2021年12月26日星期日

How wireshark can done in a APT situation ?

General Advice on Wireshark Examples

  • Pay attention to what Wireshark columns are used. They are not all the same, nor ordered the same.
  • These are very “clean” captures. Even without display filters, there is little to no other traffic.
  • Some things aren’t what they seem; for example, why are ICMP requests left unreplied? Much investigating needs to be done in malware analysis.
  • Much more can be gleaned from a capture; for example, trying other columns or opening Analyze ⇨ Expert Information



沒有留言:

發佈留言

歡迎留下寶貴意見

觀念啟蒙

「觀念啟蒙」: 1. 荒謬的責任轉嫁:把刑事犯罪包裝成行政處罰 現行歐盟 GDPR、台灣個資法與日本 APPI 的最大盲點,就在於「將應屬於公共權力的刑事追訴責任,強行轉嫁給受害的企業主」。 正如您所說的犀利譬喻:小偷打破了店家的保險箱,搶走了客人的寄放物。國家不想花心力去抓這個...