begood Posted May 26, 2010 Report Posted May 26, 2010 New features have been added in to the Pcap Forensics Tool. -Support for multiple files within a single stream-Support for multiple HTTP Requests within a single stream-HTTP GET correlation with returned data-Improved Gzip decoding-Source and Destination IP Filtering-Pinpoint file extraction The following is an example of the new switches it supports: This is the new summary when given the "-s" switch: Filtering destination IP addresses with HTTP Information: And finally, the pinpoint file extraction. The switch "-E" is used in conjunction with a format "s2f1" (stream 2 file 1) to pinpoint which file the user wants to extract as seen below: The tool can be downloaded at the same location: Pcap Forensics Tool This includes the updated gzip support which was created by the writer of JsUnpack.Pcap Forensics Tool Update | Malware Forge Quote