About this user
NetWitness® Investigator is a Windows-based software application that provides unprecedented fast and efficient, free-form contextual analysis of terabytes of raw data captured and reconstructed by the NetWitness NextGen infrastructure. Developed originally for the U.S. Intelligence Community, and now used extensively by Law Enforcement, Defense, and other public and private organizations, Investigator is based upon 10 years of development and deployment in some of the most demanding and complex threat environments.
With its groundbreaking user interface and unprecedented analytics, Investigator lets you see your network traffic in a new way. Unlike some products which display network traffic in the context of confusing network nomenclature, Investigator uses a lexicon of nouns, verbs and adjectives characteristics of the actual application layer protocols parsed by NextGen during session reconstruction.
Both novice and expert users can use Investigator to pivot terabytes of network traffic easily to dive deeply into the context and content of network sessions in real-time -- making threat analysis that once took days, take only minutes. It is this intersection of network metrics, rich application flow, and content information that differentiates NetWitness® products from any other capability on the market today.
In addition to the rich data Investigator receives from the NextGen infrastructure of NetWitness Decoders and Concentrators, Investigator can locally capture live traffic and process packet files from virtually any existing network collection device for quick and easy analysis.
Country
United States