Skip to content

Releases: githubflyideas/traffic66

traffic66 0.2.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 04:40
5e69fbd

Findings

  • traffic66 now looks through the flows every 5 minutes and lists what
    needs attention on a new Findings page: scans, port scans, password
    guessing, lateral movement inside the network, unusual uploads to new
    destinations, floods and traffic with addresses on threat lists. Each
    finding is a sentence (who did what to whom, when, for how long) with the
    numbers behind it and how the data was sampled.
  • The rules work on sampled sFlow and NetFlow. Tested with the demo's
    attack sent through a switch sampling 1:4096: every step is found, each
    as one finding; a day of normal traffic gives no findings apart from the
    internet scanner.
  • Dealt with and Not a problem close a finding; "not a problem" is
    never reported again. The overview shows the open findings first, a
    host's details page lists the findings about it, and the side menu shows
    how many high and medium findings are open.

Fixes

  • A host's details page counted only part of the internal hosts it talked
    to (the servers of internal conversations were missed).
  • Arabic and Urdu: ports read backwards ("tcp/445") and names ran into
    their addresses.

Drill-down and naming

  • Show details on any host, device or service opens a page about it:
    traffic over time by application, who it talks to, services or clients,
    countries and the latest flows. Everything on it can be clicked again to
    keep drilling down; the browser's Back button returns.
  • Name it… on any host or device names it on the spot; the name is
    saved and shown everywhere. The Names box on Sources now shows examples.

Countries and networks database

  • Upload a database on the Sources page: MaxMind GeoLite2 or DB-IP Lite
    .mmdb files (country or ASN) or an IP-to-ASN table (.tsv, .tsv.gz).
    It is checked, saved and used for new traffic at once, without a
    restart. The .mmdb reader was checked against MaxMind's own reader on
    60,000 lookups in six DB-IP databases with no difference.

Simpler pages

  • Top-N is one table: conversations (client, server, service, country) by
    default; Group by switches the grouping. Every column sorts, and
    the number columns (traffic, packets, average packet size, flows) rank
    all traffic in the range rather than re-ordering the rows shown: the
    smallest average packet size finds scanners and floods. The row of
    eleven tabs is gone.
  • "Who grew" is gone from the overview (web and terminal UI).
  • Flow paths: labels, bars and flows can all be clicked; before, only the
    thin bars could.
  • The side menu no longer shows group headings that looked like buttons;
    "Log out" no longer wraps.
  • Disk in the side menu shows used and free space; hovering over the free
    space shows how much the kept days of detail need at the current rate.
    The old "days left" figure was an unreliable extrapolation.

Capture

  • Windows local capture by name: -capture Wi-Fi, -capture Ethernet or
    the number from traffic66 interfaces, which now shows each adapter's
    Windows connection name and address.
  • Commands copied from a web page or chat work: full-width spaces, quotes,
    full-width dashes and a trailing full stop around words are ignored, and
    a mistyped command gets a "did you mean" hint.

Documentation

  • README (13 languages): drill-down, naming, the database upload, local
    capture step by step for Windows, Linux and macOS including what Wi-Fi
    can and cannot see, new screenshots.
  • This changelog; releases take their notes from it.

Downloads and installation: see the README.

traffic66 0.1.2

Choose a tag to compare

@github-actions github-actions released this 01 Oct 11:53
132f002

Using it

  • New Conversations page in the web UI and the terminal UI (key 3): who
    talks to whom, with client, server, service and traffic. The terminal UI's
    pages are now 1–9.
  • The side menu no longer shows group headings that looked like buttons but
    did nothing; groups are separated by lines.
  • Windows local capture by name: -capture Wi-Fi, -capture Ethernet or
    the number from traffic66 interfaces, instead of Npcap's
    \Device\NPF_{…} names. traffic66 interfaces now shows each adapter's
    Windows connection name and address.

Documentation

  • README section "Local capture" rewritten with step-by-step instructions
    for Windows, Linux and macOS, including what a Wi-Fi adapter can and
    cannot see (13 languages).
  • This changelog; releases now carry these notes instead of a list of pull
    requests.

Downloads and installation: see the README.

traffic66 0.1.1

Choose a tag to compare

@github-actions github-actions released this 01 Oct 08:32
d93bbaf

What's Changed

  • Users: passwd -list/-delete, README section on users and passwords (13 languages) by @githubflyideas in #7
  • ci: one-click release and branch cleanup by @githubflyideas in #8
  • Same time window for every number on a page; README screenshots (13 languages) by @githubflyideas in #9
  • Memory: bounded dedup, -memory covers the Go side, capped exporter state by @githubflyideas in #10
  • Robustness: dedup cap, clear errors, memory hard-limit docs by @githubflyideas in #11

Full Changelog: v0.1.0...v0.1.1

traffic66 0.1.0

Choose a tag to compare

@githubflyideas githubflyideas released this 01 Oct 04:49
2259887

First release of traffic66: flow analytics for sFlow, NetFlow v5/v9 and IPFIX in a single program for Windows, Linux and macOS.

  • Embedded database, nothing to install; web UI and terminal UI in 13 languages
  • Checks flow numbers against interface counters (sFlow counters or SNMP) and explains differences
  • Top 66, flow paths, countries and networks, threat lists, flow records, encapsulation
  • Linux packages are static and run on any distribution with kernel 3.2+ (CentOS 7 and Alpine included)

Downloads are attached below a few minutes after publishing. See the README for installation