Configuring raw network traffic recording

With Kaspersky Anti Targeted Attack Platform, you can save raw network traffic for investigation and detection of malicious activity within the perimeter of your corporate LAN. With raw network traffic recording, you can perform retrospective analysis of network events and investigate the actions of hackers. Raw network traffic is saved as dumps in PCAP format.

To save raw network traffic, you need to enable and configure raw network traffic recording.

In this section

Enabling and configuring raw network traffic recording on a server with the Sensor and Central Node components installed

Enabling and configuring raw network traffic recording on a standalone server with the Sensor component

Page top