FULL PACKET CAPTURE · QNAP QPKG · ISO 27001 EVIDENCE

SpesCap Full Packet Capture for QNAP NAS
Transforming Enterprise NAS into a Resilient Network Recorder

Turn any QNAP NAS with two or more NICs into a high-performance network recorder via switch port mirroring. Featuring multi-NIC capture sessions, intelligent free-space watermark cleanup, microsecond-accurate time indexing, and zero-scratchpad streaming TAR export — delivering the most cost-effective foundation for incident response and digital forensics.

// 01 — Core Highlights

Engineered for Reliability & Full Packet Forensics

Commercial NPM and NDR appliances often cost tens of thousands of dollars. SpesCap leverages native QPKG execution with QNAP's massive storage capacity and kernel-level network acceleration, providing enterprises with an accessible, high-performance packet recording appliance.

// 01

Multi-NIC Capture & Independent BPF

Supports simultaneous capture across multiple mirrored interfaces. Each capture job maintains independent rotation size, time limits, retention quotas, and custom Berkeley Packet Filter (BPF) expressions.

// 02

Free-Space Watchdog & Safe Retention

Built-in intelligent Free-space Watchdog. When storage pool free space falls below the watermark threshold (default 200 GB), SpesCap automatically purges the oldest completed PCAPs to prevent disk overflows and safeguard core NAS workloads.

// 03

One-Click Zero-Offload Interface Prep

Automatically brings up the capture link, enables promiscuous mode, disables GRO/LRO/TSO/GSO packet offloads, and expands the RX ring buffer to 4096, preserving raw on-the-wire packet timings and sizes.

// 04

Dual Drop-Rate Monitoring & QTS Alerts

Monitors both tcpdump application counters and kernel-level rx_dropped / rx_missed_errors. When drop thresholds are exceeded, immediate alerts are dispatched to QTS System Events and administrators.

// 05

Timestamp Indexing & Streaming Export

PCAPs are named by their first-packet timestamp (cap-<timestamp>.pcap). Provides date-range querying and direct streaming TAR download without creating intermediate scratch files on the NAS.

// 06

Auto-Recovery on Boot & Full Audit Trail

Capture session states are persisted, automatically resuming capture upon NAS reboot. User logins, session start/stop events, parameter edits, and exports are comprehensively recorded in audit logs and QTS system events.

// 02 — Network Topology

Out-of-Band Topology & Capture Architecture

Strictly adheres to security best practices by physically separating the capture interface from the management interface. The capture port has no IP bound and only listens in promiscuous mode, remaining completely stealth and unreachable on monitored segments.

  • Out-of-Band Mirroring (Zero Production Impact): Core switches mirror monitored traffic via Port Mirroring or ACL rules into the NAS capture port, having zero latency or throughput impact on production flows.
  • Sequential Write Optimization & HDD Preference: Packet recording is an append-heavy, sequential write load. SpesCap harnesses AF_PACKET Ring Buffers and system page caches for batch flushing, making economical HDD storage pools ideal while preserving costly SSD write endurance.
  • Versatile Scheduling Modes: Offers 24/7 Continuous Capture, Daily Recurring Windows (e.g., business hours or high-risk night shifts), and One-time Timed Capture (auto-stopping after a targeted 4-hour window), balancing retention depth with capacity costs.
  • Seamless Downstream Ecosystem Integration: Generates clean, standard PCAP directories directly ingestible by the ANMAS Cybersecurity Platform, Wireshark, or mounted into Container Station for Arkime / Zeek offline indexing.
SpesCap Topology & Workflow
Core Network

Enterprise Switch / Router Traffic

Managed Switch: Port Mirroring / ACL Mirroring

Dedicated Capture NIC (eth1)

NAS Capture Port (No IP · Promiscuous · Zero Offload)

RX Ring 4096 · TPACKET_V3 mmap Ring Buffer (256 MB)

Storage Pool (HDD)

Large-Capacity Storage Pool / ZFS Dataset

Rotated by Size (256MB) / Time (1hr) · Automatic Free-Space Watchdog Purge

Security Analytics & Forensics

ANMAS / Wireshark / Arkime / Zeek

ISO 27001 Digital Evidence · Incident Response · Threat Hunting

// 03 — Morandi Management Console

Morandi Palette Purpose-Built Interface

Designed specifically for network and cybersecurity engineers requiring long-duration monitoring without visual fatigue. Features real-time throughput metrics, packet drop counters, storage pool watermarks, retention window projections, and time-range exports.

