Skip to main content
performing-network-forensics-with-wireshark Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control communications. Use when analyzing captured traffic from a security incident, reconstructing data exfiltration, or finding network indicators of compromise during malware analysis.
Ir a la instalación Skills Marketplace Descubre y explora habilidades de IA creadas por la comunidad.
Instalar con Codex o Claude Copia este prompt, pégalo en Codex, Claude u otro asistente, y deja que revise la página de la skill y la instale por ti.
Copiar promptMostrar detalles del prompt Un comando directo omite el prompt de revisión. Revisa el origen antes de ejecutarlo.
npx skills add https://github.com/mukul975/Anthropic-Cybersecurity-Skills --skill performing-network-forensics-with-wiresharkEl comando permanece en una sola línea. Desplázate horizontalmente para revisarlo antes de copiarlo.
¿Prefieres una copia local? Descarga los archivos que SkillsMP tiene disponibles ahora.
Descargar Zip Descargando... Más de este repositorio abusing-dpapi-for-credential-access Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decryption via the DPAPI backup key. Use during authorized red-team credential-access engagements after gaining a foothold or when triaging DPAPI blobs pulled from a host.
abusing-shadow-credentials-for-privesc Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or Certipy, then authenticate via PKINIT to recover the target's NT hash without a password reset. Use when BloodHound shows GenericWrite/GenericAll/AddKeyCredentialLink over a target, as a stealthier alternative to ForceChangePassword, during authorized red-team engagements.
acquiring-disk-image-with-dd-and-dcfldd Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification (MD5/SHA) during acquisition. Use when imaging a suspect drive, USB device, or memory card for investigation, preserving volatile disk evidence during incident response, or producing a verified copy for legal or law-enforcement proceedings before any destructive analysis.
Explorador de archivos
4 archivos Ocupaciones relacionadas SOC
Basado en la clasificación ocupacional SOC
name performing-network-forensics-with-wireshark description Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control communications. Use when analyzing captured traffic from a security incident, reconstructing data exfiltration, or finding network indicators of compromise during malware analysis. domain cybersecurity subdomain digital-forensics tags ["forensics","network-forensics","wireshark","pcap","packet-analysis","traffic-analysis"] version 1.0 author mahipal license Apache-2.0 nist_csf ["RS.AN-03","DE.AE-02","RS.MA-01"] mitre_attack ["T1005","T1074","T1119","T1070","T1059"]
Performing Network Forensics with Wireshark
When to Use
When analyzing captured network traffic (PCAP files) from a security incident
For identifying command-and-control (C2) communications in captured traffic
When reconstructing data exfiltration activities from packet captures
During malware analysis to identify network indicators of compromise
For extracting files, credentials, and artifacts transferred over the network
Prerequisites
Wireshark or tshark installed for packet analysis
PCAP/PCAPNG files from network captures (tcpdump, Wireshark, network TAP)
NetworkMiner for automated artifact extraction
Sufficient RAM for large capture files (1GB+ PCAPs need 8GB+ RAM)
Understanding of TCP/IP, HTTP, DNS, TLS protocols
GeoIP databases for IP geolocation
Workflow
Step 1: Prepare and Validate the Capture File
sudo apt-get install wireshark tshark
capinfos /cases/case-2024-001/network/capture.pcap
sha256sum /cases/case-2024-001/network/capture.pcap \
> /cases/case-2024-001/network/pcap_hash.txt
tshark -r /cases/case-2024-001/network/capture.pcap -q -z io,phs
Step 2: Filter and Identify Suspicious Traffic
