9
Protecting Your Digital Assets
TM
CRU Ditto Shark User Manual
Simultaneous PCAP and Live Network Capture
a. Using the Browser Interface, select
Network Capture
from the “Action to Perform” drop-down
box.
b. Select the network capture fi lter from the “Network Capture Filter” drop-down box or type in
the ports you wish to capture in the text box directly below that using the syntax “port ## or ##”
without quotes (e.g. port 80 or 81 or 443).
c. Select “NetTap” from the “Interface” drop-down box.
d. Select the local media from the “Destination” drop-down box that you want Ditto Shark to save
your captured data to as a series of incremented PCAP fi les
e. Select the partition on the local destination media you want to capture to from the “Partition”
drop-down box.
f. Ensure your third party Wireshark network protocol analyzer is standing by to receive data. If you
need help in confi guring Wireshark itself, click the
Information icon
next to “Live Network
Capture” for a link to Wireshark’s remote capture documentation.
g. Click the
Enable button
next to “Live Network Capture” to turn live network capture on. When
you are fi nished capturing network traffi c, click the
Disable button
.
h. Click the
Start button
to begin capturing network data to your local destination media. When
you are fi nished, click the
Stop button
.
You can view the log of the PCAP network capture action by scrolling down to the “System Log”
panel on the “Home” screen. Find and click on the latest link, which will be denoted by a fi lename
with a date/timestamp format: “S_yyyymmddhhmmss”. Alternatively, you can click on the
Logs
button
from the top menu bar.
You can view the data retrieved from the PCAP network capture action by examining the destina-
tion media, which will contain a folder named with the same data/timestamp format: “S_yyyymmd-
dhhmmss”, which includes the PCAP fi les containing the captured data, an XML fi le containing the
log information of the network capture, and—if hashing is enabled—a TXT fi le that contains each of
the generated PCAP fi les’ MD5 or SHA-1 hash value (see Section 5.1.2 to enable hashing).
4.1.2 Erase Destination Disk
The Ditto Shark erases your preferred destination media. The available Erase Modes are Clear Partition
Table and Quick Erase.
To erase a disk, follow these steps:
a. Select
Erase Destination Disk
from the “Action to Perform” drop-down box.
Figure 10.
The “Action” section on the “Home” screen, showing
the options available for the “Erase Destination Disk” action.