Function introduction
1. Ordinary capture: just capture the packet output and do not analyze any results.
2. 1-drag-N capture: Analyze the captured traffic and analyze whether the traffic comes from portable wifi, private router, etc. Port mirroring needs to be done on the "gateway interface" (such as on the SVI interface), otherwise the results will be inaccurate.
3. QQ number capture: QQ traffic can be analyzed to extract QQ numbers.
(The above three functions require port mirroring to guide traffic in for capture and analysis, otherwise only your own traffic will be captured)
4. ARP capture: detect various types of ARP attacks and spoofing. ARP spoofing attacks are the main cause of slow local area networks.
Things to note
1. .NET 4.0 or above
2. WinPcap4.1.2 or above
it works
it works
it works