NetFlow流量异常分析
原名:analyzing-network-flow-data-with-netflow
解析 NetFlow v9 和 IPFIX 记录,检测流量异常及端口扫描行为。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 1
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-06
- TRACE 评分
- 3.2 / 5
内容概览
- When investigating security incidents that require analyzing network flow data with netflow - When building detection rules or threat hunting queries for this domain - When SOC analysts need structured procedures for this analysis type - When validating security monitoring coverage for related attack techniques - Familiarity with network security concepts and tools - Access to a test or lab environment for safe execution - Python 3.8+ with required dependencies installed - Appropriate authorization for any testing activities 1. Install dependencies: pip install netflow 2. Collect NetFlow/IPFIX data from routers or use the built-in collector: python -m netflow.collector -p 9995 3. Parse captured flow data using netflow.parse packet(). 4. Analyze flows for: - Port scanning: single source to many destinations on same port - Data exfiltration: high byte-count outbound flows to unusual dest…