Moloch

Moloch is an open source packet capture and search system that allows analysts and responders to examine large network packet captures. By default, Moloch organizes the packet captures into the various sessions contained within the capture. Moloch can be utilized as a network monitoring system that can be leveraged through importing packets into the Elasticsearch infrastructure. From here, responders can examine network activity in near real time. Another method that Moloch can be leveraged through is loading offline packet captures for indexing.

Installation instructions for Moloch can be found at https://molo.ch/#download. Moloch can be installed on a variety of Linux desktop or server platforms. The server option provides larger ...

Get Digital Forensics and Incident Response - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.