LogRythm NetMon Logo

LogRythm NetMon

0
Commercial
Visit Website

LogRhythm NetMon is a network traffic analytics tool designed for comprehensive network monitoring and threat detection. Key features include: 1. True Application Identification: Automatically identifies over 3,500 applications using advanced classification methods and deep packet inspection. 2. SmartFlow: Provides detailed packet metadata derived from each network session. 3. Full Packet Capture: Captures and stores network traffic in PCAP format for layers 2-7. 4. REST API: Allows integration with third-party tools for custom automations. 5. Deep Packet Analytics (DPA): Correlates against full packet payload and SmartFlow data using pre-built and customizable rules. 6. SmartCapture: Automatically captures sessions based on application or packet content. 7. Customizable Dashboards: Offers saved searches with automated alerts for continuous monitoring. 8. Unstructured Search: Enables drilling down to critical packet and flow data using an Elasticsearch backend. 9. Email Reconstruction: Supports malware analysis and data loss monitoring by reconstructing email attachments. 10. Deep Packet Inspection (DPI): Identifies and categorizes thousands of applications at wire speed, populating metadata fields. 11. Pattern Matching and Heuristics: Analyzes and extracts Layer 2-7 network data using various methods. 12. Automated Threat Detection: Recognizes PII, credit card information, port and protocol mismatches, and other indicators of inappropriate data movement.

FEATURES

ALTERNATIVES

Pure Python implementation of Microsoft RDP protocol with various tools and support for different security layers.

A tool to escalate SSRF vulnerabilities on modern cloud environments

A tool to discover new target domains using Content Security Policy

A set of interrelated detection rules for improving detection and hunting visibility and context

An analyzer for parsing GQUIC traffic in Zeek, supporting versions Q039 to Q046, with a fingerprinting method named 'CYU' for detecting anomalous GQUIC traffic.

A powerful interactive packet manipulation program and library for network exploration and security testing.

A network responder supporting various protocols with minimal assumptions on client intentions.

WireGuard is a fast, simple, and secure VPN that uses cutting-edge cryptography, designed for ease of use and performance.

PINNED