, TCP.demux™, Tools with sharp edges®, Rapid Event Analysis™, and Sandstorm Enterprises® are all trademarks or registered trademarks of Sandstorm Enterprises, Inc. Contact us by phone (+1 781-333-3200), fax (+1 270 964 0394), or email (support@sandstorm.net).