صرف ڏيکارڻ
0:09
S… Speaker 2 (2026-04-13 00-06-31)
that can greatly assist with the kind
0:13
S… Speaker 2 (2026-04-13 00-06-31)
of initial analysis of captured network
0:17
S… Speaker 2 (2026-04-13 00-06-31)
data before going into a deep dive with a
0:21
S… Speaker 2 (2026-04-13 00-06-31)
tool like Wireshark.
0:23
S… Speaker 2 (2026-04-13 00-06-31)
And I want to look at Network Miner in this video.
0:27
S… Speaker 2 (2026-04-13 00-06-31)
Now, I use Network Miner here because it is available on
0:31
S… Speaker 1 (2026-04-13 00-06-31)
multiple different platforms.
0:33
S… Speaker 2 (2026-04-13 00-06-31)
It's primarily developed for Windows.
0:37
S… Speaker 2 (2026-04-13 00-06-31)
but does work in other operating systems as well.
0:40
S… Speaker 2 (2026-04-13 00-06-31)
You can see here I've got it running on a Linux machine.
0:44
S… Speaker 2 (2026-04-13 00-06-31)
And it is a good tool to get a good summary of
0:48
S… Speaker 2 (2026-04-13 00-06-31)
the network traffic that's already in an existing capture file.
0:52
S… Speaker 1 (2026-04-13 00-06-31)
It doesn't really do,
0:53
S… Speaker 2 (2026-04-13 00-06-31)
it captures on its own.
0:55
S… Speaker 1 (2026-04-13 00-06-31)
It is technically possible,
0:57
S… Speaker 2 (2026-04-13 00-06-31)
but it is definitely not recommended.
0:59
S… Speaker 2 (2026-04-13 00-06-31)
It's better to use a...
1:01
S… Speaker 2 (2026-04-13 00-06-31)
specialized program that's meant for that,
1:03
S… Speaker 2 (2026-04-13 00-06-31)
like Wireshark or TCP dump or T -Shark or something like that to
1:08
S… Speaker 2 (2026-04-13 00-06-31)
capture network data.
1:10
S… Speaker 2 (2026-04-13 00-06-31)
But Network Miner is a good tool to get a summary of
1:15
S… Speaker 2 (2026-04-13 00-06-31)
kind of an overview and to do the initial analysis and hunting
1:19
S… Speaker 2 (2026-04-13 00-06-31)
within network data.
1:21
S… Speaker 2 (2026-04-13 00-06-31)
And again, there's many different tools that are available to do this.
1:25
S… Speaker 2 (2026-04-13 00-06-31)
This is just one I'm highlighting to kind of show the
1:30
S… Speaker 2 (2026-04-13 00-06-31)
possible features of a number of these tools.
1:33
S… Speaker 2 (2026-04-13 00-06-31)
So we've got actually two PCAP files
1:37
S… Speaker 2 (2026-04-13 00-06-31)
that we have loaded simultaneously in here.
1:39
S… Speaker 1 (2026-04-13 00-06-31)
We'll go ahead and honestly,
1:42
S… Speaker 2 (2026-04-13 00-06-31)
I'm going to remove the selected files
1:46
S… Speaker 1 (2026-04-13 00-06-31)
here.
1:47
S… Speaker 1 (2026-04-13 00-06-31)
And we'll reload,
1:48
S… Speaker 2 (2026-04-13 00-06-31)
which shows us less information in here now,
1:52
S… Speaker 2 (2026-04-13 00-06-31)
just to avoid any confusion with the communication.
1:57
S… Speaker 2 (2026-04-13 00-06-31)
So the first tab here is our host file.
1:59
S… Speaker 2 (2026-04-13 00-06-31)
Apologize if this is maybe a little difficult to see.
2:02
S… Speaker 2 (2026-04-13 00-06-31)
There is no way for me to make this any bigger at the moment.
2:08
S… Speaker 2 (2026-04-13 00-06-31)
So I definitely recommend viewing this full screen if you're having difficulty viewing
2:12
S… Speaker 2 (2026-04-13 00-06-31)
it. So we start with the hosts file as far as the
2:16
S… Speaker 2 (2026-04-13 00-06-31)
tabs along the top.
2:17
S… Speaker 2 (2026-04-13 00-06-31)
And we can enter in filters here and we can change how we're
2:21
S… Speaker 2 (2026-04-13 00-06-31)
sorting the information as well.
2:23
S… Speaker 2 (2026-04-13 00-06-31)
This tab contains information about the hosts that are included
2:27
S… Speaker 2 (2026-04-13 00-06-31)
in the capture file.
2:29
S… Speaker 2 (2026-04-13 00-06-31)
We have at the bottom here is the host that was used
2:33
S… Speaker 2 (2026-04-13 00-06-31)
to capture the information.
