On 06/03/14 16:31, Chris wrote: > Hi Scott, > > On 03/04/2014 10:17 AM, Scott Ferguson wrote: >> I route suspect boxes through a transparent proxy to see if there are >> channels in use that shouldn't be. > > are you using port mirroring or any special software? iptables logging? > > - Chris > > virtualbox, ipcop and wireshark Kind regards