FULL PACKET CAPTURE · QNAP QPKG · ENTERPRISE EVIDENCE PRESERVATION

SpesCap Full Packet Capture QPKG for QNAP NAS
Transforming Enterprise NAS into a High-Reliability, Linearly Scalable Network Packet Recorder

Harnessing the massive storage capacity and multi-NIC architecture of QNAP NAS with managed switch Port Mirroring to achieve 24/7 out-of-band capture. Featuring independent multi-NIC jobs, automated storage watermark trimming, microsecond-accurate time indexing, and zero-staging streaming export, delivering the most cost-effective authentic packet evidence repository for enterprise incident response and ISO 27001 compliance.

3.5 Gbps
Mid-Range NAS Test
Full Packet Zero Drop
Tested on 6-HDD pool, raw payloads fully persisted to disk without sampling
10GbE
Full Line Rate
snaplen 128/256 Zero Drop
812,743 pps fully captured, precisely tracking connection behaviors & fingerprints
1/7.5
Storage Optimized
Over 7x Retention Window
Extend investigation retention from weeks to months within the same drive budget
10G+
Linear Scalability
Seamless Scaling with NAS Tier
Higher-tier NAS + NVMe landing tier effortlessly scales full packet wire speed
// 01 · Target Scenarios

Building Wire-Level Truth for Critical Security Scenarios

Logs only record what systems 'deemed noteworthy,' whereas packets (PCAPs) capture 'every byte actually transmitted on the wire.' SpesCap empowers enterprises to acquire complete bottom-layer packet evidence at unmatched cost efficiency.

INCIDENT RESPONSE

Incident Response & Forensics

During ransomware outbreaks, anomalous outbound traffic, or lateral movements, raw packets are the only irreplaceable evidence capable of reconstructing attack vectors and C2 communications.

ISO 27001 COMPLIANCE

Compliance & Evidence Preservation

Fulfills ISO 27001 digital evidence acquisition (A.5.28) and activity monitoring (A.8.16), combining microsecond kernel timestamps with daily SHA-256 integrity manifests for stringent audits.

MANAGED SERVICE

MSP / MSSP Managed Services

Rapidly deploy low-cost, high-reliability traffic preservation nodes for multi-tenant clients. Multi-NIC isolation and automated watermark watchdogs dramatically reduce on-site maintenance overhead.

OT & INFRASTRUCTURE

OT Production Lines & Critical Infrastructure

Physical out-of-band mirroring design: capture NICs carry no IP and transmit zero packets, operating with zero interference to industrial PLCs and production networks.

// 02 · Core Capabilities

6 Enterprise-Grade Pillars for Robust Packet Preservation

Traditional commercial capture appliances cost tens to hundreds of thousands of dollars. SpesCap natively integrates QPKG with QNAP NAS vast storage capacity and multi-threaded kernel acceleration, acquiring authentic evidence at unbeatable ROI.

// 01

Multi-NIC Parallel Capture & Independent BPF

Full support for parallel multi-interface mirroring. Each Capture Job operates independently with its own slice size, rotation interval, retention limits, and BPF filter rules, completely isolated.

// 02

Storage Watermark Watchdog & Safe Auto-Pruning

Built-in Free-space Watchdog mechanism. When pool free space drops below threshold (default 200 GB), older PCAP files are safely recycled chronologically, protecting core NAS business services.

// 03

Zero-Offload One-Click Provisioning

One-click automated bring-up: enables Promiscuous Mode, completely disables GRO / LRO / TSO / GSO offloads, and expands RX Ring Buffer to 4096, preserving authentic on-the-wire packet timing.

// 04

Dual-Layer Drop Monitoring & QTS Alerts

Simultaneously monitors application counters and Linux kernel rx_dropped / rx_missed_errors. Real-time QTS system events and alerts trigger when drop rates exceed thresholds.

// 05

First-Packet Timestamp & Zero-Staging Stream Export

Files are automatically named by their actual first-packet timestamp as cap-<timestamp>.pcap. Offers one-click time-range query and zero-staging streaming TAR download without temporary disk overhead.

// 06

Auto-Resume on Boot & Full AUDIT Trail

Capture states are persisted across reboots, automatically resuming capture upon NAS startup. All admin logins, job actions, configuration edits, and exports are recorded in AUDIT logs and QTS events.

// 03 · Network Topology

Network Topology & Capture Architecture

Adopts the standard security design of physically separated management and capture interfaces. The dedicated capture NIC has no IPv4 address and never transmits active traffic, remaining unroutable and inaccessible, while all management, query, and export traffic traverses an independent NIC.

