Network Flow Record (NetFlow)
Definition
A summarised record of a network conversation: source IP, destination IP, ports, protocol, byte count, and duration. Flow records do not contain payload content but establish communication patterns between hosts and are a primary evidence type in cyber investigations.
- Data captured
- Source/destination IP, ports, protocol, bytes, duration
- Content included
- No payload
- Use
- Establishes communication patterns between hosts
- Field
- Cyber forensics evidence
Common questions
How is a flow record used to identify data exfiltration?+
Unusually large or sustained outbound byte counts to an unfamiliar external IP can flag possible exfiltration even without any payload content being available.
Can flow records alone prove what data was transferred?+
No. They show that a conversation occurred and its volume, not its content, so correlating with other logs or a payload capture is needed to confirm what left the network.
Related terms
- Chain of Custody
- The documented chronological record of who collected, handled, transferred, and examined a piece of evidence. For digital evidence, chain of custody includes...
- Cyber Forensics
- The branch of forensic science concerned with collecting, preserving, and analysing digital evidence from networked environments for use in legal proceedings. Covers...
- Cybercrime
- Offences where a computer network is the tool or the target. Tool-based cybercrime includes fraud, harassment, and intellectual property theft conducted online....
- Digital Forensics
- The discipline concerned with the recovery, preservation, and analysis of evidence stored on physical digital devices. Primary evidence sources are disk images,...
- Indicator of Compromise (IoC)
- An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...