Hack.lu 2026

Flow Intelligence: Using NetFlow and nfdump for Network Visibility and Forensics

Understanding what happens inside your network is essential for defending it. During an incident, you must be able to quickly identify malicious activity, trace its origin, and assess the impact. NetFlow is one of the most powerful sources of visibility for this task — yet it is often misunderstood or underused and its value underrated, even though most network devices can export it at no additional cost.

This workshop introduces the fundamentals of NetFlow and shows how to collect, process, and analyse flow data using the open‑source nfdump toolkit. Participants will learn how to deploy exporters and collectors, interpret flow records, and apply practical techniques for incident response, threat hunting, and network forensics.


Understanding network behavior is essential for both operations and security. During incidents, flow data often provides the fastest way to identify affected systems, trace communication paths, and assess impact.

This hands-on workshop focuses on using NetFlow data in real-world scenarios. Participants will work with the open-source tool nfdump to collect, query, and analyse flow data efficiently.

The workshop covers:

  • Fundamentals of NetFlow/IPFIX and flow-based visibility
  • Configuring exporters and collectors in small to medium-sized networks
  • Efficient querying and filtering of large flow datasets
  • Enrichment of NetFlow data with external sources such as geo-information etc.
  • Identifying anomalies such as scans, lateral movement, and data exfiltration
  • Using flow data for incident investigation and response

The session is designed for network administrators, incident responders, and law enforcement personnel dealing with cybercrime investigations. It focuses on practical workflows and techniques that can be applied immediately in operational environments.

Peter Haag

Log time Cyber Threat Intelligence Analyst. Author of open source tools nfdump.
Passionate photographer.