English language page Russian language page
download support
   It now looks like a utility - for the convenience of beginners at the most prominent place to add start network scanning button "Scan Net" and interrupt scanning button "Stop". Changing titles of tabs on the left panel, as I thought, more informative - "Devices" instead of "Host info", etc. Right panel tabs titles also changed - "Traffic online" instead of "Captured packets" and "Traffic offline" instead of "Packets offline".
   The contents of the tab "Filters" in the left panel, too, has changed - now, if you capture of "Ethernet" traffic, opens the same name tab to the settings of the protocol driver filter, where you can select the type of the channel level traffic. Direct - this traffic that is exchanged only the host device with the network, multicasat traffic exchanged between devices belonging to a particular group, broadcast traffic is available to each network device, all the local - it is all the network local traffic and finally "all" traffic, which is available on the interface device, which was translated in the so-called promiscuous mode. The word "all" is taken here in quotes so that you do not think that tick the item "all" you're really going to listen to the entire network. In today's networks, built on the switches, the network device receives only the traffic intended precisely for this device, well, and broadcast and multicast. On the other hand, is not so bad, the methods of capturing the desired traffic still exist - ARP spoofing, for example. Without going into details, I will say that all that is necessary for the implementation of this method is a tool - the built-in editor, you can tweak the existing ARP frame, send a stream of frames with a given frequency to the right address and... listen to the desired traffic! And once they started talking about ARP frames - a checkmark in the item "exclude ARP (RARP) traffic" will disable the capture of ARP traffic.
   Tab "IPv6", available only in the capture of "Ethernet" traffic, to the settings filter of the same name traffic, allows the filter so far only on the value of the "Hop Limit" field of the packet header. And yet - the "Ethernet" traffic capture mode is not available in x64 Windows operation systems, because the protocol driver is not digitally signed certified Microsoft center. This signature is good $$$!
   When you capture IP packets (available also in the x64 systems) opens the tab "IPv4" to the settings filter of the network traffic level. IP packets can be filtered so far only on the value of TTL and the availability of options in the header of IP packets. Under the tab "TCP I" set up filtering of TCP length field of the packet data and packet header flag set, the tabs at the "UDP" and "ICMP" includes filtering traffic of similar protocols. Under the tab "TCP II" can enable TCP traffic counts, and include filtering traffic of the all protocols other than TCP, UDP or ICMP.
    Under the tab "Devices" in addition to the list of network devices can be viewed and a list of other devices - hard drives, volumes, USB, HID and Bluetooth devices. Available is a choice of menu item "Other devices" in the system tray or a combination of hot keys - Ctrl + Alt + Shift + D, who can come in handy.