2021年12月30日星期四

How to safe analysis the milware in wireshark?

Most samlple cache in windows host , so if you use Kali or other linux , you can avoid the risk of infected.



How to write a forensic report by wireshark?

The report contain :

1.Date and approximate time of the infrction 

2.The infected computer`s IP

3.The infected compouter `s Mac address

4.Host name

5.Which email the employee opened



2021年12月27日星期一

How to add a filter into a button in wireshark?

 Step1.click + in right top menu and fill in label by "Basic"




Step2.click "確定“

How to setup a environment for inspection by wireshark?

Step1.Open wireshark

Step2.Edit / Preference



Step3.click check box of Name Resolution 




Step3.right click on the column (for ex. info) and click column preference 




Step4.Note that the Dest addr ( unresolved and resolved) and the list of column



http.request or ssl.handshake.type == 1 or tcp.flags eq 0x0002 and !udp.port eq 1900

2021年12月26日星期日

How wireshark can done in a APT situation ?

General Advice on Wireshark Examples

  • Pay attention to what Wireshark columns are used. They are not all the same, nor ordered the same.
  • These are very “clean” captures. Even without display filters, there is little to no other traffic.
  • Some things aren’t what they seem; for example, why are ICMP requests left unreplied? Much investigating needs to be done in malware analysis.
  • Much more can be gleaned from a capture; for example, trying other columns or opening Analyze ⇨ Expert Information



【請註冊帳號試用】資安職能地圖

【請註冊帳號試用】 https://eapdb.com/cyberskill/ 測試帳號: TestHR@hr.com 測試密碼: TestHR 這份文件詳細介紹了新心資安科技所開發的「資安職能地圖」系統,旨在協助企業有效盤點與管理內部的資安人才實力。該平台採用零信任原則,人...