PCAP Analysis
Analyze network captures:
- Connection analysis
- C2 beaconing detection
- Data exfiltration identification
- DNS tunneling detection
- Lateral movement patterns
- Protocol anomalies
- Artifact extraction
Required Context
- PCAP File: Path to capture file
- Focus: C2, exfil, lateral, general
- Time Range: If filtering needed
Tools Used
zeek, tshark, tcpdump, suricata, NetworkMiner
Example
/pcap
File: /captures/suspicious.pcap
Focus: C2 beaconing, exfiltration