View Issue Details

IDProjectCategoryView StatusLast Update
0000144Kali LinuxNew Tool Requestspublic2013-03-19 20:11
Reportersaberzaid Assigned Todookie  
PrioritynormalSeverityminorReproducibilityhave not tried
Status closedResolutionwon't fix 
Summary0000144: NetSleuth : Open source Network Forensics And Analysis Tools
Description

NetSleuth identifies and fingerprints network devices by silent network monitoring or by processing data from PCAP files.

NetSleuth is an opensource network forensics and analysis tool, designed for triage in incident response situations. It can identify and fingerprint network hosts and devices from pcap files captured from Ethernet or WiFi data (from tools like Kismet).

It also includes a live mode, silently identifying hosts and devices without needing to send any packets or put the network adapters into promiscuous mode ("silent portscanning").

NetSleuth is a free network monitoring, cyber security and network forensics analysis (NFAT) tool that provides the following features:

An easy realtime overview of what devices and what people are connected to any WiFi or Ethernet network.
Free. The tool can be downloaded for free, and the source code is available under the GPL.
Simple and cost effective. No requirement for hardware or reconfiguration of networks.
“Silent portscanning” and undetectable network monitoring on WiFi and wired networks.
Automatic identification of a vast array of device types, including smartphones, tablets, gaming consoles, printers, routers, desktops and more.
Offline analysis of pcap files, from tools like Kismet or tcpdump, to aid in intrusion response and network forensics.

download:

http://netgrab.co.uk/netsleuth/download-netsleuth/

Activities

dookie

dookie

2013-03-19 20:11

reporter   ~0000143

This is a Windows tool and not a very impressive one at that.
When you are making tool suggestions, try to avoid suggesting Windows tools as they take up a lot of space and makes the ISO large for little benefit.

Issue History

Date Modified Username Field Change
2013-03-19 18:43 saberzaid New Issue
2013-03-19 20:11 dookie Note Added: 0000143
2013-03-19 20:11 dookie Status new => closed
2013-03-19 20:11 dookie Assigned To => dookie
2013-03-19 20:11 dookie Resolution open => won't fix