ForDevelopers |
Advantage UnsniffA network analyzer is used in development to check for malformed packets, incorrect sequence of PDUs, excessive retransmissions, and a host of other problems. Unsniff rises above all the rest due to its visualization, extensibility, and automation capabilities.Some of the things you can do with Unsniff are:
System EngineersA system engineer is responsible for specifying the various components of the application and their interfaces. The interaction between components can be (1) a standard protocol - such as DNS, LDAP, RSVP or (2) a custom or proprietary protocol. The systems engineer can use Unsniff to document and even design these protocols. The features of Unsniff most useful to systems engineers are:
Software/Hardware developersDevelopers have the unenviable task of actually implementing the components that comprise the network application. They also have to implement the protocols that are used to pull the whole system together. Whether you are using third party protocol stacks or implementing your own - Unsniff will make you more productive.
TestersTesting teams ensure that the application behaves as expected under a variety of conditions. Testing & Verification is one area where Unsniff can prove to be major time and effort saver. This is possible due to the extensibility and scripting capabilities of Unsniff. You can capture data from various points in the network and execute test scripts using the Unsniff Scripting API. You can test for malformed packets, timing errors, sequence errors, incorrect request/response pairs, throughput, and much more.
For more information about how Unsniff Network Analyzer can help with your particular usage scenario, contact us at |
Why Unsniff ?
Unsniff Network Analyzer offers multi layer monitoring with deep content awareness right out of the box. The unique advantages of Unsniff are :
- Multi layer monitoring - flows, PDUs as top level objects
- Advanced NFAT (Network Forensics) abilities
- Scriptable for automation
- Fast native Windows UI w/ new visualization
- USNF format instantly opens huge capture files
- Advanced TLS decryption and analysis (incl TLS1.2 AEAD)
Scriptable : Automate your analysis
Unsniff exposes all entities as scriptable objects. They include Packets, Flows, PDUs, User Objects too. Write tiny but powerful scripts to automate the most tedious proceses. Some use cases
- Automatically extract all images greater than 200K into a directory ?
- Save each VOIP call as a separate .WAV file
- Save the first 100K of each TCP flow
- Reassemble and save in and out directions of each flow with a custom naming scheme ?
- Import from Wireshark, apply custom filters, then export back into Wireshark
- Pretty much anything you can do manually can be automated
Not just packets : PDUs , flows , and content too
Network flows are TCP streams. Each flow is treated as a top level object in Unsniff. You are presented with a list of flows in addition to packets and you can choose to work on flows as a unit instead of per packet.
Protocol Data Units (PDUs) are reassembled messages that are extracted from raw packets. Unsniff lets you see these messages instead of just packet. For example you can view and monitor SSL/TLS Records instead of fragments of packets. Unsniff supports SNMP, LDAP, TLS, and other PDUs.
User Objects are extracted content ; such as images, emails, files, video, audio. The Unsniff User Objects Sheet allows you to work with them for forensics and investigative purposes. Most use cases are covered.
User Objects : Advanced Forensics and reconstruction
Unsniff has top notch and deep network forensics analysis (NFAT) capabilities. All objects are extracted and shown in the User Objects sheet. A subset of support.
- HTTP : Full page reconstruction, images, POST messages, all CSS/JS, video, flash, and every kind of content can be extracted
- Deep Keyword Search : Search in content
- Email SMTP, POP3, IMAP, FTP files, SMB files,
- Yahoo! Chat, MSN Chat, AOL Chat
- Yahoo! / MSN Voice chat.
- Google video chat - incl support for VP8 video/SPEEX audio codec
- SIP/RTP/H.323/IAX2 - VOIP calls - incl all major codecs
- Youtube reconstruction