Using the Program


Capturing packets

The program interface consists of three panes. Captured packets are organized and showed on the left-top pane based on type, source and destination addresses, and connections. You can also add "workspace" to display packets that fit special criteria, such as containing a word, matching a user-defined rule, and/or matching time, size, etc (see the section of "Program Options"). The left-bottom pane and the right pane displays decoded data or statistics data. To start capturing packets, select a network adapter from the drop-down list on the toolbar, and click on the Start Capture button or select Edit -> Capture from the menu. To stop capturing packets, click on the Stop button on the toolbar or select Edit -> Stop from the menu.

Main menu

File
1. New - create a new document.
2. Open... - open an existing document.
3. Import... - import packet data from a "libpcap" file.
4. Save - save the active document.
5. Save as - save the active document with a new name
6. Exit - quit the application; prompt to save document

Edit
1. Capture - start capturing packets.
2. Stop - stop capturing packets.
3. Stop Alarm - stop alarm.
4. Copy - copy selected data into the clipboard.
5. Export Graph Data - write statistics data into a file.
6. Search... - search words or matches against a user defined rule.

Options
1. Status Bar - show or hide status bar.
2. Customize Workspace... - add or edit "workspace" to display packets that fit special criteria, such as containing a word, matching a user-defined rule, and/or matching time, size, etc.
3. Rules... - view and define rules for intrusion detection
4. Colors... - define colors for window background, decoded and raw data.
5. Data Manager... - define options for saving, filtering, displaying and logging data file, etc.

Help
1. About - display program information.
2. Help Topics - launches IPSoft helper.