tshark -r /cases/case-2024-001/network/capture.pcap -q -z conv,tcp
tshark -r /cases/case-2024-001/network/capture.pcap -q -z endpoints,ip \
| -t$ -k3 -rn | -20
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y \
-T fields -e frame.time -e ip.src -e dns.qry.name \
> /cases/case-2024-001/analysis/dns_queries.txt
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y \
-T fields -e frame.time -e ip.src -e dns.qry.name \
> /cases/case-2024-001/analysis/suspicious_dns.txt
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y \
-T fields -e frame.time -e ip.src -e ip.dst -e http.request.method \
-e http.host -e http.request.uri -e http.user_agent \
> /cases/case-2024-001/analysis/http_requests.txt
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y \
-T fields -e frame.time -e ip.src -e ip.dst -e tcp.dstport \
> /cases/case-2024-001/analysis/suspicious_ports.txt
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y \
-T fields -e frame.time_epoch \
> /tmp/beacon_times.txt
sort
'\t'
head
"dns.qr == 0"
"dns.qr == 0 && dns.qry.name matches \"[a-z0-9]{30,}\""
"http.request"
"tcp.dstport == 4444 || tcp.dstport == 8080 || tcp.dstport == 1337 || tcp.dstport == 6667"
"ip.dst == 185.0.0.1"
Step 3: Extract Files and Objects from Traffic
tshark -r /cases/case-2024-001/network/capture.pcap \
--export-objects http,/cases/case-2024-001/analysis/http_objects/
tshark -r /cases/case-2024-001/network/capture.pcap \
--export-objects smb,/cases/case-2024-001/analysis/smb_objects/
tshark -r /cases/case-2024-001/network/capture.pcap \
--export-objects dicom,/cases/case-2024-001/analysis/dicom_objects/
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y "ftp-data" \
-T fields -e ftp-data.data \
--export-objects ftp-data,/cases/case-2024-001/analysis/ftp_objects/
find /cases/case-2024-001/analysis/http_objects/ -type f -exec sha256sum {} \; \
> /cases/case-2024-001/analysis/extracted_file_hashes.txt
while read hash filepath; do
echo "Checking $filepath ($hash )"
curl -s "https://www.virustotal.com/api/v3/files/$hash " \
-H "x-apikey: YOUR_API_KEY" | python3 -c "
import json,sys
data=json.load(sys.stdin)
if 'data' in data:
stats=data['data']['attributes']['last_analysis_stats']
print(f' Malicious: {stats[\"malicious\"]}, Undetected: {stats[\"undetected\"]}')
else:
print(' Not found on VT')
"
done < /cases/case-2024-001/analysis/extracted_file_hashes.txt
Step 4: Reconstruct TCP Streams and Sessions
tshark -r /cases/case-2024-001/network/capture.pcap \
-q -z "follow,tcp,ascii,42" \
> /cases/case-2024-001/analysis/stream_42.txt
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y "http && ip.addr == 185.0.0.1" \
-T fields -e frame.time -e http.request.method -e http.host \
-e http.request.uri -e http.response.code -e http.content_length \
> /cases/case-2024-001/analysis/suspicious_http.txt
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y "tls.handshake.type == 11" \
-T fields -e ip.dst -e tls.handshake.certificate \
> /cases/case-2024-001/analysis/tls_certs.txt
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y "tls.handshake.extensions_server_name" \
-T fields -e frame.time -e ip.src -e ip.dst \
-e tls.handshake.extensions_server_name \
> /cases/case-2024-001/analysis/tls_sni.txt
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y "ftp.request.command == \"USER\" || ftp.request.command == \"PASS\"" \
-T fields -e frame.time -e ip.src -e ftp.request.command -e ftp.request.arg
tshark -r /cases/case-2024-001/network/capture.pcap \
-Y "http.authorization" \
-T fields -e frame.time -e ip.src -e http.host -e http.authorization
Step 5: Use NetworkMiner for Automated Analysis
sudo apt-get install mono-complete
wget https://www.netresec.com/?download=NetworkMiner -O NetworkMiner.zip
unzip NetworkMiner.zip -d /opt/NetworkMiner/
mono /opt/NetworkMiner/NetworkMiner.exe /cases/case-2024-001/network/capture.pcap