  • Out-of-band Mirroring: Managed switches duplicate internal network traffic to the NAS capture port via Port Mirroring or ACL rules, with zero impact on production traffic or network performance.
  • Efficient Sequential Writes & Drive Longevity: Packet capture is an intensive 'high-volume, sequential, write-only' workload. SpesCap utilizes kernel AF_PACKET Ring Buffers and system Page Cache batch flushes to maximize HDD sequential write efficiency while preserving SSD flash endurance.
  • Flexible Scheduling Modes: Supports '24/7 continuous capture', 'daily recurring schedules (e.g., business hours or off-peak hours)', and 'one-time timed capture (e.g., auto-stop after 4-hour investigation)', balancing depth with storage cost.
  • Seamless Downstream Forensics Integration: Generates standard PCAP directory structures, natively ingestible by ANMAS Forensics System and Wireshark, or mounted to Arkime / Zeek via Container Station for offline collaborative analysis.
SpesCap Capture Topology
Core Network

Enterprise Core Network Traffic

Managed Switch: Port Mirroring / ACL Mirroring

Dedicated Capture NIC (eth1)

NAS Capture Port (No IP · Promiscuous · Zero Offload)

RX Ring 4096 · TPACKET_V3 Ring Buffer · Microsecond Kernel Timestamps

Storage Pool (HDD / SSD)

NAS High-Capacity Pool / ZFS Dataset

Sliced by Size (256MB) / Time (1hr) · Automated Watermark Recycling

Security Analytics & Forensics

ANMAS / Wireshark / Arkime / Zeek

ISO 27001 Evidence Preservation · Incident Response · Threat Behavior Retrospection

// 04 · Verified Performance & Sizing

Empirically Verified Performance & Hardware Scaling Blueprint

All figures below represent empirical benchmarks. Under a baseline mid-range 8-core Atom NAS with a 6-HDD storage pool, SpesCap already achieves massive write throughput, and more importantly, the software capture pipeline ingests over 1.2 GB/s without saturation, allowing performance to scale linearly upward on higher-tier NAS hardware platforms!

Mid-Range NAS Baseline (Atom + 6 HDD)Measured ResultDisk Write ThroughputApplicable Analysis Scenario
Full Packet Capture (Full Payload) 3.5 Gbps Zero Packet Loss 435 MB/s Forensics & legal evidence preservation requiring complete payload retention
snaplen 256 10GbE Line Rate Zero Loss 221 MB/s Connection behavior analysis: JA3/JA4 fingerprints, SNI, cert chains, traffic timing
snaplen 128 10GbE Line Rate Zero Loss 117 MB/s Long-term evidence preservation: Storage footprint is ~1/7.5 of full capture, yielding 7x retention
Small Packets (64 Bytes) Capture software drop: 0 125 MB/s NIC received 1.6M pps fully persisted to disk, demonstrating superior PPS capability
// Storage Write Optimization

Bottleneck in Disk, Massive Software Headroom

In RAM disk testing, the same 10GbE line-rate full packet load produced zero drops. The capture software path ingests over 1.2 GB/s, proving software is never the bottleneck, capacity is governed by pool write throughput.

// Precise Sizing

Byte Throughput Determines Packet Loss

Empirical tests prove drop thresholds correlate strictly with 'write MB/s' and are independent of packet rate (pps). Capacity planning can be computed directly in MB/s without guessing packet size distributions.

// Multi-Threaded Core

Multi-Reader Engine Breaks Single-Core Ceiling

Built with our proprietary multi-reader engine (AF_PACKET TPACKET_V3 + PACKET_FANOUT). Multiple workers share kernel fanout and write independent files, completely eliminating single-thread packet drops under heavy loads.

Hardware Scaling Blueprint: From Mid-Range NAS to Flagship Rackmount Servers

Because capture throughput scales directly with storage write speed, enterprises can seamlessly select the right NAS tier according to monitored bandwidth:

Target Capture ThroughputRequired Continuous WriteRecommended Hardware & Storage ArchitectureValidation Status
10 Gbps Line Rate (snaplen 256) ~221 MB/s Mid-Range 8-Bay NAS + HDD storage pool Verified Zero Loss
3.5 Gbps (Full Packet Capture) ~435 MB/s Mid-Range 8-Bay NAS + 6+ HDD storage pool Verified Zero Loss
5 Gbps (Full Packet Capture) ~620 MB/s High-spindle Enterprise HDD pool, or add SSD write landing tier Verified Zero Loss
10 Gbps Line Rate (Full Packet Capture) ~1.24 GB/s Flagship NAS / Rack Server (Xeon/EPYC) + NVMe landing tier + Tiered HDD cold archive Verified Zero Loss

※ SPES provides pre-installed, turn-key hardware delivery as well as on-premise PoC verification, testing directly against your organization's actual traffic profile and hardware plan before finalizing specifications and capacity sizing, ensuring every investment is precisely validated.

