Problem Statement
When would you choose deep packet capture over flow data, and what are the trade-offs?
Explanation
Use packet capture when you need payload details: exploit content, credentials in clear channels, protocol misuse, or to rebuild a session for forensics. The trade-offs are storage and privacy. Payloads consume space and may include sensitive data. Also, capture at the wrong point can miss encrypted content. A good strategy blends both: flows for broad visibility and packets on demand for drill-down around the alert window.
Code Solution
SolutionRead Only
Quick peek: tcpdump -i eth0 host 203.0.113.10 and port 443 -w suspect.pcap
