Analyzing Network Traffic

Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection, TLS/JA3 fingerprinting, HTTP and file carving, exfiltration hunting, and IOC handoff. Use when a `.pcap` or `.pcapng` capture lands on your desk, when a suspected C2 beacon needs confirming, when there is data exfiltration to investigate, when malware network behaviour must be characterized from what it emitted, when a Zeek or Suricata alert needs running down, or when DNS tunneling or unusual TLS is suspected.

trilwu 39dd1ec 20.8 KB Updated

File contents

trilwu/secskills/tree/main/secskills-defense/skills/analyzing-network-traffic commit 39dd1ec206

Frequently asked questions

npx skillmds add trilwu/analyzing-network-traffic