performing-network-forensics-with-wireshark - Performing Network Forensics with Wireshark
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
Tags
Updated: 2026-09-24Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Analyze captured network traffic
- Identify command and control communications
- Reconstruct data exfiltration activities
- Extract transferred files and credentials
- Filter and identify suspicious traffic
- Reconstruct TCP streams and sessions
- Generate network forensics reports
Inputs
- PCAP or PCAPNG capture files
- GeoIP databases
- VirusTotal API key
Outputs
- Extracted files and objects
- Traffic analysis text files
- File integrity hash logs
- Network forensics analysis report
Requirements
- Wireshark or tshark
- NetworkMiner
- Mono runtime environment
- Sufficient RAM for large captures
