Harnessing the massive storage capacity and multi-NIC architecture of QNAP NAS with managed switch Port Mirroring to achieve 24/7 out-of-band capture. Featuring independent multi-NIC jobs, automated storage watermark trimming, microsecond-accurate time indexing, and zero-staging streaming export, delivering the most cost-effective authentic packet evidence repository for enterprise incident response and ISO 27001 compliance.
Logs only record what systems 'deemed noteworthy,' whereas packets (PCAPs) capture 'every byte actually transmitted on the wire.' SpesCap empowers enterprises to acquire complete bottom-layer packet evidence at unmatched cost efficiency.
During ransomware outbreaks, anomalous outbound traffic, or lateral movements, raw packets are the only irreplaceable evidence capable of reconstructing attack vectors and C2 communications.
Fulfills ISO 27001 digital evidence acquisition (A.5.28) and activity monitoring (A.8.16), combining microsecond kernel timestamps with daily SHA-256 integrity manifests for stringent audits.
Rapidly deploy low-cost, high-reliability traffic preservation nodes for multi-tenant clients. Multi-NIC isolation and automated watermark watchdogs dramatically reduce on-site maintenance overhead.
Physical out-of-band mirroring design: capture NICs carry no IP and transmit zero packets, operating with zero interference to industrial PLCs and production networks.
Traditional commercial capture appliances cost tens to hundreds of thousands of dollars. SpesCap natively integrates QPKG with QNAP NAS vast storage capacity and multi-threaded kernel acceleration, acquiring authentic evidence at unbeatable ROI.
Full support for parallel multi-interface mirroring. Each Capture Job operates independently with its own slice size, rotation interval, retention limits, and BPF filter rules, completely isolated.
Built-in Free-space Watchdog mechanism. When pool free space drops below threshold (default 200 GB), older PCAP files are safely recycled chronologically, protecting core NAS business services.
One-click automated bring-up: enables Promiscuous Mode, completely disables GRO / LRO / TSO / GSO offloads, and expands RX Ring Buffer to 4096, preserving authentic on-the-wire packet timing.
Simultaneously monitors application counters and Linux kernel rx_dropped / rx_missed_errors. Real-time QTS system events and alerts trigger when drop rates exceed thresholds.
Files are automatically named by their actual first-packet timestamp as cap-<timestamp>.pcap. Offers one-click time-range query and zero-staging streaming TAR download without temporary disk overhead.
Capture states are persisted across reboots, automatically resuming capture upon NAS startup. All admin logins, job actions, configuration edits, and exports are recorded in AUDIT logs and QTS events.
Adopts the standard security design of physically separated management and capture interfaces. The dedicated capture NIC has no IPv4 address and never transmits active traffic, remaining unroutable and inaccessible, while all management, query, and export traffic traverses an independent NIC.
Managed Switch: Port Mirroring / ACL Mirroring
RX Ring 4096 · TPACKET_V3 Ring Buffer · Microsecond Kernel Timestamps
Sliced by Size (256MB) / Time (1hr) · Automated Watermark Recycling
ISO 27001 Evidence Preservation · Incident Response · Threat Behavior Retrospection
All figures below represent empirical benchmarks. Under a baseline mid-range 8-core Atom NAS with a 6-HDD storage pool, SpesCap already achieves massive write throughput, and more importantly, the software capture pipeline ingests over 1.2 GB/s without saturation, allowing performance to scale linearly upward on higher-tier NAS hardware platforms!
| Mid-Range NAS Baseline (Atom + 6 HDD) | Measured Result | Disk Write Throughput | Applicable Analysis Scenario |
|---|---|---|---|
| Full Packet Capture (Full Payload) | 3.5 Gbps Zero Packet Loss | 435 MB/s | Forensics & legal evidence preservation requiring complete payload retention |
| snaplen 256 | 10GbE Line Rate Zero Loss | 221 MB/s | Connection behavior analysis: JA3/JA4 fingerprints, SNI, cert chains, traffic timing |
| snaplen 128 | 10GbE Line Rate Zero Loss | 117 MB/s | Long-term evidence preservation: Storage footprint is ~1/7.5 of full capture, yielding 7x retention |
| Small Packets (64 Bytes) | Capture software drop: 0 | 125 MB/s | NIC received 1.6M pps fully persisted to disk, demonstrating superior PPS capability |
In RAM disk testing, the same 10GbE line-rate full packet load produced zero drops. The capture software path ingests over 1.2 GB/s, proving software is never the bottleneck, capacity is governed by pool write throughput.
