Performing a Forensic Search on capture files - User Guide - LiveWire - 26.2.0

LiveWire User Guide

ft:locale
en-US
Product name
LiveWire
Version
26.2.0
You can perform a forensic search on a capture file or multiple capture files that have been collected by a capture engine to analyze the output for statistics or anomalies.
Note:
  • Forensic searches cannot be performed on an RCE and can only be performed on the LiveWire control point.
  • When creating a forensic search for a group of files, it is recommended that all files in a group originate from the same capture and do not result in a large time window. Performing a forensic search outside of these guidelines can result in longer wait times for analysis. Before starting the forensic search, check the Start time, End Time, packet count, and file count of the forensic search. You can adjust the Start time and End times to reduce the time window.
To perform a forensic search on capture files:
  1. Select the Files tab.
  2. Under Files, select in the row of the file or file group and select Forensic Search
  3. On the Forensic Search pop-up, enter the following information:
    • Name: enter the name of the forensic search.
    • Start time: enter start time of the capture files that you would like to perform the forensic search on.
    • End time: enter end time of the capture files that you would like to perform the forensic search on.
      Note: Under Presets, you can select the time frame of the capture files that you would like to perform the forensic search on. You can select the following Preset times:
      • Today
      • Yesterday
      • This week
      • Last week
      • This month
      Additionally, you can set the following Relative times based on the current time of the LiveWire control point:
      • Last 60 seconds
      • Last 5 minutes
      • Last 30 minutes
      • Last 1 hour
      • Last 24 hours
      • Last 7 days
      • Last 1 month
    • Filter: enter the expression that will be used to filter packet information.
    • Under Analysis & Output, select the types of analysis that you would like to perform with the forensic search.
  4. Click OK.

Once you click OK, LiveWire redirects you to the Forensic Search page and begins the forensic search analysis on the selected packets.