Kaspersky Anti Targeted Attack Platform

Configuring recording of mirrored traffic from SPAN ports

With Kaspersky Anti Targeted Attack Platform, you can save mirrored traffic from SPAN ports for investigation and detection of malicious activity within the perimeter of your corporate LAN. With mirrored traffic recording, you can perform retrospective analysis of network events and investigate the actions of hackers. Traffic is saved as dumps in PCAP format.

To save mirrored traffic from SPAN ports, enable the recording of such traffic and configure it in the web interface of the application or in the administrator menu of the Sensor component. You can also select network protocols for receiving traffic.

In this section

Selecting network protocols for receiving mirrored traffic from SPAN ports

Configuring the recording of mirrored traffic from SPAN ports using the web interface

Configuring the recording of mirrored traffic from SPAN ports using the administrator menu of the Sensor component