158 䡲 Cyber Forensics Field Manual, Second Edition
hosts, a packet sniff er could record all of the packets traveling between the hosts, potentially
providing additional information for cyber forensic investigators.
Most packet sniff ers are also protocol analyzers, which mean that they can reassemble streams
from individual packets and decode communications that use any of hundreds or thousands of
diff erent protocols.
Protocol analyzers usually can process not only live network traffi c, but also
packets that have been recorded previously in capture fi les by packet sniff ers. Protocol analyzers
are extremely valuable in displaying raw packet data in an understandable format.
Intrusion Detection Systems (IDS)
Network IDSs perform packet sniffi ng ...