Perform analysis of raw network data captured by the NetWitness NextGen infrastructure.
NetWitness Investigator is the award-winning interactive threat analysis application of the NetWitness NextGen product suite. Investigator provides security operations staff, auditors, and fraud and forensics investigators the power to perform unprecedented free-form contextual analysis of raw network data captured and reconstructed by the NetWitness NextGen infrastructure. Developed originally for the U.S. Intelligence Community, and now used extensively by Law Enforcement, Defense, and other public and private organizations, Investigator is based upon 10 years of development and deployment in some of the most demanding and complex threat environments. With its groundbreaking user interface and unprecedented analytics, Investigator lets you see your network traffic in a new way. Unlike packet analysis products, products which display network traffic in the context of confusing network nomenclature, Investigator uses a lexicon of nouns, verbs and adjectives--characteristics of the actual application and logic layer protocols parsed during session reconstruction.
Could not parse out SMB traffic, still working on that
Summary
great tool for anyone interested in networking and monitoring networks
unique anti-leakage and forensic IT solution
andymuchi
Pros
esay to install and configure, fully visual admin.
Cons
limited vesrion
Summary
Essential for Compliance Managers, auditors and forensic Investigators
Worthless if it won't activate
ok4me2c
Pros
I wish I could find ONE!
Cons
No Reply from Customer Support
Summary
Downloaded and installed 8 days ago,and then it took about 20 tries before it complete the registration process.The message at the end of the registration said "Your registration was successfully submited,a customer support representitive will notify you when it activated and ready to use" Still waiting for that to happen.My patience is wearing a little thin,and I hate to waste anymore time on being ignoored,but because of all the possitive reviews,I will give it a couple more days,then I will re-post my final result and opinion.
Very cool. Excellent tool for curious people.
pacificwalter
Pros
Excellent program. Gives you a lot of information about your network.
Cons
Does not monitor every type of connection, and does slow the computer a bit. Check out networkminer (sourceforge), wireshark etc. They are all excellent.