Turn any QNAP NAS with two or more NICs into a high-performance network recorder via switch port mirroring. Featuring multi-NIC capture sessions, intelligent free-space watermark cleanup, microsecond-accurate time indexing, and zero-scratchpad streaming TAR export — delivering the most cost-effective foundation for incident response and digital forensics.
Commercial NPM and NDR appliances often cost tens of thousands of dollars. SpesCap leverages native QPKG execution with QNAP's massive storage capacity and kernel-level network acceleration, providing enterprises with an accessible, high-performance packet recording appliance.
Supports simultaneous capture across multiple mirrored interfaces. Each capture job maintains independent rotation size, time limits, retention quotas, and custom Berkeley Packet Filter (BPF) expressions.
Built-in intelligent Free-space Watchdog. When storage pool free space falls below the watermark threshold (default 200 GB), SpesCap automatically purges the oldest completed PCAPs to prevent disk overflows and safeguard core NAS workloads.
Automatically brings up the capture link, enables promiscuous mode, disables GRO/LRO/TSO/GSO packet offloads, and expands the RX ring buffer to 4096, preserving raw on-the-wire packet timings and sizes.
Monitors both tcpdump application counters and kernel-level rx_dropped / rx_missed_errors. When drop thresholds are exceeded, immediate alerts are dispatched to QTS System Events and administrators.
PCAPs are named by their first-packet timestamp (cap-<timestamp>.pcap). Provides date-range querying and direct streaming TAR download without creating intermediate scratch files on the NAS.
Capture session states are persisted, automatically resuming capture upon NAS reboot. User logins, session start/stop events, parameter edits, and exports are comprehensively recorded in audit logs and QTS system events.
Strictly adheres to security best practices by physically separating the capture interface from the management interface. The capture port has no IP bound and only listens in promiscuous mode, remaining completely stealth and unreachable on monitored segments.
Managed Switch: Port Mirroring / ACL Mirroring
RX Ring 4096 · TPACKET_V3 mmap Ring Buffer (256 MB)
Rotated by Size (256MB) / Time (1hr) · Automatic Free-Space Watchdog Purge
ISO 27001 Digital Evidence · Incident Response · Threat Hunting
Designed specifically for network and cybersecurity engineers requiring long-duration monitoring without visual fatigue. Features real-time throughput metrics, packet drop counters, storage pool watermarks, retention window projections, and time-range exports.
| Session Name | Interface | Status | Throughput | Drop Rate | Rotation Rules | Output Target |
|---|---|---|---|---|---|---|
| Core-Switch-Mirror | eth1 | Stopped | 1.4 Kbps 2 pps | 0.00 % Kernel 26,215 | 49 MB / 3600s No limit | /share/ZFS18_DATA/spescap/pcap/eth1-e856e3/20260823-105900 |
SpesCap is fine-tuned for QNAP QTS and QuTS hero kernels, bundling statically compiled high-performance tcpdump binaries with TPACKET_V3 memory mmap ring buffers for maximum hardware compatibility and zero dependency friction.
| Hardware & System Specifications | Recommendations & Standards |
|---|---|
| Architectures & OS | x86_64 (Intel / AMD) or arm64 processors; compatible with QTS 5.0+ and QuTS hero 5.0+ (ZFS) |
| Processor (CPU) | Recommended Quad-core or better (1GbE line-rate capture consumes approx. 1 CPU core for kernel ring buffers & I/O flushing) |
| Memory (RAM) | Minimum 4 GB RAM; if running Arkime, OpenSearch or ANMAS on the same NAS, 16 GB+ is recommended |
| Network Interfaces | At least 2 dedicated NIC ports (1 for QTS management, 1+ for Port Mirroring capture) |
| Storage Pool (Storage) | Recommended HDD Storage Pool (Sequential write workloads are ideal for HDDs, maximizing cost-efficiency and protecting SSD flash endurance) |
| Switch Compatibility | Managed switch supporting Port Mirroring (SPAN) or ACL Mirroring (e.g., QNAP QSW-M series) |
| Security Safeguards | PBKDF2-HMAC-SHA256 password hashing (210,000 iterations), CSRF token validation, HttpOnly + SameSite=Strict cookies, HTTPS support |
| Daily Mirrored Traffic | Retention Period | Required Raw Storage | Recommended Hardware Config |
|---|---|---|---|
| 50 GB / day (Light office branch) | 30 Days (1 Month) | approx. 1.5 TB | 2-Bay / 4-Bay NAS (RAID 1 / 5) |
| 200 GB / day (Midsize enterprise core) | 14 Days (2 Weeks) | approx. 2.8 TB | 4-Bay / 6-Bay NAS (RAID 5 / 6) |
| 500 GB / day (High-density server segment) | 30 Days (1 Month) | approx. 15.0 TB | 6-Bay / 8-Bay NAS (RAID 6) |
| 1.5 TB / day (10GbE Backbone sample/full) | 14 Days (2 Weeks) | approx. 21.0 TB | 8-Bay / 12-Bay+ Enterprise Storage Pool |
During security breaches, ransomware incidents, or compliance audits, full packet recordings serve as the definitive, irrefutable technical evidence. SpesCap empowers organizations to meet regulatory and forensic readiness standards.
Preserves complete packet headers, payloads, and microsecond-level timing, providing non-repudiable forensic evidence for incident response.
All administrative logins, capture session changes, configuration adjustments, and downloads are recorded in AUDIT logs and QTS system events.
Continuous monitoring of packet drop counts and retention depth provides proactive observability over security capture infrastructure.
Supports ACL Mirroring to restrict packet capture scope, combined with time-restricted retention and role-based access control.
SpesCap is not only a standalone network recorder, but also the foundational packet preservation layer within the comprehensive SPES enterprise security ecosystem.
PCAPs exported from SpesCap seamlessly ingest into the ANMAS Security Platform, automating malware connection discovery, C2 beacon analysis, protocol anomaly detection, and forensic reporting.
Pair with the SpesLog Custom Log Archive Platform to maintain synchronized system text logs (Syslog, Windows Event) and wire-level PCAPs for complete 360° audit visibility.
Available pre-installed on SPES-customized Enterprise QNAP NAS solutions, complete with pre-configured NIC preparation, storage pool tuning, and switch mirroring setup.
Our security architecture consultants are ready to assist with QNAP NAS capture planning, switch mirroring configuration, and POC verification.