Releases: githubflyideas/traffic66
Releases · githubflyideas/traffic66
Release list
traffic66 0.2.0
Findings
- traffic66 now looks through the flows every 5 minutes and lists what
needs attention on a new Findings page: scans, port scans, password
guessing, lateral movement inside the network, unusual uploads to new
destinations, floods and traffic with addresses on threat lists. Each
finding is a sentence (who did what to whom, when, for how long) with the
numbers behind it and how the data was sampled. - The rules work on sampled sFlow and NetFlow. Tested with the demo's
attack sent through a switch sampling 1:4096: every step is found, each
as one finding; a day of normal traffic gives no findings apart from the
internet scanner. - Dealt with and Not a problem close a finding; "not a problem" is
never reported again. The overview shows the open findings first, a
host's details page lists the findings about it, and the side menu shows
how many high and medium findings are open.
Fixes
- A host's details page counted only part of the internal hosts it talked
to (the servers of internal conversations were missed). - Arabic and Urdu: ports read backwards ("tcp/445") and names ran into
their addresses.
Drill-down and naming
- Show details on any host, device or service opens a page about it:
traffic over time by application, who it talks to, services or clients,
countries and the latest flows. Everything on it can be clicked again to
keep drilling down; the browser's Back button returns. - Name it… on any host or device names it on the spot; the name is
saved and shown everywhere. The Names box on Sources now shows examples.
Countries and networks database
- Upload a database on the Sources page: MaxMind GeoLite2 or DB-IP Lite
.mmdbfiles (country or ASN) or an IP-to-ASN table (.tsv,.tsv.gz).
It is checked, saved and used for new traffic at once, without a
restart. The.mmdbreader was checked against MaxMind's own reader on
60,000 lookups in six DB-IP databases with no difference.
Simpler pages
- Top-N is one table: conversations (client, server, service, country) by
default; Group by switches the grouping. Every column sorts, and
the number columns (traffic, packets, average packet size, flows) rank
all traffic in the range rather than re-ordering the rows shown: the
smallest average packet size finds scanners and floods. The row of
eleven tabs is gone. - "Who grew" is gone from the overview (web and terminal UI).
- Flow paths: labels, bars and flows can all be clicked; before, only the
thin bars could. - The side menu no longer shows group headings that looked like buttons;
"Log out" no longer wraps. - Disk in the side menu shows used and free space; hovering over the free
space shows how much the kept days of detail need at the current rate.
The old "days left" figure was an unreliable extrapolation.
Capture
- Windows local capture by name:
-capture Wi-Fi,-capture Ethernetor
the number fromtraffic66 interfaces, which now shows each adapter's
Windows connection name and address. - Commands copied from a web page or chat work: full-width spaces, quotes,
full-width dashes and a trailing full stop around words are ignored, and
a mistyped command gets a "did you mean" hint.
Documentation
- README (13 languages): drill-down, naming, the database upload, local
capture step by step for Windows, Linux and macOS including what Wi-Fi
can and cannot see, new screenshots. - This changelog; releases take their notes from it.
Downloads and installation: see the README.
traffic66 0.1.2
Using it
- New Conversations page in the web UI and the terminal UI (key 3): who
talks to whom, with client, server, service and traffic. The terminal UI's
pages are now 1–9. - The side menu no longer shows group headings that looked like buttons but
did nothing; groups are separated by lines. - Windows local capture by name:
-capture Wi-Fi,-capture Ethernetor
the number fromtraffic66 interfaces, instead of Npcap's
\Device\NPF_{…}names.traffic66 interfacesnow shows each adapter's
Windows connection name and address.
Documentation
- README section "Local capture" rewritten with step-by-step instructions
for Windows, Linux and macOS, including what a Wi-Fi adapter can and
cannot see (13 languages). - This changelog; releases now carry these notes instead of a list of pull
requests.
Downloads and installation: see the README.
traffic66 0.1.1
What's Changed
- Users: passwd -list/-delete, README section on users and passwords (13 languages) by @githubflyideas in #7
- ci: one-click release and branch cleanup by @githubflyideas in #8
- Same time window for every number on a page; README screenshots (13 languages) by @githubflyideas in #9
- Memory: bounded dedup, -memory covers the Go side, capped exporter state by @githubflyideas in #10
- Robustness: dedup cap, clear errors, memory hard-limit docs by @githubflyideas in #11
Full Changelog: v0.1.0...v0.1.1
traffic66 0.1.0
First release of traffic66: flow analytics for sFlow, NetFlow v5/v9 and IPFIX in a single program for Windows, Linux and macOS.
- Embedded database, nothing to install; web UI and terminal UI in 13 languages
- Checks flow numbers against interface counters (sFlow counters or SNMP) and explains differences
- Top 66, flow paths, countries and networks, threat lists, flow records, encapsulation
- Linux packages are static and run on any distribution with kernel 3.2+ (CentOS 7 and Alpine included)
Downloads are attached below a few minutes after publishing. See the README for installation