Nfsight is a Netflow processing and visualization application designed to offer a comprehensive network awareness solution. It is developed as a Nfsen plugin to construct bidirectional flows out of the unidirectional netflow flows. Nfsight leverages these bidirectional flows to provide client/server identification and intrusion detection capabilities.
Nfsight is a research project jointly developed at the University of Maryland and AT&T Labs Research.
The latest release is available in the download section.
User documentation to install Nfsight is available offline in the README file of the release, or online in the documentation section.
Query to visualize server activity:
Netbios scanning activity from a single host:
Distributed SSH attack: