NetFlow
Definition
A network protocol (originally Cisco, now standardised as IPFIX under RFC 7011) that records metadata about IP traffic flows: source and destination IP, port, protocol, byte count, and duration. NetFlow does not capture packet content but is far less storage-intensive than full packet capture and is adequate for many investigative queries.
- Origin
- Developed by Cisco, standardised as IPFIX under RFC 7011
- Records
- Source/destination IP, port, protocol, byte count, duration
- Content captured
- None; metadata only, not packet payload
- Storage cost
- Far lower than full packet capture
Common questions
What can NetFlow data prove that full packet capture cannot cheaply match at scale?+
Because it is compact metadata, NetFlow can be retained for months or years across an entire network, letting investigators reconstruct communication patterns and timelines long after the traffic occurred. Full packet capture at that retention window would require prohibitive storage.
When does NetFlow fall short for an investigation?+
It cannot show what was said or transferred, only that a connection existed between two endpoints, its size, and its duration. Cases needing the actual content, such as recovering exfiltrated file contents or message text, require full packet capture or endpoint evidence instead.
Related terms
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- DHCP Lease Log
- A record maintained by a Dynamic Host Configuration Protocol server that maps each IP address assignment to the requesting device's MAC address,...
- Hypothesis Testing
- In digital forensics, the practice of forming a specific, falsifiable proposition about what occurred (such as 'the attacker used account X to...
- Intrusion Detection System (IDS)
- A network or host-based monitoring system that analyses traffic or system behaviour against a rule set (signature-based) or a statistical baseline (anomaly-based)...
- Link Analysis
- A graph-based analytical technique that maps entities (IP addresses, domains, accounts, phone numbers, wallets) as nodes and relationships (communications, ownership, transactions) as...
- PCAP (Packet Capture)
- A file format (and the process of creating it) that records every byte of every network packet passing a capture point, including...
- RADIUS Log
- An authentication, authorisation, and accounting record produced by a Remote Authentication Dial-In User Service server. Each entry records the username, authenticating device...
- SIEM (Security Information and Event Management)
- A platform that aggregates log and event data from systems, networks, and applications across an environment, correlates events against detection rules, generates...
- Syslog
- A standardised protocol (RFC 5424) for transmitting log messages from network devices to a centralised log server. Routers, switches, firewalls, and servers...
- Timeline Reconstruction
- The process of ordering digital events from multiple sources into a single chronological account. Requires normalising all timestamps to a common reference...
Explained in these topics
- Cyber Investigation Tools and Analytical Workflow
- Network Evidence Sources and Their Forensic ValueA network protocol developed by Cisco for collecting IP traffic flow metadata. Each flow record captures source and destination IP addresses, port numbers, pro...