Skip to content
Skillv1.0.0

analyzing-network-flow-data-with-netflow

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic b

by nuroctane(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from nuroctane/nur-cli (skills/security/analyzing-network-flow-data-with-netflow/SKILL.md). Install upstream with npx skills add nuroctane/nur-cli --skill analyzing-network-flow-data-with-netflow. Copyright stays with the author (Apache-2.0).

Analyzing Network Flow Data with Netflow

When to Use

  • When investigating security incidents that require analyzing network flow data with netflow
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • Familiarity with network security concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

  1. Install dependencies: pip install netflow
  2. Collect NetFlow/IPFIX data from routers or use the built-in collector: python -m netflow.collector -p 9995
  3. Parse captured flow data using netflow.parse_packet().
  4. Analyze flows for:
    • Port scanning: single source to many destinations on same port
    • Data exfiltration: high byte-count outbound flows to unusual destinations
    • C2 beaconing: periodic connections with consistent intervals
    • Volumetric anomalies: traffic spikes beyond baseline thresholds
  5. Generate a prioritized findings report.
python scripts/agent.py --flow-file captured_flows.json --output netflow_report.json

Examples

Parse NetFlow v9 Packet

import netflow
data, _ = netflow.parse_packet(raw_bytes, templates={})
for flow in data.flows:
    print(flow.IPV4_SRC_ADDR, flow.IPV4_DST_ADDR, flow.IN_BYTES)

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/nuroctane-nur-cli-analyzing-network-flow-data-with-netflow/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

nuroctane-nur-cli-analyzing-network-flow-data-with-netflow.ocm.jsonjson
{
  "ocm": "1",
  "id": "nuroctane-nur-cli-analyzing-network-flow-data-with-netflow",
  "kind": "skill",
  "name": "analyzing-network-flow-data-with-netflow",
  "description": "Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify flows with abnormal byte counts, connection durations, and periodic timing patterns.",
  "publisher": "nuroctane",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "coding"
    ],
    "tags": [
      "skill-md",
      "analyzing",
      "network",
      "flow",
      "data",
      "github"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify flows with abnormal byte counts, connection durations, and periodic timing patterns."
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "github",
      "repository": "https://github.com/nuroctane/nur-cli",
      "path": "skills/security/analyzing-network-flow-data-with-netflow/SKILL.md",
      "ref": "2c1f854ca0bf6bb6c45e404de2cab2345956262c",
      "url": "https://github.com/nuroctane/nur-cli/blob/2c1f854ca0bf6bb6c45e404de2cab2345956262c/skills/security/analyzing-network-flow-data-with-netflow/SKILL.md",
      "key": "nuroctane/nur-cli/skills/security/analyzing-network-flow-data-with-netflow/SKILL.md"
    },
    "license": "Apache-2.0"
  },
  "instructions": "# Analyzing Network Flow Data with Netflow\n\n\n## When to Use\n\n- When investigating security incidents that require analyzing network flow data with netflow\n- When building detection rules or threat hunting queries for this domain\n- When SOC analysts need structured procedures for this analysis type\n- When validating security monitoring coverage for related attack techniques\n\n## Prerequisites\n\n- Familiarity with network security concepts and tools\n- Access to a test or lab environment for safe execution\n- Python 3.8+ with required dependencies installed\n- Appropriate authorization for any testin",
  "cost": {
    "context_tokens": 377
  }
}

Fetch it by URL: GET /api/v1/registry/nuroctane-nur-cli-analyzing-network-flow-data-with-netflow/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.