Data transmitted across a network (ex: Web, DNS, Mail, File, etc.), that is either summarized (ex: Netflow) and/or captured as raw data in an analyzable format (ex: PCAP)
Initial construction of a network connection, such as capturing socket information with a source/destination IP and port(s) (ex: Windows EID 5156, Sysmon EID 3, or Zeek conn.log)
Initial construction of a network connection, such as capturing socket information with a source/destination IP and port(s) (ex: Windows EID 5156, Sysmon EID 3, or Zeek conn.log)
Logged network traffic data showing both protocol header and body values (ex: PCAP)
Logged network traffic data showing both protocol header and body values (ex: PCAP)
Summarized network packet data, with metrics, such as protocol headers and volume (ex: Netflow or Zeek http.log)
Summarized network packet data, with metrics, such as protocol headers and volume (ex: Netflow or Zeek http.log)