3 ms·
If you don't need immediate access to the packet payload, I've been enjoying Brim Desktop [1]. It comes pre-packaged with Zeek (formerly Bro) and gives you a UI
by kdv 6y ago
If you don't need immediate access to the packet payload, I've been enjoying Brim Desktop [1]. It comes pre-packaged with Zeek (formerly Bro) and gives you a UI to view and query those Zeek logs, which will link flows together. It also supports opening specific flows in Wireshark for deeper analysis. It might not do everything you need, but it's improved my pcap analysis workflow. It's free at the moment, and this part of the demo [2] gives you an overview of processing a pcap.
[1] https://www.brimsecurity.com https://www.brimsecurity.com
[2] https://youtu.be/InT-7WZ5Y2Y?t=382 https://youtu.be/InT-7WZ5Y2Y?t=382