Enhance Threat Response with Cloud-Based Packet Capture

Streamline and enrich security incident investigations, forensics, and threat detection.

Enhance Threat  Response with Zscaler Cloud-Based Packet Capture

Empower your team to resolve security incidents faster

Give security practitioners and threat researchers easy access to raw, decrypted traffic for efficient security forensics—without requiring additional appliances.

Support deeper incident response
Support deeper incident response
Enhance retrospective analysis
Enhance retrospective analysis
Improve detection fidelity
Improve detection fidelity
The Problem

Access to past traffic content is critical

Security teams need to understand the content traversing your environment to conduct effective forensic analysis, investigate incidents, ensure compliance, and more. Appliance-based packet capture tools, unequipped for the volume and speed of the cloud, are no longer enough.

Poor performance and scalability

Hardware-bound legacy solutions can't decrypt and capture today's massive volume of traffic efficiently.

High infrastructure and bandwidth costs

Legacy solutions capture all content regardless of risk relevance, creating high volumes of low-interest capture.

Complexity in analysis

Analyzing the vast amounts of data collected by legacy PCAP solutions can be complex and time-consuming.

Solution Overview

Get secure and seamless access to traffic content

Easily capture decrypted traffic via specific criteria in Zscaler policy engines.

Traffic Capture enables you to incorporate capture decisions into existing policies across URL filtering, malware protection, advanced threat protection, firewall and IPS control, DNS control, and file type control.

By defining granular policies and rules for capturing specific content, you can concentrate on packets and full content related to risky events identified by advanced threat and malware detection signatures, threat intelligence, AI/ML as well as flexible and specific policy controls.

Traffic Capture is part of Zscaler Internet Access™, the world’s most-deployed security service edge (SSE) solution.

Benefits

Reduce time, effort, and cost to capture traffic content

Cut costs and complexity
Cut costs and complexity

Decrypt and capture traffic content without a legacy appliance-based solution, saving countless hours and expense.

Reduce infrastructure and bandwidth costs
Reduce infrastructure and bandwidth costs

Define policy-level criteria to capture only content associated with risky events, rather than all content, avoiding further added costs.

Safeguard your data your way
Safeguard your data your way

Securely store captured data as PCAP files in your preferred external storage.

Use Cases

Power superior security forensics

Conduct in-depth forensics

Capture some traffic for extended periods to support threat hunting and many forensic/incident response investigation needs.

Investigate incidents

Study and replay traffic that might have caused a threat signature or other detection to trigger a false positive.

Appraise threat signatures

Test new threat signatures or detections of any kind against known threat activity in real traffic content.

Comply with regulations

Capture traffic content to comply with regulatory compliance requirements.

FAQs

Request a demo

Let our experts show you the power and efficiency of cloud-based Traffic Capture.