Peter Haag
Log time Cyber Threat Intelligence Analyst. Author of open source tools nfdump.
Passionate photographer.
Session
Understanding what happens inside your network is essential for defending it. During an incident, you must be able to quickly identify malicious activity, trace its origin, and assess the impact. NetFlow is one of the most powerful sources of visibility for this task — yet it is often misunderstood or underused and its value underrated, even though most network devices can export it at no additional cost.
This workshop introduces the fundamentals of NetFlow and shows how to collect, process, and analyse flow data using the open‑source nfdump toolkit. Participants will learn how to deploy exporters and collectors, interpret flow records, and apply practical techniques for incident response, threat hunting, and network forensics.