traffic66 0.2.0
Findings
- traffic66 now looks through the flows every 5 minutes and lists what
needs attention on a new Findings page: scans, port scans, password
guessing, lateral movement inside the network, unusual uploads to new
destinations, floods and traffic with addresses on threat lists. Each
finding is a sentence (who did what to whom, when, for how long) with the
numbers behind it and how the data was sampled. - The rules work on sampled sFlow and NetFlow. Tested with the demo's
attack sent through a switch sampling 1:4096: every step is found, each
as one finding; a day of normal traffic gives no findings apart from the
internet scanner. - Dealt with and Not a problem close a finding; "not a problem" is
never reported again. The overview shows the open findings first, a
host's details page lists the findings about it, and the side menu shows
how many high and medium findings are open.
Fixes
- A host's details page counted only part of the internal hosts it talked
to (the servers of internal conversations were missed). - Arabic and Urdu: ports read backwards ("tcp/445") and names ran into
their addresses.
Drill-down and naming
- Show details on any host, device or service opens a page about it:
traffic over time by application, who it talks to, services or clients,
countries and the latest flows. Everything on it can be clicked again to
keep drilling down; the browser's Back button returns. - Name it… on any host or device names it on the spot; the name is
saved and shown everywhere. The Names box on Sources now shows examples.
Countries and networks database
- Upload a database on the Sources page: MaxMind GeoLite2 or DB-IP Lite
.mmdbfiles (country or ASN) or an IP-to-ASN table (.tsv,.tsv.gz).
It is checked, saved and used for new traffic at once, without a
restart. The.mmdbreader was checked against MaxMind's own reader on
60,000 lookups in six DB-IP databases with no difference.
Simpler pages
- Top-N is one table: conversations (client, server, service, country) by
default; Group by switches the grouping. Every column sorts, and
the number columns (traffic, packets, average packet size, flows) rank
all traffic in the range rather than re-ordering the rows shown: the
smallest average packet size finds scanners and floods. The row of
eleven tabs is gone. - "Who grew" is gone from the overview (web and terminal UI).
- Flow paths: labels, bars and flows can all be clicked; before, only the
thin bars could. - The side menu no longer shows group headings that looked like buttons;
"Log out" no longer wraps. - Disk in the side menu shows used and free space; hovering over the free
space shows how much the kept days of detail need at the current rate.
The old "days left" figure was an unreliable extrapolation.
Capture
- Windows local capture by name:
-capture Wi-Fi,-capture Ethernetor
the number fromtraffic66 interfaces, which now shows each adapter's
Windows connection name and address. - Commands copied from a web page or chat work: full-width spaces, quotes,
full-width dashes and a trailing full stop around words are ignored, and
a mistyped command gets a "did you mean" hint.
Documentation
- README (13 languages): drill-down, naming, the database upload, local
capture step by step for Windows, Linux and macOS including what Wi-Fi
can and cannot see, new screenshots. - This changelog; releases take their notes from it.
Downloads and installation: see the README.