Skip to content

Network Traffic Analysis #30

Description

@8damon

Blackbird is missing a glaringly obvious feature that all malware analysis tools must have. Network analysis!

To be integrated:

  • HTTP callout/connections
  • DNS resolution
  • Connections, endpoint, operations, bytes sent/received
  • Blocking and masking controls that are safe for Community builds
  • Public threat detection rows from local telemetry

Public migration notes

Current validation work maps to Community as local network-analysis QA only. This public lane should stay focused on the driver, sensor, controller, runner, and WPF interface surfaces that exist in Community.

Acceptance criteria

  • Live and replayed captures populate HTTP, DNS, connection, and threat rows correctly.
  • Network rows preserve endpoint, host, PID, source, and evidence fields in copy/details flows.
  • Counts and history survive process/session switching.
  • Public UI text stays focused on Community capabilities and does not advertise private orchestration features.
Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    Status
    Verification & Testing

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions