Network Forensic Analysis
Analyzing packet captures and network evidence for security investigations — from capture methodology through protocol analysis, timeline reconstruction, and evidence preservation.
When to Use
- Investigating a security incident from network evidence
- Analyzing pcap files for indicators of compromise
- Reconstructing network sessions and timelines
- Preparing network evidence for legal proceedings
Forensics Process
FORENSICS_PHASES = {
'preservation': 'Capture and hash evidence, maintain chain of custody',
'triage': 'Identify suspicious sessions, IPs, ports, and protocols',
'analysis': 'Deep packet inspection, protocol decode, file extraction',
'correlation': 'Correlate with logs, endpoints, and threat intel',
}
Common Pitfalls
- Truncated captures — missing packet payloads lose evidence
- No chain of custody — evidence integrity must be provable
- Analyzing originals — always work from copies, not original evidence
- Missing encrypted traffic — focus on metadata, DNS, TLS handshakes
- No timeline — timestamps need synchronized clocks (NTP)
Verification Checklist
- Full packet captures with timestamps
- Cryptographic hashes of evidence files
- Chain of custody documented
- Timeline reconstructed from multiple sources
- Protocol analysis for HTTP, DNS, TLS covering attack vector