Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

SentryWire serves as a comprehensive packet capture device and network security monitoring system designed to provide complete visibility into networks across various sectors, including enterprise, federal, and industrial control systems. It is capable of retaining packet capture data for extensive periods—ranging from weeks to years—ensuring that security teams maintain critical insights and can carry out investigations on threats well beyond the lifespan of other monitoring tools. By utilizing commodity hardware, distributed storage solutions, and a modular design, it adeptly captures, indexes, and retains full packet data at scale, accommodating everything from lightweight virtual setups to extensive enterprise clusters. In contrast to traditional packet sniffers that only record headers or metadata, SentryWire archives the entire packet stream, allowing for forensic replays, in-depth packet inspections, and thorough retrospective analyses while offering extended historical investigations. It accommodates capture rates that span from a modest 1 Mbps to an impressive over 1 Tbps, featuring capabilities such as real-time logging, advanced filtering, compression, visualization, and sophisticated BPF-syntax analysis to enhance security operations. This robust platform ultimately empowers organizations to navigate complex network environments with confidence, ensuring they remain vigilant against emerging threats.

Description

Xplico is a prominent tool featured in many leading digital forensics and penetration testing distributions, including Kali Linux, BackTrack, DEFT, Security Onion, Matriux, BackBox, CERT Forensics Tools, Pentoo, and CERT-Toolkit. It supports simultaneous access for multiple users, allowing each to manage one or several cases effectively. The interface is web-based, and its backend database options include SQLite, MySQL, or PostgreSQL. Additionally, Xplico can function as a Cloud Network Forensic Analysis Tool. Its primary objective is to extract application data from internet traffic captures, such as retrieving emails via protocols like POP, IMAP, and SMTP, along with HTTP content, VoIP calls through SIP, and file transfers using FTP and TFTP from pcap files. Importantly, Xplico is not classified as a network protocol analyzer. As an open-source Network Forensic Analysis Tool (NFAT), it organizes the reassembled data with an associated XML file that distinctly identifies the data flows and the corresponding pcap file. This structured approach enables users to efficiently analyze and manage the data extracted from network traffic.

API Access

Has API No 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

A10 Defend Threat Control Yes 
BluVector Advanced Threat Detection Yes 
Extreme Networks Yes 
Forcepoint Behavioral Analytics Yes 
Fortinet Yes 
Gigamon Yes 
HP-UX Yes 
Keysight Application Threat Intelligence Yes 
LogRhythm SIEM Yes 
Magnet AXIOM Yes 
MySQL No 
Red Hat OpenShift Yes 
SQLite No 

Integrations

A10 Defend Threat Control No 
BluVector Advanced Threat Detection No 
Extreme Networks No 
Forcepoint Behavioral Analytics No 
Fortinet No 
Gigamon No 
HP-UX No 
Keysight Application Threat Intelligence No 
LogRhythm SIEM No 
Magnet AXIOM No 
MySQL Yes 
Red Hat OpenShift No 
SQLite Yes 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) Yes 
In Person No 

Vendor Details

Company Name

SentryWire

Country

United States

Website

www.sentrywire.com

Vendor Details

Company Name

Xplico

Founded

2007

Website

www.xplico.org

Product Features

Alternatives

Alternatives

NetworkMiner Reviews

NetworkMiner

Netresec
LiveWire Reviews

LiveWire

BlueCat
WinDump Reviews

WinDump

WinPcap