2:35
S… Speaker 1 (2026-04-13 00-06-31)
And we can expand on this,
2:36
S… Speaker 2 (2026-04-13 00-06-31)
and it gives us the IP address information,
2:38
S… Speaker 1 (2026-04-13 00-06-31)
MAC information,
2:39
S… Speaker 1 (2026-04-13 00-06-31)
OS running on it,
2:41
S… Speaker 2 (2026-04-13 00-06-31)
all kinds of extra information as well,
2:45
S… Speaker 2 (2026-04-13 00-06-31)
including details about the web browser that was used
2:49
S… Speaker 2 (2026-04-13 00-06-31)
in the capture and various other information
2:54
S… Speaker 1 (2026-04-13 00-06-31)
about the host itself.
2:56
S… Speaker 1 (2026-04-13 00-06-31)
And this is all coming from...
2:58
S… Speaker 1 (2026-04-13 00-06-31)
the capture file.
3:00
S… Speaker 2 (2026-04-13 00-06-31)
We can see the outgoing sessions from this host,
3:03
S… Speaker 2 (2026-04-13 00-06-31)
which would be all we have because that's what this capture file includes.
3:06
S… Speaker 2 (2026-04-13 00-06-31)
But you can see a lot of information about just this one
3:11
S… Speaker 2 (2026-04-13 00-06-31)
particular device that an application like NetworkMiner is
3:15
S… Speaker 2 (2026-04-13 00-06-31)
going to just pull from the PCAP file
3:19
S… Speaker 1 (2026-04-13 00-06-31)
in this example.
3:20
S… Speaker 2 (2026-04-13 00-06-31)
and kind of summarize in one location for you.
3:24
S… Speaker 2 (2026-04-13 00-06-31)
And we have here the destination we were reaching out to,
3:26
S… Speaker 2 (2026-04-13 00-06-31)
which was HTTP Forever,
3:28
S… Speaker 2 (2026-04-13 00-06-31)
and it gives us some additional information here as well.
3:32
S… Speaker 2 (2026-04-13 00-06-31)
The host name,
3:33
S… Speaker 2 (2026-04-13 00-06-31)
the ports that are open that it sees,
3:36
S… Speaker 2 (2026-04-13 00-06-31)
again, these are just ports that are in the capture file itself,
3:39
S… Speaker 2 (2026-04-13 00-06-31)
not necessarily all the ports that are open on it.
3:43
S… Speaker 2 (2026-04-13 00-06-31)
The information as far as the incoming sessions to that server,
3:47
S… Speaker 2 (2026-04-13 00-06-31)
which were all from the client down here.
3:50
S… Speaker 1 (2026-04-13 00-06-31)
And again,
3:51
S… Speaker 2 (2026-04-13 00-06-31)
additional information about the host,
3:54
S… Speaker 2 (2026-04-13 00-06-31)
including the web server banner,
3:56
S… Speaker 2 (2026-04-13 00-06-31)
which we see here is running on an Ubuntu machine running Engine X.
4:01
S… Speaker 2 (2026-04-13 00-06-31)
So a lot of information about the hosts that are included,
4:05
S… Speaker 2 (2026-04-13 00-06-31)
including some Google hosts as well.
4:07
S… Speaker 1 (2026-04-13 00-06-31)
We have a Cloudflare,
4:08
S… Speaker 2 (2026-04-13 00-06-31)
CDN,
4:09
S… Speaker 2 (2026-04-13 00-06-31)
and so forth.
4:11
S… Speaker 2 (2026-04-13 00-06-31)
So all the information that was included,
4:13
S… Speaker 2 (2026-04-13 00-06-31)
all the hosts from this packet capture.
4:16
S… Speaker 2 (2026-04-13 00-06-31)
Next tab we have over is files.
4:18
S… Speaker 2 (2026-04-13 00-06-31)
And because this was just HTTP traffic,
4:21
S… Speaker 2 (2026-04-13 00-06-31)
we have a number of files we can pull out.
4:23
S… Speaker 2 (2026-04-13 00-06-31)
And again, this is similar to what we see in Wireshark
4:27
S… Speaker 2 (2026-04-13 00-06-31)
going to a lot of the different options as well.
4:31
S… Speaker 1 (2026-04-13 00-06-31)
We have,
4:32
S… Speaker 2 (2026-04-13 00-06-31)
whoops, I didn't mean to sort that.
4:33
S… Speaker 1 (2026-04-13 00-06-31)
We have the index file here.
4:35
S… Speaker 2 (2026-04-13 00-06-31)
We have the CSS,
4:37
S… Speaker 2 (2026-04-13 00-06-31)
JavaScript files,
4:39
S… Speaker 2 (2026-04-13 00-06-31)
more image files.
4:41
S… Speaker 1 (2026-04-13 00-06-31)
A lot of information,
4:43
S… Speaker 1 (2026-04-13 00-06-31)
and we can open these files and view them and see where they are because they are
4:47
S… Speaker 2 (2026-04-13 00-06-31)
all going to be reconstructed and saved in a specific location.
4:51
S… Speaker 1 (2026-04-13 00-06-31)
Let's get rid.
4:52
S… Speaker 1 (2026-04-13 00-06-31)
There we go.
