23 thoughts on “Feedback

    1. I presume you are referring to the dialog “Microsoft Defender Smartscreen prevented an unrecognized app from starting…” that pops up when the installer is run the first time. The reason is simply that Nethor installer doesn’t have enough reputation yet and partly because I have not purchased a certificate that will gain trust for Defender. You can safely bypass this by clicking “More info” and then the button “Run anyway”. Regarding viruses, there are two false positives if you check the software at virustotal.com that you can safely ignore. I hope this illuminates the issue.

      1. Hi Are I m proud of your work. I wish you all suksess you deserve for you incredible inside power! Wish I could meet you again as sometimes. Corrado

  1. Hello, really enjoying trying out the product. I am noticing issues where the filters do not seem work… for example Wireshark find PTP but Nethor does not.

    1. I am pleased that you like Nethor and thanks for pointing out the issue with Precision Time Protocol. I am not familiar with this protocol but from reading Wikipedia, I learned that it operates over UDP on ports 319 and 320. Nethor has filter terms “ptp-event” and “ptp-general” respectively but there is a bug. Those terms are in conflict with another term, “ptp” (IP protocol 123, Performance Transparency Protocol). I will fix this in next release.
      Temporary solutions are either open file “IpProtocols.xml” and rename the alias “ptp” for protocol 123 to “ptp2”, or use filter expression: “udp.src == 319 OR udp.src == 320 OR udp.dst == 319 OR udp.dst == 320”.

  2. Huge amount of work for a sole dev. Remarkable packet playback feature. I suggest you a more event or flow centred approach ( e.g. like Brim, CapLoader, Network Miner and Colasoft Capsa Enterprise). Kind of classic (old fashioned) GUI. Do you plan to monetise it eventually?

    1. Yes, I have spent a while coding, but I also have a lot of spare time. Thanks for pointing out about an event based engine. I am not sure where to begin. I must study the apps you mentioned, and maybe get some ideas. I have no plan to license Nethor. I will keep it as freeware. To cover the cost of food and coffee, I may eventually set up a goodwill based donation button. Again, thank you for the feedback!

      1. Hey Are Taraldsen,
        if you want to keep it free, maybe you can give us the source code?
        Thank you for all the efforts and please set up a donation button 😀
        Best
        prk0ghy

  3. Remarkable application, wonderful user experience and intuitive, practical and wonderful interface. However, would it be possible to append a greater selections of IP Telecommunication Protocol decodes,, SCTP, SIP, HTTP2/JASON, including LTE and 5G transport related decodes, as in Wireshark

    1. Uplifting words! Thank you. I will look into these protocols eventually. I must point out I possess no former experience with any. If anyone can share me packets it would help a lot.

  4. impressive. I like the matrix functionality to be able to visualize the order in which systems are accessed/addressed: to bring some points of attention: 1. matrix layout – when changing onscreen layout then it would be nice to be able to save that new layout and option to restore it and use it again (with that respective pcapng file and possibly filter applied). Second: it would be usefull to be able to use the same filter syntax as used in wireshark (ip-segments comparison; negation of an entire clause, etc. [basically regex]) . Third; in the matrix view, it would be really helpfull to have the detail pane of the current packet (or have the flow graph) in the same window as the matrix view, that would make a most usefull analysis tool for quite a number of situations)) As I said, most impressive work and you deserve many kudoos for it ! Loving it!

  5. And forgot one more ‘feature request’; under the flow chart layout – ability to reorder the different columns (systems). Keep it up and all the best!

    1. 1) Great idea! It’s on my todo-list.

      2) Sorry. This is too comprehensive. Wireshark has the most advanced filter engine out there. I alone am unable to program accordingly.

      3) Great! I can do this. A higher screen resolution would be preferable for such a layout to be practical.

      4) Why would you do this? Anyway, I may not be able to achieve implementation of drag & drop columns.

      1. reply to 4) I am using the matrix and flow layouts to explain the working and interaction of systems. it is not always the first system communicating that is the master in a communication flow. re-ordering depending on what needs the focus in an explanation of flows. regards and thank you!

  6. This looks like a fantastic tool, however I’m having trouble importing pcaps captured via Wi-Fi. I’m using tcpdump on linux to capture pcaps which open fine in Wireshark, but Nethor gives me an error; unsupported link type; 127

    Does Nethor support Wi-Fi pcaps?

  7. i am facing issue while opening IP_Capture.pcapng file in nethor what is solution to this. error message:: IP_Capture.pcapng: Packet 1: The added or subtracted value results in an un-representable DateTime. Parameter name: value. Any help will be appreciated.

  8. I discovered this around 2021 looking for alternatives to wire shark for students. I was looking for something similar to GRASSMARLIN but would work on modern systems without too much of a headache and your program worked great. Just wanted to let you know this is part of the CYBV 326 Network Analysis course at the University of Arizona. I do not have any feature requests but I do look forward to future releases.

Leave a Reply to Are TaraldsenCancel reply

Discover more from Nethor

Subscribe now to keep reading and get access to the full archive.

Continue reading