Empirical tests prove drop thresholds correlate strictly with 'write MB/s' and are independent of packet rate (pps). Capacity planning can be computed directly in MB/s without guessing packet size distributions.
Built with our proprietary multi-reader engine (AF_PACKET TPACKET_V3 + PACKET_FANOUT). Multiple workers share kernel fanout and write independent files, completely eliminating single-thread packet drops under heavy loads.
Because capture throughput scales directly with storage write speed, enterprises can seamlessly select the right NAS tier according to monitored bandwidth:
| Target Capture Throughput | Required Continuous Write | Recommended Hardware & Storage Architecture | Validation Status |
|---|---|---|---|
| 10 Gbps Line Rate (snaplen 256) | ~221 MB/s | Mid-Range 8-Bay NAS + HDD storage pool | Verified Zero Loss |
| 3.5 Gbps (Full Packet Capture) | ~435 MB/s | Mid-Range 8-Bay NAS + 6+ HDD storage pool | Verified Zero Loss |
| 5 Gbps (Full Packet Capture) | ~620 MB/s | High-spindle Enterprise HDD pool, or add SSD write landing tier | Verified Zero Loss |
| 10 Gbps Line Rate (Full Packet Capture) | ~1.24 GB/s | Flagship NAS / Rack Server (Xeon/EPYC) + NVMe landing tier + Tiered HDD cold archive | Verified Zero Loss |
※ SPES provides pre-installed, turn-key hardware delivery as well as on-premise PoC verification, testing directly against your organization's actual traffic profile and hardware plan before finalizing specifications and capacity sizing, ensuring every investment is precisely validated.
Packet capture choices typically force a dilemma between 'million-dollar proprietary appliances' and 'high-maintenance open-source stacks.' SpesCap focuses on optimizing the core 'bottom-layer high-reliability ingestion,' delivering unmatched ROI and operational simplicity.
| Comparison Criteria | Custom tcpdump Scripts | SpesCap (QNAP QPKG) | Open-Source Search Systems (Arkime) | High-End Commercial Appliances |
|---|---|---|---|---|
| Ingestion Ceiling | Single-threaded, severe packet drops under high loads | Mid-Range NAS: 3.5 Gbps full packet, 10GbE snaplen zero drop, scalable upward to 5 Gbps, 10 Gbps, or higher | Requires high-end hosts to balance protocol parsing and indexing | 10~100 Gbps continuous recording |
| Storage & Expansion Cost | Manual rotation scripts and disk management required | Directly leverages NAS drive bays, minimal cost per TB, snaplen yields 7x capacity | Requires OpenSearch clusters and heavy SSD storage footprints | Locked to proprietary chassis and expansion shelves, high cost per TB |
| Evidence Integrity | No automated hashing or integrity manifests | Per-file SHA-256 manifest (standard format) + AUDIT trails + QuTS hero snapshots/WORM | Depends on underlying OS and database configurations | Built-in proprietary hardware hashing and digital signatures |
| Deployment & Maintenance | Custom scripts, failure-prone and difficult to maintain | Single QPKG one-click install, auto-resume on boot, intuitive Web UI | Demands Elasticsearch / OpenSearch cluster administration expertise | Turnkey vendor delivery, but tied to hardware and licensing contracts |
| Best Fit Scenarios | Ad-hoc packet captures, short engineering debugs | Long-term network evidence preservation for SMEs, MSPs & Branch Offices | Dedicated SOC teams requiring daily threat hunting | Data center backbones, financial & telecom cores |
SpesCap concentrates exclusively on 'lossless packet ingestion and evidence preservation'. Generated standard PCAPs feed directly into ANMAS, Wireshark, or Zeek for deep protocol parsing and threat hunting.
The true long-term cost of capture projects is 'Retention Days × Cost per TB'. SpesCap harnesses existing NAS drive bays and snaplen truncation, allowing organizations to achieve months of retention on modest budgets.
