drop network logs pcap or connection data · detect encrypted channels · non-standard ports · tunneling · covert channels · runs locally
drop logs / pcap
Drop captures or logs
pcap/pcapng · zeek conn.log · csv with timestamps + IPs + ports
status
drop pcap / zeek conn.log / csv connection exports