4 Cheap Options to Monitor Networks for Evidence

Computer forensics don't have to solely focus on recovering and searching for evidence on storage devices.

Computer forensics don't have to solely focus on recovering and searching for evidence on storage devices. Although programs like Encase and FTK 3.0 are excellent tools to help find documents, photographs and other files for your investigation, they cut short on collecting network traffic your suspect sends and receives.

Viewing stored URL visits and local cache only paint a limited picture of the suspect's Internet usage and sometimes amount to the same as reading tea leaves. A document opened online, an incriminating instant message or even a VOIP call can and should be forensically captured and reviewed for your investigations.

Below are four free or low-cost options to monitor your target's network connection, capture forensic traffic and review the data for evidence. Consult with your company's legal and IT departments before monitoring Internet connections. This may be illegal in some areas or against company policy.

Before getting started you have to decide which of the four monitoring options best work for your investigation. Each option has its own unique function that works for different scenarios that are rated below based on Level of Expertise to setup it up, Covert Application (risk of getting caught) and Network Type (wireless vs. LAN):

1. SPAN port monitoring. Level of Expertise: 1 of 5, Covert: 3 of 5, Network: LAN and WLAN.

Monitoring this way is probably the easiest to do and best option for the corporate environment. Although your target will have no clue he or she is being monitored, you need to trust your IT department because they will need to plug a computer into the SPAN port.

No additional tools are needed other than an extra Ethernet cable and your computer. And because the system is monitoring near the end point of the system, Wi-Fi traffic of your suspect can be captured as it leaves the network and returns. Your IT department will know what a SPAN port is and how to do this. It is a very common procedure for uses other than monitoring.

2. Hub router. Level of Expertise: 2 of 5, Covert: 3 of 5, Network: LAN only.

Without getting too technical, a hub router (not a switched router, which is common at most stores) is an easy and effective way to split the suspect's network so you see a mirror image of their traffic. These routers can be ordered online for $30, but your IT department probably has a few extra lying around. Simply connect the hub between the suspect's wall port or in the network room and into your computer to start monitoring. As long as you hide the hub and third Ethernet cable this can be very covert and easy to do without even tipping off IT.

3. AirpCap card. Level of Expertise: 3 of 5, Covert: 5 of 5, Network: WLAN only.

I'm placing this option on here for more of an educational purpose. In the corporate setup the SPAN port will be your best setup for monitoring Wi-Fi connections but you never know. The AirpCard is a USB-based tool that works much like a police scanner. Instead of receiving police traffic it can capture and view network traffic traveling between the target's laptop and the Wi-Fi router.

This tool is very useful in TSCM, penetration testing and other not-so-legal exploits, making hackers in love with it. Another negative is its price. It will cost you about $350.

4. ARP poisoning. Level of Expertise: 5 of 5, Covert: 3 of 5, Network: LAN and WLAN.

ARP poisoning is a handy exploit that allows you to confuse a LAN- or WLAN-networked computer connected on your network into believing you are the router and letting you capture the target's data as it passes through your computer to the real router.

This is often called a man-in-the-middle attack and is often used by hackers at coffee shops to steal your information. Although this can be fairly easy to set up without IT support, there is a chance of crashing your corporate network if done wrong. If you are willing to take the risk head over to www.oxid.it and down the powerful program "Cain and Abel."

There are plenty of short YouTube videos that can get you running in minutes.

Now that you have picked your tool to access the network information between your target and the Internet you need to capture and save the data. The best way to forensically capture the data packets of information is using the open source program Wireshark.

Wireshark is the most unsurpassed network tool on the market. After installing Wireshark you are only a few steps away from capturing data. Start by selecting capture/interfaces and depending on the type of monitoring you are doing above you should see your network card already transmitting and receiving packets. Before proceeding, press the options button and select the browse button to name the captured Internet traffic and its saved location. I recommend saving the file to an external drive because Internet traffic can add up fast. Also select "use multiple files" and "next file every 250 megabytes." This prevents errors from destroying days of captured data and helps in reviewing it later.

Once you are good to go press start and watch the data scroll across your screen. For practice you can also skip the first step of monitoring and capture your own Internet traffic to get comfortable with Wireshark and the next few tools.

While you are watching Wireshark you will see a wealth of random data and colors streaming across your screen. Although you might see a website domain you recognize scroll by, the data contains everything your target is sending/receiving, making it next to impossible to decipher any evidence on your own. That's where open source program Network Miner and Freeware Netwitness Investigator 9.0 come into play. Both tools have an import option to pull information from your 250-mb files (known as pcap files) and can recreate the information into searchable and viewable data.

Network Miner exports all files found, including a quick image viewer making it great for pornography investigations, while Investigator is your one-stop shop to recreate websites, e-mails, instant messages, VOIP calls and other types of data you captured in the pcap files. You can literally see your target entering in search fields, downloading YouTube videos and even unknown viruses communicating to bot servers in China. Unfortunately, Investigator is licensed to view only 1GB (or four 250MB files) at a time vs. their unlimited enterprise solution. So if you have lots of data, searching might have to be done in time blocks, but honestly the network traffic captured on one computer is fairly small.

As stated above, there is no reason why you can't record your own Internet activity and practice searching for data you know you were looking at moments ago. Also, Netwitness offers a free forum to share search ideas and troubleshoot any issues you might run into.

Once you get comfortable with the monitoring tools, saving the data and exploring with Network Miner and Investigator you can search or create alerts to help find that smoking gun you might not see doing basic forensics.

Brandon Gregg is a corporate investigations manager.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags Networking

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Brandon Gregg

Show Comments

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Cate Bacon

Aruba Instant On AP11D

The strength of the Aruba Instant On AP11D is that the design and feature set support the modern, flexible, and mobile way of working.

Dr Prabigya Shiwakoti

Aruba Instant On AP11D

Aruba backs the AP11D up with a two-year warranty and 24/7 phone support.

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Tom Sellers


This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang


It really doesn’t get more “gaming laptop” than this.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?