Skip to content

Flow Record

Definition

A summary record of a network conversation, typically recording source and destination IP addresses and ports, protocol, start time, duration, byte count in each direction, and packet count. Flow records (NetFlow, IPFIX, sFlow) are generated by routers and switches and provide traffic metadata without storing payload content.

Contents
Source/destination IP and port, protocol, duration, byte and packet counts
Common formats
NetFlow, IPFIX, sFlow
Source device
Routers and switches
Payload
Not captured; metadata only

Common questions

What can a flow record tell an investigator that a full packet capture cannot?+

Flow records are compact enough to retain for months across an entire network, where full packet capture is not, so they let an analyst reconstruct who talked to whom, when, and how much data moved, over a much longer retention window than payload capture typically allows.

Why are flow records useful when traffic is encrypted?+

Because they record connection metadata rather than content, they remain fully readable even when the payload is encrypted with TLS or a VPN. Timing, volume and destination patterns in the flow data can still reveal command-and-control beaconing or data exfiltration.

Is a flow record admissible on its own to prove what data was transferred?+

It shows that a connection occurred and its volume, but not the content exchanged. Courts typically treat it as circumstantial evidence of communication or transfer, usually corroborated with host logs, DNS records or other artefacts rather than standing alone.

Related terms

JA3 Fingerprint
An MD5 hash computed from selected fields of the TLS Client Hello: the TLS version, cipher suites, extensions, elliptic curves, and elliptic-curve...
Server Name Indication (SNI)
A TLS extension sent in plaintext in the Client Hello message that identifies the hostname the client intends to reach. SNI is...
SSL Inspection (TLS Interception)
A technique in which an intermediary device terminates an incoming TLS session, inspects the decrypted content, then re-encrypts and forwards it using...
SSLKEYLOGFILE
A file format, originally implemented in Mozilla Firefox and later adopted by Chrome and other browsers, that logs TLS session keys as...
Traffic Fingerprinting
The process of identifying an application, protocol, or user action from statistical properties of an encrypted flow, such as packet size distributions,...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.