What More Do You Want?
packet sniffers
disk management
sessionization
logging/monitoring utilities
Intrusion Detection Systems
post hoc rather than a priori; handling of the unfamiliar
completeness of record