Step 6: Generate Network Forensics Report
cat << 'EOF' > /cases/case-2024-001/analysis/network_forensics_report.txt
NETWORK FORENSICS ANALYSIS REPORT
===================================
Case: 2024-001
Capture File: capture.pcap (856 MB, 1,245,678 packets)
Capture Period: 2024-01-15 14:00 to 15:00 UTC
Analyst: [Examiner Name]
TRAFFIC OVERVIEW:
Total packets: 1,245,678
Unique source IPs: 45
Unique destination IPs: 234
Protocols: TCP (78%), UDP (18%), ICMP (2%), Other (2%)
C2 COMMUNICATION:
Destination: 185.0.0.1:443
Beaconing interval: ~60 seconds
Total connections: 58
Data transferred: 4.2 MB outbound, 12.3 MB inbound
TLS SNI: update-service.malware-c2.com
EXFILTRATION:
Method: HTTPS POST to 185.0.0.1
Volume: 4.2 MB over 45 minutes
Files: 3 ZIP archives extracted from HTTP objects
DNS TUNNELING:
Suspicious queries to: data.evil-dns.com
Average subdomain length: 45 characters
Query count: 1,234 (normal baseline: 50)
EOF
Key Concepts Concept Description PCAP/PCAPNG Packet capture file formats storing raw network traffic TCP stream Complete bidirectional communication between two endpoints Deep packet inspection Analysis of packet payload content beyond header information Beaconing Regular-interval callbacks from malware to C2 servers DNS tunneling Encoding data within DNS queries for covert exfiltration TLS/SNI Server Name Indication revealing the target hostname in encrypted connections Network flow Summary of communication between endpoints (IPs, ports, bytes, duration) Protocol hierarchy Statistical breakdown of protocols present in a capture
Tools & Systems Tool Purpose Wireshark GUI-based packet analyzer with deep protocol dissection tshark Command-line version of Wireshark for scripted analysis NetworkMiner Automated network forensic analysis and file extraction tcpdump Command-line packet capture utility zeek (Bro) Network security monitor generating structured connection logs ngrep Network grep for pattern matching in packet content capinfos PCAP file statistics and metadata utility mergecap Merge multiple PCAP files into a single capture
Common Scenarios Scenario 1: Malware C2 Communication Analysis
Load PCAP in Wireshark, identify beaconing patterns to external IPs, examine TLS certificates for self-signed or unusual issuers, extract HTTP POST data containing encoded commands, correlate C2 IPs with threat intelligence feeds.
Scenario 2: Data Exfiltration Detection
Analyze traffic statistics for unusually large outbound transfers, examine DNS query lengths for DNS tunneling indicators, track FTP and HTTP file uploads to external servers, reconstruct exfiltrated files from packet data.
Scenario 3: Lateral Movement in Enterprise Network
Filter for SMB, RDP, WMI, and PSExec traffic between internal hosts, identify credential usage patterns across multiple systems, trace the propagation path of the attacker through the network, correlate with Windows Event Log authentication events.
Scenario 4: Web Application Attack Reconstruction
Filter HTTP traffic to the web server, identify SQL injection, XSS, and directory traversal attempts, follow the TCP stream of the successful exploit, extract uploaded webshells or payloads, document the attack chain for the incident report.
Output Format Network Forensics Summary:
Capture: capture.pcap
Duration: 1 hour (14:00-15:00 UTC, 2024-01-15)
Packets: 1,245,678 | Size: 856 MB
Top Suspicious Connections:
192.168.1.50 -> 185.0.0.1:443 (C2, 58 connections, 4.2MB out)
192.168.1.50 -> 10.0.0.25:445 (SMB lateral movement)
192.168.1.50 -> 10.0.0.30:3389 (RDP lateral movement)
Extracted Artifacts:
Files: 23 (3 malicious per VT)
Credentials: 2 plaintext FTP logins
DNS Queries: 1,234 suspicious (possible tunneling)
TLS Certs: 5 self-signed certificates
IOCs Identified:
IPs: 185.0.0.1, 203.0.113.50
Domains: update-service.malware-c2.com, data.evil-dns.com
Hashes: 3 file hashes flagged as malware