// 05 · Strategic Positioning

SpesCap Strategic Positioning & Solution Comparison

Packet capture choices typically force a dilemma between 'million-dollar proprietary appliances' and 'high-maintenance open-source stacks.' SpesCap focuses on optimizing the core 'bottom-layer high-reliability ingestion,' delivering unmatched ROI and operational simplicity.

Comparison Criteria Custom tcpdump Scripts SpesCap (QNAP QPKG) Open-Source Search Systems (Arkime) High-End Commercial Appliances
Ingestion Ceiling Single-threaded, severe packet drops under high loads Mid-Range NAS: 3.5 Gbps full packet, 10GbE snaplen zero drop, scalable upward to 5 Gbps, 10 Gbps, or higher Requires high-end hosts to balance protocol parsing and indexing 10~100 Gbps continuous recording
Storage & Expansion Cost Manual rotation scripts and disk management required Directly leverages NAS drive bays, minimal cost per TB, snaplen yields 7x capacity Requires OpenSearch clusters and heavy SSD storage footprints Locked to proprietary chassis and expansion shelves, high cost per TB
Evidence Integrity No automated hashing or integrity manifests Per-file SHA-256 manifest (standard format) + AUDIT trails + QuTS hero snapshots/WORM Depends on underlying OS and database configurations Built-in proprietary hardware hashing and digital signatures
Deployment & Maintenance Custom scripts, failure-prone and difficult to maintain Single QPKG one-click install, auto-resume on boot, intuitive Web UI Demands Elasticsearch / OpenSearch cluster administration expertise Turnkey vendor delivery, but tied to hardware and licensing contracts
Best Fit Scenarios Ad-hoc packet captures, short engineering debugs Long-term network evidence preservation for SMEs, MSPs & Branch Offices Dedicated SOC teams requiring daily threat hunting Data center backbones, financial & telecom cores
FOCUS & SYNERGY

Focusing on Core Ingestion for Maximum Synergy

SpesCap concentrates exclusively on 'lossless packet ingestion and evidence preservation'. Generated standard PCAPs feed directly into ANMAS, Wireshark, or Zeek for deep protocol parsing and threat hunting.

TCO OPTIMIZATION

Minimizing Long-Term TCO per TB

The true long-term cost of capture projects is 'Retention Days × Cost per TB'. SpesCap harnesses existing NAS drive bays and snaplen truncation, allowing organizations to achieve months of retention on modest budgets.

// 06 · Management Console

Professional Management Console

Engineered with a low-saturation palette for long hours of network administration and SOC monitoring. Displays real-time throughput, drop rate monitoring, storage pool watermarks, estimated retention hours, and time-range packet stream export.

http://nas-sec-01.corp:28088/ · SpesCap NAS Packet Capture
SpesCap NAS Full Packet Capture UI Example
Version 0.7.1
Dashboard Capture Jobs NICs Files Settings Logs
Capturing
2 / 2
fanout engine · 4 worker threads
Total Throughput
340 Mbps
66,400 pps
Max Drop Rate
0.00 %
Kernel 0 · NIC 0, alerts logged to QTS events on threshold breach
Pool Free Space
8.9 TB
Total 10.2 TB, PCAP usage 1.3 TB, auto-pruning below 200 GB
Est. Retention
90 Days
Projected from last 24-hour average traffic
Capture Jobs
Name Interface Status Throughput Packet Drop Rotation Output Directory
Core Switch Mirror eth1 Capturing 312 Mbps 60,900 pps 0.00 % Kernel 0 256 MB / 3600s Retain 8 TB /share/ZFS18_DATA/spescap/pcap/eth1-e856e3/20260825-090000
DMZ Full Traffic (snaplen 128) eth3 Capturing 28 Mbps 5,500 pps 0.00 % Kernel 0 256 MB / 3600s Retain 500 GB /share/ZFS18_DATA/spescap/pcap/eth3-b2a71c/20260825-090000
// 07 · Specifications & Sizing

System Requirements & Capacity Planning Guide

Deeply tuned for QNAP QTS and QuTS hero kernels, SpesCap delivers outstanding compatibility across NAS models. Below are system recommendations and sizing reference tables for typical enterprise traffic.

