analyzing-network-traffic-of-malware - Analyzing Network Traffic of Malware
Analyzes malware network traffic to identify C2 protocols, exfiltration channels, payload downloads, and lateral movement using Wireshark, Zeek, and Suricata.
Tags
Updated: 2026-09-24Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Analyze PCAP traffic summary statistics
- Inspect DNS activity and DGAs
- Analyze HTTP and HTTPS C2
- Detect network C2 beaconing patterns
- Generate Suricata network detection rules
- Extract transferred files from traffic
Inputs
- Malware PCAP capture files
- Suricata ET rulesets
Outputs
- Suricata custom detection rule files
- Extracted payload files and HTTP objects
- Zeek structured metadata log files
- Traffic analysis and alert logs
Requirements
- Wireshark and tshark 4.x
- Zeek network analysis framework
- Suricata IDS with ET rulesets
- NetworkMiner forensic analysis tool
- Python 3.8+ with scapy and dpkt
