แสดงเฉพาะ
0:09
S… Speaker 2 (2026-04-13 00-06-31)
that can greatly assist with the kind
0:13
S… Speaker 2 (2026-04-13 00-06-31)
of initial analysis of captured network
0:17
S… Speaker 2 (2026-04-13 00-06-31)
data before going into a deep dive with a
0:21
S… Speaker 2 (2026-04-13 00-06-31)
tool like Wireshark.
0:23
S… Speaker 2 (2026-04-13 00-06-31)
And I want to look at Network Miner in this video.
0:27
S… Speaker 2 (2026-04-13 00-06-31)
Now, I use Network Miner here because it is available on
0:31
S… Speaker 1 (2026-04-13 00-06-31)
multiple different platforms.
0:33
S… Speaker 2 (2026-04-13 00-06-31)
It's primarily developed for Windows.
0:37
S… Speaker 2 (2026-04-13 00-06-31)
but does work in other operating systems as well.
0:40
S… Speaker 2 (2026-04-13 00-06-31)
You can see here I've got it running on a Linux machine.
0:44
S… Speaker 2 (2026-04-13 00-06-31)
And it is a good tool to get a good summary of
0:48
S… Speaker 2 (2026-04-13 00-06-31)
the network traffic that's already in an existing capture file.
0:52
S… Speaker 1 (2026-04-13 00-06-31)
It doesn't really do,
0:53
S… Speaker 2 (2026-04-13 00-06-31)
it captures on its own.
0:55
S… Speaker 1 (2026-04-13 00-06-31)
It is technically possible,
0:57
S… Speaker 2 (2026-04-13 00-06-31)
but it is definitely not recommended.
0:59
S… Speaker 2 (2026-04-13 00-06-31)
It's better to use a...
1:01
S… Speaker 2 (2026-04-13 00-06-31)
specialized program that's meant for that,
1:03
S… Speaker 2 (2026-04-13 00-06-31)
like Wireshark or TCP dump or T -Shark or something like that to
1:08
S… Speaker 2 (2026-04-13 00-06-31)
capture network data.
1:10
S… Speaker 2 (2026-04-13 00-06-31)
But Network Miner is a good tool to get a summary of
1:15
S… Speaker 2 (2026-04-13 00-06-31)
kind of an overview and to do the initial analysis and hunting
1:19
S… Speaker 2 (2026-04-13 00-06-31)
within network data.
1:21
S… Speaker 2 (2026-04-13 00-06-31)
And again, there's many different tools that are available to do this.
1:25
S… Speaker 2 (2026-04-13 00-06-31)
This is just one I'm highlighting to kind of show the
1:30
S… Speaker 2 (2026-04-13 00-06-31)
possible features of a number of these tools.
1:33
S… Speaker 2 (2026-04-13 00-06-31)
So we've got actually two PCAP files
1:37
S… Speaker 2 (2026-04-13 00-06-31)
that we have loaded simultaneously in here.
1:39
S… Speaker 1 (2026-04-13 00-06-31)
We'll go ahead and honestly,
1:42
S… Speaker 2 (2026-04-13 00-06-31)
I'm going to remove the selected files
1:46
S… Speaker 1 (2026-04-13 00-06-31)
here.
1:47
S… Speaker 1 (2026-04-13 00-06-31)
And we'll reload,
1:48
S… Speaker 2 (2026-04-13 00-06-31)
which shows us less information in here now,
1:52
S… Speaker 2 (2026-04-13 00-06-31)
just to avoid any confusion with the communication.
1:57
S… Speaker 2 (2026-04-13 00-06-31)
So the first tab here is our host file.
1:59
S… Speaker 2 (2026-04-13 00-06-31)
Apologize if this is maybe a little difficult to see.
2:02
S… Speaker 2 (2026-04-13 00-06-31)
There is no way for me to make this any bigger at the moment.
2:08
S… Speaker 2 (2026-04-13 00-06-31)
So I definitely recommend viewing this full screen if you're having difficulty viewing
2:12
S… Speaker 2 (2026-04-13 00-06-31)
it. So we start with the hosts file as far as the
2:16
S… Speaker 2 (2026-04-13 00-06-31)
tabs along the top.
2:17
S… Speaker 2 (2026-04-13 00-06-31)
And we can enter in filters here and we can change how we're
2:21
S… Speaker 2 (2026-04-13 00-06-31)
sorting the information as well.
