Packet capture
The packets, on disk. Ground truth for a window of time. Heavy, precise, and easy to collect too late.
Packet capture stores traffic, or a slice of it, as it was on the wire. Analysts use it for the handshake, the payload, the timing. Full packet is expensive. Ring buffers and filters make it survivable.
You cannot replay what you did not keep. For incident response, capture on the relevant segment as soon as you suspect, with a written purpose and retention. NetFlow tells you who talked. Packet capture tells you what they said if it was not encrypted, and TLS still leaves names, sizes, and timing.
See also: NetFlow, Network detection and response, Transport Layer Security (TLS), Incident response.
