Situational awareness during an attack is crucial to minimizing the malicious effects. The use of Netflow data is a simple and often under utilized technique for gaining visibility. This talk will focus on using flow data as a tool to facilitate incident response as well as network forensics. We will explore what Netflow is, how to setup the collection of flows, how Netflow can be integrated into existing incident response workflows, and give various examples.
If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.
Copyright 2020, IronGeek