Network Situational Awareness with Flow Data
via YouTube
Pass the PMP® Exam on Your First Try — Expert-Led Training
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
Syllabus
Intro
Jason Smith
Applied Network Security Monitoring
Not on the Agenda
Full PCAP vs. Flow Data
Building Flow Records
Generating Flow Data
Collecting Flow Data
Flow Data Tool Comparisons
SILK and FlowBAT
SILK Collection Architecture
Getting Started with Flows
SILK - Install
SILK Analysis - PCAP Conversion
SILK Analysis - Output Examples
FlowBAT - Install
FlowBAT Analysis - Filtering
FlowBAT Analysis - Stats
FlowBAT Analysis - Non-Standard Ports Discovering outbound data to applications using nonstandard ports
Identifying Services
Analyzing PCAP Files PCAPs need to exist on the FlowBAT server
Network Flow Automation
Flow Plotter
Conclusion