This presentation was given at FloCon 2009, which took place in Scottsdale, Arizona, on January 12-15, 2009. At this event, presenters discussed many topics, including those dealing with flow for network forensics, network inventory, and incident response.