Hardware & System RequirementsSpecifications & Configuration Guidelines
Supported Architectures & OSx86_64 (Intel / AMD) or arm64 processors, compatible with QTS 5.0+ and QuTS hero 5.0+ (ZFS)
Processor (CPU)Recommended 4+ cores, multi-threaded reader engine provides high computing efficiency to fully unleash hardware potential
Memory (RAM)Basic operation 4 GB+, 16 GB+ recommended if running Arkime or OpenSearch on the same host
Network Interfaces (NIC)At least 2 ports (1 port for QTS management, remaining dedicated to Port Mirroring capture)
Storage RecommendationsCapture is a high-sequential write load, HDD pools offer the best cost-efficiency, for 10GbE full-rate capture, add an NVMe landing tier
Switch RequirementsManaged switch supporting Port Mirroring or ACL Mirroring (e.g., QNAP QSW-M series)
Security ArchitectureBuilt-in PBKDF2-HMAC-SHA256 password hashing, CSRF token protection, HttpOnly cookies, and HTTPS certificate support

Capacity Sizing Reference Table (Estimated for Typical SME Traffic)

Daily Ingress Volume Retention Period Raw PCAP Storage Required Recommended Pool Configuration
50 GB / day (Light office subnet) 30 days (1 month) ~1.5 TB 2-Bay / 4-Bay NAS (RAID 1 / 5)
200 GB / day (Medium enterprise core line) 14 days (2 weeks) ~2.8 TB 4-Bay / 6-Bay NAS (RAID 5 / 6)
500 GB / day (High-traffic server segment) 30 days (1 month) ~15.0 TB 6-Bay / 8-Bay NAS (RAID 6)
1.5 TB / day (10GbE backbone sample/full) 14 days (2 weeks) ~21.0 TB 8-Bay / 12-Bay+ Enterprise Storage Pool
※ Note 1: Encrypted traffic (e.g., TLS 1.3 / HTTPS) has high entropy, capacity planning must always use uncompressed raw volume.
※ Note 2: The most effective way to extend retention is snaplen truncation. Using snaplen 128 reduces footprint to ~1/7.5, scaling required storage down proportionally and extending retention windows.
※ Note 3: Configuring switch mirror sources to ingress-only eliminates duplicate packets and saves substantial storage prior to disk procurement.
// 08 · Compliance & Forensics

Aligning with ISO 27001 Digital Evidence & Compliance

SpesCap implements the ISO/IEC 27037 and NIST SP 800-86 digital evidence standards, delivering authentic, immutable, and fully auditable packet evidence with a verifiable chain of custody.

Control A.5.28

Digital Evidence Collection & Forensics

Completely preserves packet headers, microsecond timing, and raw payloads, archived by first-packet timestamp for authentic wire-level evidence.

Control A.8.15

Logging & Operational Audit Trails

All administrator logins, capture job actions, configuration changes, and downloads are logged to AUDIT trails and written to QTS system event logs.

Control A.8.16

Real-time Activity & Anomaly Monitoring

Dual-layer kernel and application monitoring of packet loss, combined with retention forecasting, enables proactive infrastructure monitoring.

Control A.5.34

Privacy & PII Protection Guidelines

Supports kernel-level BPF filtering to restrict capture to specific subnets and exclude sensitive services, ensuring minimum necessary data preservation.

Evidence Integrity & Chain of Custody

• Microsecond Timestamps & Unsampled Packets: Preserves authentic wire-level bytes with kernel-level microsecond timestamps.
• Atomic Renaming: In-progress files are atomically renamed upon completion, guaranteeing downstream analytics tools never read partial fragments.
• Per-File SHA-256 Integrity Manifest: Every file is hashed upon completion into a daily manifest compatible with standard sha256sum format for independent verification.
• Storage-Layer Immutability: Seamlessly pairs with QuTS hero snapshots and WORM folders to freeze and protect evidence immediately after an incident.

// 09 · Solution Synergy

Deep Synergy with the SPES Security Portfolio

SpesCap is not only a standalone capture QPKG, but also a vital piece in SPES enterprise cybersecurity ecosystem responsible for 'raw packet preservation.'

ANMAS CYBERSECURITY

Joint Defense with ANMAS Analytics Platform

PCAP files exported from SpesCap can be directly imported into the ANMAS Security System for automated analysis of malicious connections, C2 communications, anomalous protocols, and lateral movement trails, producing professional forensic reports.

SPESLOG ARCHIVING

Dual-Track Defense: SpesLog Archiving & Packet Evidence

Paired with the SpesLog Custom Log Archiving Platform, achieve 360-degree audit coverage by capturing both system text logs (Syslog, Event Log) and network wire-level PCAP packets.

ENTERPRISE QNAP

Turnkey Deployment on Custom Enterprise QNAP NAS

Pre-loadable on Custom Enterprise QNAP NAS planned by SPES. Our senior engineers handle NIC provisioning, storage pool optimization, and switch mirror configuration for a seamless out-of-the-box experience.

Ready to Build a Comprehensive Packet-Level Defense for Your Enterprise?

Our cybersecurity architecture consulting team is ready to provide QNAP NAS capture planning, switch mirror configuration, and on-premise PoC hardware validation.