LogRhythm NetMon is a network traffic analytics tool designed for comprehensive network monitoring and threat detection. Key features include: 1. True Application Identification: Automatically identifies over 3,500 applications using advanced classification methods and deep packet inspection. 2. SmartFlow: Provides detailed packet metadata derived from each network session. 3. Full Packet Capture: Captures and stores network traffic in PCAP format for layers 2-7. 4. REST API: Allows integration with third-party tools for custom automations. 5. Deep Packet Analytics (DPA): Correlates against full packet payload and SmartFlow data using pre-built and customizable rules. 6. SmartCapture: Automatically captures sessions based on application or packet content. 7. Customizable Dashboards: Offers saved searches with automated alerts for continuous monitoring. 8. Unstructured Search: Enables drilling down to critical packet and flow data using an Elasticsearch backend. 9. Email Reconstruction: Supports malware analysis and data loss monitoring by reconstructing email attachments. 10. Deep Packet Inspection (DPI): Identifies and categorizes thousands of applications at wire speed, populating metadata fields. 11. Pattern Matching and Heuristics: Analyzes and extracts Layer 2-7 network data using various methods. 12. Automated Threat Detection: Recognizes PII, credit card information, port and protocol mismatches, and other indicators of inappropriate data movement.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Tor Browser is a free and open-source software that allows users to browse the internet anonymously and privately.
A free, open-source network protocol analyzer for capturing and displaying packet-level data.
A suite for man in the middle attacks, featuring sniffing of live connections, content filtering, and protocol dissection.
A TCP-based traceroute implementation that bypasses firewall filters to trace the path to a destination.
NBD (Network Block Device) is a network protocol implementation that allows clients to access remote block devices over a network as if they were local storage.
Snort is an open source intrusion prevention system that uses rules to detect and prevent malicious network activity.
A free DNS recursive service that blocks malicious host names and protects user privacy.
Tcpdump is a command-line packet analyzer for capturing and analyzing network traffic.
A Bluetooth 5 and 4.x sniffer using TI CC1352/CC26x2 hardware with advanced features and Python-based host-side software.