nBox Recorder is a network traffic disk recorder application. With nBox Recorder you can capture full-sized network packets at gigabit rate from a live network interface and write them into files. It has been designed and developed mainly because most network security systems rely on capturing all packets (headers and payload), since any packets may have been responsible for the attack or could contain the problems that we are trying to find.
nBox Recorder uses the industry standard PCAP file format to dump packets into files so the resulting output can be easily integrated with existing third party or even open-source analysis tools like ntopng, Wireshark, Suricata, Zeek, Snort.
nBox Recorder can be effectively used to perform:
- Off-line network packets analysis by feeding a specialized tool (such as snort or ntopng)
- Reconstruct specific communication flows or network activities
- Reproduce the previous captured traffic to a different network

Open Source Technologies
nBox relies on Open Source high-performance technologies for capturing and processing traffic, including our PF_RING framework, delivering Line-Rate packet capture up to 100 Gbit/s. nBox Recorder uses the industry standard PCAP file format to dump packets into files, so the resulting output can be easily integrated with existing third party and Open Source analysis tools like ntopng, Wireshark or Snort.


100% Visibility, Nanosecond Precision
nBox provides 100% visibility with sustained Line-Rate loss-less packet capture, which is a requirement in network security. Loss-less packet capture up to 100 Gbit, combined with nanosecond accuracy, delivers the best visibility in any condition. Full packets are stored, indexed and organized in a timeline to enable on-demand retrieval, specifying time interval and BPF criteria to fully reconstruct past events.
High Performance, Small Form Factor
Our nBox Recorder and NetFlow appliances are able to process up to 100 Gbit and fit in 1U form factor rackmount (depending on the required data retention). Up to 24 disks in 2U form factor, or longer-term storage on modular systems to scale as needed.

at a glance
Key Features
- High performance full packet capture to disk with no packet loss
- Based on n2disk, a 100 Gbit Network traffic recording software with indexing capabilities
- BPF filters support: you can specify any filters you want to filter out the unwanted network packets from the dumping process
- Conditional dump: save packets on disk based on traffic conditions (e.g. when traffic is above threshold X) and time of the day
- Detailed dump statistics
- Ability to reproduce dumped files onto a physical interface, or using tools such as ntopng and nProbe
Specifications
Tech Specs
- Linux
- Web GUI available through any HTML5-ready browser
- TLS/HTTPS support
- nboxui
- n2disk
- 19″ Rack-mount
- Dell-based systems include up to 3 years on-site hardware guarantee
models
Choose Your Model
Different models have different capacity and performance.
- Web-based UI for recording/extraction
- n2disk included
- PF_RING ZC drivers included
- Form factor: 1 Unit
- Monitoring port options:
- 2x 10 Gbit Intel ZC SFP+
- 2 x 10 Gbit/s (2 x 14.88 Mpps)
- 8 x 0.96 TB
- Web-based UI for recording/extraction
- n2disk included
- PF_RING ZC drivers included
- Form factor: 1 Unit
- Monitoring port options:
- 2 x 40 Gbit FPGA-based adapter with Hardware Timestamps (QSFP28)
- 2 x 40 Gbit/s (with FPGA)
- 8 x 1.6 TB
- Web-based UI for recording/extraction
- n2disk included
- PF_RING ZC drivers included
- Form factor: 2 Units
- Monitoring port options:
- 1 x 100 Gbit FPGA-based adapter with Hardware Timestamps (QSFP28)
- 100 Gbit/s line rate (with FPGA)
- 8 x 1.6 TB