2:23
S… Speaker 2 (2026-04-13 00-06-31)
This tab contains information about the hosts that are included
2:27
S… Speaker 2 (2026-04-13 00-06-31)
in the capture file.
2:29
S… Speaker 2 (2026-04-13 00-06-31)
We have at the bottom here is the host that was used
2:33
S… Speaker 2 (2026-04-13 00-06-31)
to capture the information.
2:35
S… Speaker 1 (2026-04-13 00-06-31)
And we can expand on this,
2:36
S… Speaker 2 (2026-04-13 00-06-31)
and it gives us the IP address information,
2:38
S… Speaker 1 (2026-04-13 00-06-31)
MAC information,
2:39
S… Speaker 1 (2026-04-13 00-06-31)
OS running on it,
2:41
S… Speaker 2 (2026-04-13 00-06-31)
all kinds of extra information as well,
2:45
S… Speaker 2 (2026-04-13 00-06-31)
including details about the web browser that was used
2:49
S… Speaker 2 (2026-04-13 00-06-31)
in the capture and various other information
2:54
S… Speaker 1 (2026-04-13 00-06-31)
about the host itself.
2:56
S… Speaker 1 (2026-04-13 00-06-31)
And this is all coming from...
2:58
S… Speaker 1 (2026-04-13 00-06-31)
the capture file.
3:00
S… Speaker 2 (2026-04-13 00-06-31)
We can see the outgoing sessions from this host,
3:03
S… Speaker 2 (2026-04-13 00-06-31)
which would be all we have because that's what this capture file includes.
3:06
S… Speaker 2 (2026-04-13 00-06-31)
But you can see a lot of information about just this one
3:11
S… Speaker 2 (2026-04-13 00-06-31)
particular device that an application like NetworkMiner is
3:15
S… Speaker 2 (2026-04-13 00-06-31)
going to just pull from the PCAP file
3:19
S… Speaker 1 (2026-04-13 00-06-31)
in this example.
3:20
S… Speaker 2 (2026-04-13 00-06-31)
and kind of summarize in one location for you.
3:24
S… Speaker 2 (2026-04-13 00-06-31)
And we have here the destination we were reaching out to,
3:26
S… Speaker 2 (2026-04-13 00-06-31)
which was HTTP Forever,
3:28
S… Speaker 2 (2026-04-13 00-06-31)
and it gives us some additional information here as well.
3:32
S… Speaker 2 (2026-04-13 00-06-31)
The host name,
3:33
S… Speaker 2 (2026-04-13 00-06-31)
the ports that are open that it sees,
3:36
S… Speaker 2 (2026-04-13 00-06-31)
again, these are just ports that are in the capture file itself,
3:39
S… Speaker 2 (2026-04-13 00-06-31)
not necessarily all the ports that are open on it.
3:43
S… Speaker 2 (2026-04-13 00-06-31)
The information as far as the incoming sessions to that server,
3:47
S… Speaker 2 (2026-04-13 00-06-31)
which were all from the client down here.
3:50
S… Speaker 1 (2026-04-13 00-06-31)
And again,
3:51
S… Speaker 2 (2026-04-13 00-06-31)
additional information about the host,
3:54
S… Speaker 2 (2026-04-13 00-06-31)
including the web server banner,
3:56
S… Speaker 2 (2026-04-13 00-06-31)
which we see here is running on an Ubuntu machine running Engine X.
4:01
S… Speaker 2 (2026-04-13 00-06-31)
So a lot of information about the hosts that are included,
4:05
S… Speaker 2 (2026-04-13 00-06-31)
including some Google hosts as well.
4:07
S… Speaker 1 (2026-04-13 00-06-31)
We have a Cloudflare,
4:08
S… Speaker 2 (2026-04-13 00-06-31)
CDN,
4:09
S… Speaker 2 (2026-04-13 00-06-31)
and so forth.
4:11
S… Speaker 2 (2026-04-13 00-06-31)
So all the information that was included,
4:13
S… Speaker 2 (2026-04-13 00-06-31)
all the hosts from this packet capture.
4:16
S… Speaker 2 (2026-04-13 00-06-31)
Next tab we have over is files.
4:18
S… Speaker 2 (2026-04-13 00-06-31)
And because this was just HTTP traffic,
4:21
S… Speaker 2 (2026-04-13 00-06-31)
we have a number of files we can pull out.
