Kyle Topasna
1 min readFeb 5, 2020

--

Great point! I have used netflow in the past and it works just as well or better in some cases. I wrote this mostly from the lens of a SOC analyst. Moloch provides the ability to do the indexing AND full packet capture, providing more information when triaging events.

--

--

Kyle Topasna
Kyle Topasna

Written by Kyle Topasna

Cybersecurity Professional, AI Engineer, Data Scientist

No responses yet