http://nas-sec-01.corp:28088/ — SpesCap NAS Packet Capture
SpesCap NAS Full Packet Capture
v0.4.0
Dashboard Sessions Interfaces Files Settings Logs
Active Sessions
0 / 1
No capture session running
Aggregate Rate
0 bps
0 pps
Max Drop Rate
0.00 %
Alerts logged to QTS events
Storage Pool Free
10.2 TB
Total 10.2 TB, PCAPs 6.8 GB, auto-purge below 200 GB
Retention Window
-
Awaiting active stream
Capture Sessions
Session Name Interface Status Throughput Drop Rate Rotation Rules Output Target
Core-Switch-Mirror eth1 Stopped 1.4 Kbps 2 pps 0.00 % Kernel 26,215 49 MB / 3600s No limit /share/ZFS18_DATA/spescap/pcap/eth1-e856e3/20260823-105900
// 04 — Specifications & Sizing

Hardware Requirements & Sizing Guide

SpesCap is fine-tuned for QNAP QTS and QuTS hero kernels, bundling statically compiled high-performance tcpdump binaries with TPACKET_V3 memory mmap ring buffers for maximum hardware compatibility and zero dependency friction.

Hardware & System SpecificationsRecommendations & Standards
Architectures & OSx86_64 (Intel / AMD) or arm64 processors; compatible with QTS 5.0+ and QuTS hero 5.0+ (ZFS)
Processor (CPU)Recommended Quad-core or better (1GbE line-rate capture consumes approx. 1 CPU core for kernel ring buffers & I/O flushing)
Memory (RAM)Minimum 4 GB RAM; if running Arkime, OpenSearch or ANMAS on the same NAS, 16 GB+ is recommended
Network InterfacesAt least 2 dedicated NIC ports (1 for QTS management, 1+ for Port Mirroring capture)
Storage Pool (Storage)Recommended HDD Storage Pool (Sequential write workloads are ideal for HDDs, maximizing cost-efficiency and protecting SSD flash endurance)
Switch CompatibilityManaged switch supporting Port Mirroring (SPAN) or ACL Mirroring (e.g., QNAP QSW-M series)
Security SafeguardsPBKDF2-HMAC-SHA256 password hashing (210,000 iterations), CSRF token validation, HttpOnly + SameSite=Strict cookies, HTTPS support

Storage Capacity Planning Reference

Daily Mirrored Traffic Retention Period Required Raw Storage Recommended Hardware Config
50 GB / day (Light office branch) 30 Days (1 Month) approx. 1.5 TB 2-Bay / 4-Bay NAS (RAID 1 / 5)
200 GB / day (Midsize enterprise core) 14 Days (2 Weeks) approx. 2.8 TB 4-Bay / 6-Bay NAS (RAID 5 / 6)
500 GB / day (High-density server segment) 30 Days (1 Month) approx. 15.0 TB 6-Bay / 8-Bay NAS (RAID 6)
1.5 TB / day (10GbE Backbone sample/full) 14 Days (2 Weeks) approx. 21.0 TB 8-Bay / 12-Bay+ Enterprise Storage Pool
* Note: Encrypted network traffic (TLS 1.3 / HTTPS) exhibits high entropy, rendering filesystem compression largely ineffective. Plan capacity sizing based on uncompressed volumes.
// 05 — Compliance & Forensics

Aligning with ISO 27001 & Digital Forensics

During security breaches, ransomware incidents, or compliance audits, full packet recordings serve as the definitive, irrefutable technical evidence. SpesCap empowers organizations to meet regulatory and forensic readiness standards.

Control A.5.28

Evidence Collection & Forensics

Preserves complete packet headers, payloads, and microsecond-level timing, providing non-repudiable forensic evidence for incident response.

Control A.8.15

Logging & Operational Audit

All administrative logins, capture session changes, configuration adjustments, and downloads are recorded in AUDIT logs and QTS system events.

Control A.8.16

Activity & Infrastructure Monitoring

Continuous monitoring of packet drop counts and retention depth provides proactive observability over security capture infrastructure.

Control A.5.33

Privacy & Data Protection

Supports ACL Mirroring to restrict packet capture scope, combined with time-restricted retention and role-based access control.

// 06 — Solution Synergy

Synergy with SPES Security Portfolio

SpesCap is not only a standalone network recorder, but also the foundational packet preservation layer within the comprehensive SPES enterprise security ecosystem.

ANMAS CYBERSECURITY

ANMAS Security Analytics Joint Solution

PCAPs exported from SpesCap seamlessly ingest into the ANMAS Security Platform, automating malware connection discovery, C2 beacon analysis, protocol anomaly detection, and forensic reporting.

SPESLOG ARCHIVING

Dual-Track: SpesLog Archiving + Packet Preservation

Pair with the SpesLog Custom Log Archive Platform to maintain synchronized system text logs (Syslog, Windows Event) and wire-level PCAPs for complete 360° audit visibility.

ENTERPRISE QNAP

Turnkey Custom QNAP Deployment

Available pre-installed on SPES-customized Enterprise QNAP NAS solutions, complete with pre-configured NIC preparation, storage pool tuning, and switch mirroring setup.

Ready to build packet-level visibility and forensic readiness?

Our security architecture consultants are ready to assist with QNAP NAS capture planning, switch mirroring configuration, and POC verification.