USArmyResearchLab / Dshell

Dshell is a network forensic analysis framework.
Other
5.44k stars 1.14k forks source link

Filter to pass flows with non-zero amounts of data #126

Closed amm3 closed 3 years ago

amm3 commented 3 years ago

I find it useful to sometimes just view all flows that have data transmitted. This weeds out port-scanning and other empty connections that clutter netflow output, particularly when triaging.

dek443 commented 3 years ago

We tested this decoder, and all looks good. We agree it has its purpose alongside the other flow decoders. Thank you for your continued support and contributions.