Skip to content

Network Capture

Evidence: Network Capture
Description: Collect Network Capture
Category: System
Platform: macos
Short Name: nc
Is Parsed: No
Sent to Investigation Hub: Yes
Collect File(s): No

This collector gathers structured data about network capture.

FieldDescriptionExample
TimestampTimestampExample value
IPVersionIP VersionExample value
ProtocolProtocolExample value
SourceAddressSource AddressExample value
DestinationAddressDestination AddressExample value
InterfaceIndexInterface Index123
SourcePortSource PortExample value
DestinationPortDestination PortExample value