SCADAfence Network Capture Tool

The SCADAfence Network Capture Tool is a new tool we’re providing to the community as free and open source (under the GPLv3 license), for both Linux and Windows operating systems.

The tool is a lightweight wrapper for network capture and compression applications that allows capturing of traffic in high bandwidth networks, with no limits on the file size or the duration of capture. 

What makes this tool special?

We’ve tried using many tools, and our customers have tried as well. Wireshark, for example, might crash/stop while capturing high bandwidth OT/IoT networks. Wireshark also has problems with too many open files handles that can cause it to crash. In addition, its output files aren’t compressed. 

Other tools name the files in a way that can’t be used by automated systems. They also produce files that are too big to open with Wireshark, they don’t have timestamps and suffer from additional issues that we’ve encountered.

This tool was created in order to save you time since it has been developed by people who use it for the same use case as what you need it for (see list of use cases below). We have used this tool to capture high bandwidth OT & IoT network traffic continuously for months.

The Tool’s Main features:

  1. Simple command line interface
  2. Textual log of capture into a log file
  3. Status updates every 10 seconds – How many files have been captured/compressed and error reporting
  4. Separates the files to 100MB each (before compression), to allow opening it with Wireshark without RAM issues
  5. Supports very high network bandwidth
  6. Names the files in a way that can be easily understood humans and machines, which includes file number (so that the order won’t be lost) and a timestamp: sniff_00001_20170828132202.pcap.gz
  7. Automatic parallel gzip compression of the pcap files, in a way in which the capturing doesn’t stop while compressing
  8. Standard pcap file format – can be opened with Wireshark or any other application that supports the pcap file format
  9. Free and open source – You can extend/change the code as you wish
  10. Low CPU/RAM footprint, can run reliably for months

The tool’s main use cases:

  1. Capture traffic for testing with products utilizing Deep Packet Inspection such as SCADAfence Platform Sensors
  2. Capture traffic during a cyber incident to gather evidence or allow researchers to look at full raw packet data
  3. Capture traffic in order to understand which protocols you have in your network
  4. Capture traffic in order to investigate networking issues

The tool can be used in industrial/IoT networks or in any other type of network. 

I’m very happy that we’re able to provide a free, entry-level tool for people that are just starting out their journey into OT/IoT network security monitoring, and I hope this tool will be of help to you.

To Get the Network Capture tool for free, please click here: