KevinBeaver
7610 pts. | Jul 1 2009 12:13AM GMT
I’ve always recommended people not overlook a good old-fashioned network analyzer such as OmniPeek and CommView for incident response. A hex editor such as WinHex and a data recovery tool such as Davory are good things to have in your toolbox as well.
Troy Tate
0 pts. | Jul 23 2009 8:02PM GMT
It depends on the environment and requirements. A simple tool like ntop can help track usage over a period of time or Wireshark (tshark) can be used to capture ring buffer files and details can be captured over a set period of time for analysis.






