Skill 详情
analyzing-network-traffic-with-wireshark
Relevant network-security analysis specialty, but narrow.
使用前先检查
自动化审核只检查相关性,不代表安全审查或推荐。使用前请阅读来源中的说明。
SKILL.md
这段内容是审核时保存的快照。外部来源才是完整且最新的版本。
--- name: analyzing-network-traffic-with-wireshark description: 'Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments. ' domain: cybersecurity subdomain: network-security tags: - network-security - wireshark - packet-analysis - traffic-analysis - pcap version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - PR.IR-01 - DE.CM-01 - ID.AM-03 - PR.DS-02 mitre_attack: - T1040 - T1071 - T1557 - T1046 --- # Analyzing Network Traffic with Wireshark ## When to Use - Investigating suspected network intrusions by examining packet-level evidence of command-and-control traffic, data exfiltration, or lateral movement - Diagnosing network performance issues such as retransmissions, fragmentation, or DNS resolution failures - Analyzing malware communication patterns by capturing traffic from sandboxed or isolated hosts - Validating firewall and IDS rules by confirming what traffic is actually traversing network segments - Extracting files, credentials, or indicators of compromise from captured network sessions **Do not use** to capture traffic on networks without authorization, to intercept private communications without legal authority, or as a substitute for full-featured SIEM platforms in production monitoring. ## Prerequisites - Wireshark 4.0+ and tshark command-line utility installed - Root/sudo privileges or membership in the `wireshark` group for live packet capture - Network interface access (physical NIC, span port, or network tap) to the monitored segment - Sufficient disk space for packet capture files (estimate 1 GB per minute on busy gigabit links) - Familiarity with TCP/IP protocols, HTTP, DNS, TLS, and SMB at the packet level ## Workflow ### Step 1: Configure Capture Environment Set up the capture interface and filters to target relevant traffic: ```bash # List available interfaces tshark -D # Start capture on eth0 with a capture filter to limit scope tshark -i eth0 -f "host 10.10.5.23 and (port 80 or port 443 or port 445)" -w /tmp/capture.pcapng # Capture with ring buffer to manage disk usage (10 files, 100MB each) tshark -i eth0 -b filesize:102400 -b files:10 -w /tmp/rolling_capture.pcapng # Capture on multiple interfaces simultaneously tshark -i eth0 -i eth1 -w /tmp/multi_interface.pcapng ``` For Wireshark GUI, set capture filter in the Capture Options dialog before starting. ### Step 2: Apply Display Filters for Targeted Analysis ```bash # Filter HTTP traffic containing suspicious user agents tshark -r capture.pcapng -Y "http.user_agent contains \"curl\" or http.user_agent contains \"Wget\"" # Find DNS queries to suspicious TLDs tshark -r capture.pcapng -Y "dns.qry.name contains \".xyz\" or dns.qry.name contains \".top\" or dns.qry.name contains \".tk\"" # Identify TCP retransmissions indicating network issues tshark -r capture.pcapng -Y "tcp.analysis.retransmission" # Filter SMB traffic for lateral movement detection tshark -r capture.pcapng -Y "smb2.cmd == 5 or smb2.cmd == 3" -T fields -e ip.src -e ip.dst -e smb2.filename # Find cleartext credential transmission tshark -r capture.pcapng -Y "ftp.request.command == \"PASS\" or http.authbasic" # Detect beaconing patterns (regular interval connections) tshark -r capture.pcapng -Y "ip.dst == 203.0.113.50" -T fields -e frame.time_relative -e ip.src -e tcp.dstport ``` ### Step 3: Protocol-Specific Deep Analysis ```bash # Follow a TCP stream to reconstruct a conversation tshark -r capture.pcapng -q -z follow,tcp,ascii,0 # Analyze HTTP request/response pairs tshark -r capture.pcapng -Y "http" -T fields -e frame.time -e ip.src -e ip.dst -e http.request.method -e http.request.uri -e http.response.code # Extract DNS query/response statistics tshark -r capture.pcapng -q -z dns,tree # Analyze TLS handshakes for weak cipher suites tshark -r capture.pcapng -Y "tls.handshake.typ在 GitHub 阅读完整来源 (打开外部页面)