Skip to content
Go back in time

Sniffer Recording & Forensic History

The sniffer never stops recording — so the evidence is still there three weeks later.

Most monitoring only knows about now. When the question is about last Tuesday at 14:20, it has nothing — the moment passed and the evidence went with it. The Net-Monitor sniffer records continuously and keeps what it records, so you can go back to any point in time and see exactly what was on the wire. Continuous 24/7 recording and long-term retention come with NM-Security Cyber; NM-Network Monitoring includes the same sniffer for shorter, on-demand capture sessions while you are chasing a problem.

What this means for you

  • Answer "what happened last Tuesday?" with evidence
  • Investigate an incident nobody was watching live
  • Support audit, compliance and insurance questions
  • Settle a supplier dispute with a record, not an opinion
Inside the capability

What it actually does.

Sniffer recording, 24/7

With NM-Security Cyber the sniffer records around the clock rather than on demand, so there is no window in which something happens unrecorded because nobody had started a capture yet.

Data saved for future research

Sniffer data is retained rather than discarded after analysis, so the evidence outlives the incident that produced it.

Search back through history

Query stored history by host, interface, protocol or conversation to find exactly when a behaviour started — and what it looked like before it did.

Reconstruct the moment

Return to a specific minute and examine the traffic as it actually was, instead of reasoning backwards from a graph and a memory.

Evidence for audit and dispute

A factual record of what the network was doing, for auditors, insurers, regulators, or a supplier who says the problem was not theirs.

Feeds your existing stack

Interfaces to external systems over a standard open API, so stored evidence is available to the SIEM or case-management tools you already run.

In the console

How it looks day to day.

The same correlated data behind every view, so you are never comparing two tools that disagree.

net-monitor · consoleLIVE

Discovered devices

DEVICETYPEPORTSLOAD
core-1Router48/4862%
core-2Router48/4855%
dist-3Switch96/9671%
acc-3Switch46/4894%
acc-4Switch48/4838%

Physical map

Illustrative views representing Net-Monitor output.

See it against your own network.

Book a short session with one of our engineers. We will run Net-Monitor against your own network and show you exactly what it finds — no slideware, no obligation.