NetWitness® Investigator is the
award-winning interactive threat analysis
application of the NetWitness NextGen product
suite. Investigator provides security
operations staff, auditors, and fraud and
forensics investigators the power to perform
unprecedented free-form contextual analysis
of raw network data.
You need to always know what is really
happening on your network and have the power
to drill into network and application layer
session attributes on the fly. NetWitness
Investigator is the only product that gives
you the deep knowledge contained in full
packet capture and session analysis and the
capability to move mountains of data in just
a few easy clicks.
Get started with an introduction to NetWitness Investigator on our YouTube channel.
Also view a FREE Advanced Training Webcast to learn about the latest features and advanced capabilities like FlexParse. Click here to watch the training Webcast.
NetWitness Investigator now supports NetWitness® Live, an online, 24x7 data service that provides
immediate access to real-time threat-intelligence. Freeware users are provided access to daily
threat intelligence from the SANS Internet Storm Center
, the Department of
Treasury and select NetWitness content helpful in identifying the latest network threats.
For more information about NetWitness Live and the additional threat feed sources available
visit www.netwitness.com.
Read the NetWitness Investigator EULA EULA Notice: NetWitness Investigator Freeware has an annual renewable license, as defined in the Investigator Freeware EULA.
One year from activation date, all users will be prompted through the application to login to the
registration portal and validate registration information. Simply use your community user credentials (as existing account) and follow the on-screen instructions to continue to
leverage the award-winning NetWitness Investigator that thousands of security professionals depend on every day.
Product Features:
802.11 support
Right-click custom actions
Windows 7 support
Captures raw packets live from most
wired or wireless interfaces
Imports packets from any open-source,
home-grown and commercial packet capture
system (e.g. .pcap file import)
License supports 25 simultaneous 1GB captures - far exceeding data manipulation capabilities of packet tools like Wireshark
Real-time, patented layer 7
analytics
–
Effectively analyze data starting from
application layer entities like users,
email, address, files , and actions.
–
Infinite, free-form analysis paths
–
Content starting points
–
Patented port agnostic service
identification