4:54
S… Speaker 2 (2026-04-13 00-06-31)
And you can see where they are all saved,
4:56
S… Speaker 2 (2026-04-13 00-06-31)
including the kind of hierarchy of where they fall
5:00
S… Speaker 2 (2026-04-13 00-06-31)
on the web server when they were hosted there.
5:05
S… Speaker 2 (2026-04-13 00-06-31)
So all of the files that are included.
5:07
S… Speaker 2 (2026-04-13 00-06-31)
Again, if we're looking at encrypted data in this packet
5:11
S… Speaker 2 (2026-04-13 00-06-31)
capture, we're not going to see these files because,
5:13
S… Speaker 2 (2026-04-13 00-06-31)
well, they are encrypted.
5:14
S… Speaker 1 (2026-04-13 00-06-31)
Any images,
5:16
S… Speaker 2 (2026-04-13 00-06-31)
any image files that were reconstructed,
5:18
S… Speaker 1 (2026-04-13 00-06-31)
which we have the icon file here,
5:20
S… Speaker 2 (2026-04-13 00-06-31)
we have various session information.
5:22
S… Speaker 1 (2026-04-13 00-06-31)
Again, this is all the same information that is viewable.
5:26
S… Speaker 2 (2026-04-13 00-06-31)
from within an application like Wireshark,
5:28
S… Speaker 2 (2026-04-13 00-06-31)
but it's more summarized and a little easier to view at
5:32
S… Speaker 1 (2026-04-13 00-06-31)
a very high level.
5:34
S… Speaker 2 (2026-04-13 00-06-31)
If there was DNS information in this packet capture,
5:37
S… Speaker 1 (2026-04-13 00-06-31)
it would be shown here.
5:38
S… Speaker 1 (2026-04-13 00-06-31)
And again,
5:39
S… Speaker 1 (2026-04-13 00-06-31)
we can open up an additional file.
5:41
S… Speaker 2 (2026-04-13 00-06-31)
We'll add this other HTTP capture,
5:44
S… Speaker 2 (2026-04-13 00-06-31)
and we can see it does include DNS information as
5:49
S… Speaker 2 (2026-04-13 00-06-31)
well.
5:50
S… Speaker 2 (2026-04-13 00-06-31)
So we have a lot of information about DNS queries and
5:54
S… Speaker 2 (2026-04-13 00-06-31)
responses that were performed in here.
5:56
S… Speaker 2 (2026-04-13 00-06-31)
And if we go over to the parameters section,
5:59
S… Speaker 2 (2026-04-13 00-06-31)
we're going to go ahead and remove this one again just to minimize
6:03
S… Speaker 2 (2026-04-13 00-06-31)
the information shown all at once.
6:05
S… Speaker 2 (2026-04-13 00-06-31)
And we have a lot of the HTTP actions and other parameters
6:10
S… Speaker 1 (2026-04-13 00-06-31)
that were included.
6:11
S… Speaker 2 (2026-04-13 00-06-31)
And because this packet capture did include HTTPS
6:15
S… Speaker 2 (2026-04-13 00-06-31)
traffic as well,
6:16
S… Speaker 2 (2026-04-13 00-06-31)
we have TLS handshake information.
6:19
S… Speaker 2 (2026-04-13 00-06-31)
see a lot of information at a good summary.
6:23
S… Speaker 2 (2026-04-13 00-06-31)
Now again, this isn't going to show you necessarily all of the information
6:27
S… Speaker 2 (2026-04-13 00-06-31)
included in the packet.
6:29
S… Speaker 2 (2026-04-13 00-06-31)
An application like Network Miner is good to
6:33
S… Speaker 2 (2026-04-13 00-06-31)
get a summary of the data.
6:36
S… Speaker 2 (2026-04-13 00-06-31)
to see what you're looking at in a packet capture before
6:40
S… Speaker 2 (2026-04-13 00-06-31)
really diving deep and examining it,
6:43
S… Speaker 2 (2026-04-13 00-06-31)
looking for IOCs and trying to hunt whatever it is you're hunting for
6:48
S… Speaker 2 (2026-04-13 00-06-31)
in the network threat hunt.
6:50
S… Speaker 2 (2026-04-13 00-06-31)
It's a good application to get that high -level summary before
6:54
S… Speaker 2 (2026-04-13 00-06-31)
diving in deeper.

هيءَ ترانسڪريٽ AI (آٽوميٽڪ سڏ سڃاڻپ) پاران تيار ڪئي وئي آھي. ان ۾ غلطيون ٿي سگھن ٿيون - اصل آڊيو سان چيڪ ڪريو ته جيئن خطرناڪ استعمال ڪري سگھجي. AI پاليسي

❤️ STT.ai کي پيارو آهي؟ پنھنجن دوستن کي چئو!
خلاصو
ھن ترانسڪريپٽ جي AI خلاصي پيدا ڪرڻ لاءِ خلاصو دٻايو.
خلاصو ڪيو وڃي ٿو...
AI کان ان ترانسڪريپٽ بابت پڇو
ھن ترانسڪريپشن بابت ڪابه سوال ڪريو - AI لاڳاپيل حصا ڳوليندو ۽ جواب ڏيندو.