Engineered with a low-saturation palette for long hours of network administration and SOC monitoring. Displays real-time throughput, drop rate monitoring, storage pool watermarks, estimated retention hours, and time-range packet stream export.
| Name | Interface | Status | Throughput | Packet Drop | Rotation | Output Directory |
|---|---|---|---|---|---|---|
| Core Switch Mirror | eth1 | Capturing | 312 Mbps 60,900 pps | 0.00 % Kernel 0 | 256 MB / 3600s Retain 8 TB | /share/ZFS18_DATA/spescap/pcap/eth1-e856e3/20260825-090000 |
| DMZ Full Traffic (snaplen 128) | eth3 | Capturing | 28 Mbps 5,500 pps | 0.00 % Kernel 0 | 256 MB / 3600s Retain 500 GB | /share/ZFS18_DATA/spescap/pcap/eth3-b2a71c/20260825-090000 |
Deeply tuned for QNAP QTS and QuTS hero kernels, SpesCap delivers outstanding compatibility across NAS models. Below are system recommendations and sizing reference tables for typical enterprise traffic.
| Hardware & System Requirements | Specifications & Configuration Guidelines |
|---|---|
| Supported Architectures & OS | x86_64 (Intel / AMD) or arm64 processors, compatible with QTS 5.0+ and QuTS hero 5.0+ (ZFS) |
| Processor (CPU) | Recommended 4+ cores, multi-threaded reader engine provides high computing efficiency to fully unleash hardware potential |
| Memory (RAM) | Basic operation 4 GB+, 16 GB+ recommended if running Arkime or OpenSearch on the same host |
| Network Interfaces (NIC) | At least 2 ports (1 port for QTS management, remaining dedicated to Port Mirroring capture) |
| Storage Recommendations | Capture is a high-sequential write load, HDD pools offer the best cost-efficiency, for 10GbE full-rate capture, add an NVMe landing tier |
| Switch Requirements | Managed switch supporting Port Mirroring or ACL Mirroring (e.g., QNAP QSW-M series) |
| Security Architecture | Built-in PBKDF2-HMAC-SHA256 password hashing, CSRF token protection, HttpOnly cookies, and HTTPS certificate support |
| Daily Ingress Volume | Retention Period | Raw PCAP Storage Required | Recommended Pool Configuration |
|---|---|---|---|
| 50 GB / day (Light office subnet) | 30 days (1 month) | ~1.5 TB | 2-Bay / 4-Bay NAS (RAID 1 / 5) |
| 200 GB / day (Medium enterprise core line) | 14 days (2 weeks) | ~2.8 TB | 4-Bay / 6-Bay NAS (RAID 5 / 6) |
| 500 GB / day (High-traffic server segment) | 30 days (1 month) | ~15.0 TB | 6-Bay / 8-Bay NAS (RAID 6) |
| 1.5 TB / day (10GbE backbone sample/full) | 14 days (2 weeks) | ~21.0 TB | 8-Bay / 12-Bay+ Enterprise Storage Pool |
SpesCap implements the ISO/IEC 27037 and NIST SP 800-86 digital evidence standards, delivering authentic, immutable, and fully auditable packet evidence with a verifiable chain of custody.
Completely preserves packet headers, microsecond timing, and raw payloads, archived by first-packet timestamp for authentic wire-level evidence.
All administrator logins, capture job actions, configuration changes, and downloads are logged to AUDIT trails and written to QTS system event logs.
Dual-layer kernel and application monitoring of packet loss, combined with retention forecasting, enables proactive infrastructure monitoring.
Supports kernel-level BPF filtering to restrict capture to specific subnets and exclude sensitive services, ensuring minimum necessary data preservation.
• Microsecond Timestamps & Unsampled Packets: Preserves authentic wire-level bytes with kernel-level microsecond timestamps.
• Atomic Renaming: In-progress files are atomically renamed upon completion, guaranteeing downstream analytics tools never read partial fragments.
• Per-File SHA-256 Integrity Manifest: Every file is hashed upon completion into a daily manifest compatible with standard sha256sum format for independent verification.
• Storage-Layer Immutability: Seamlessly pairs with QuTS hero snapshots and WORM folders to freeze and protect evidence immediately after an incident.
SpesCap is not only a standalone capture QPKG, but also a vital piece in SPES enterprise cybersecurity ecosystem responsible for 'raw packet preservation.'
PCAP files exported from SpesCap can be directly imported into the ANMAS Security System for automated analysis of malicious connections, C2 communications, anomalous protocols, and lateral movement trails, producing professional forensic reports.
Paired with the SpesLog Custom Log Archiving Platform, achieve 360-degree audit coverage by capturing both system text logs (Syslog, Event Log) and network wire-level PCAP packets.
Pre-loadable on Custom Enterprise QNAP NAS planned by SPES. Our senior engineers handle NIC provisioning, storage pool optimization, and switch mirror configuration for a seamless out-of-the-box experience.
Our cybersecurity architecture consulting team is ready to provide QNAP NAS capture planning, switch mirror configuration, and on-premise PoC hardware validation.