4:23
S… Speaker 2 (2026-04-13 00-06-31)
And again, this is similar to what we see in Wireshark
4:27
S… Speaker 2 (2026-04-13 00-06-31)
going to a lot of the different options as well.
4:31
S… Speaker 1 (2026-04-13 00-06-31)
We have,
4:32
S… Speaker 2 (2026-04-13 00-06-31)
whoops, I didn't mean to sort that.
4:33
S… Speaker 1 (2026-04-13 00-06-31)
We have the index file here.
4:35
S… Speaker 2 (2026-04-13 00-06-31)
We have the CSS,
4:37
S… Speaker 2 (2026-04-13 00-06-31)
JavaScript files,
4:39
S… Speaker 2 (2026-04-13 00-06-31)
more image files.
4:41
S… Speaker 1 (2026-04-13 00-06-31)
A lot of information,
4:43
S… Speaker 1 (2026-04-13 00-06-31)
and we can open these files and view them and see where they are because they are
4:47
S… Speaker 2 (2026-04-13 00-06-31)
all going to be reconstructed and saved in a specific location.
4:51
S… Speaker 1 (2026-04-13 00-06-31)
Let's get rid.
4:52
S… Speaker 1 (2026-04-13 00-06-31)
There we go.
4:54
S… Speaker 2 (2026-04-13 00-06-31)
And you can see where they are all saved,
4:56
S… Speaker 2 (2026-04-13 00-06-31)
including the kind of hierarchy of where they fall
5:00
S… Speaker 2 (2026-04-13 00-06-31)
on the web server when they were hosted there.
5:05
S… Speaker 2 (2026-04-13 00-06-31)
So all of the files that are included.
5:07
S… Speaker 2 (2026-04-13 00-06-31)
Again, if we're looking at encrypted data in this packet
5:11
S… Speaker 2 (2026-04-13 00-06-31)
capture, we're not going to see these files because,
5:13
S… Speaker 2 (2026-04-13 00-06-31)
well, they are encrypted.
5:14
S… Speaker 1 (2026-04-13 00-06-31)
Any images,
5:16
S… Speaker 2 (2026-04-13 00-06-31)
any image files that were reconstructed,
5:18
S… Speaker 1 (2026-04-13 00-06-31)
which we have the icon file here,
5:20
S… Speaker 2 (2026-04-13 00-06-31)
we have various session information.
5:22
S… Speaker 1 (2026-04-13 00-06-31)
Again, this is all the same information that is viewable.
5:26
S… Speaker 2 (2026-04-13 00-06-31)
from within an application like Wireshark,
5:28
S… Speaker 2 (2026-04-13 00-06-31)
but it's more summarized and a little easier to view at
5:32
S… Speaker 1 (2026-04-13 00-06-31)
a very high level.
5:34
S… Speaker 2 (2026-04-13 00-06-31)
If there was DNS information in this packet capture,
5:37
S… Speaker 1 (2026-04-13 00-06-31)
it would be shown here.
5:38
S… Speaker 1 (2026-04-13 00-06-31)
And again,
5:39
S… Speaker 1 (2026-04-13 00-06-31)
we can open up an additional file.
5:41
S… Speaker 2 (2026-04-13 00-06-31)
We'll add this other HTTP capture,
5:44
S… Speaker 2 (2026-04-13 00-06-31)
and we can see it does include DNS information as
5:49
S… Speaker 2 (2026-04-13 00-06-31)
well.
5:50
S… Speaker 2 (2026-04-13 00-06-31)
So we have a lot of information about DNS queries and
5:54
S… Speaker 2 (2026-04-13 00-06-31)
responses that were performed in here.
5:56
S… Speaker 2 (2026-04-13 00-06-31)
And if we go over to the parameters section,
5:59
S… Speaker 2 (2026-04-13 00-06-31)
we're going to go ahead and remove this one again just to minimize
6:03
S… Speaker 2 (2026-04-13 00-06-31)
the information shown all at once.
6:05
S… Speaker 2 (2026-04-13 00-06-31)
And we have a lot of the HTTP actions and other parameters
6:10
S… Speaker 1 (2026-04-13 00-06-31)
that were included.
6:11
S… Speaker 2 (2026-04-13 00-06-31)
And because this packet capture did include HTTPS
6:15
S… Speaker 2 (2026-04-13 00-06-31)
traffic as well,
6:16
S… Speaker 2 (2026-04-13 00-06-31)
we have TLS handshake information.
6:19
S… Speaker 2 (2026-04-13 00-06-31)
see a lot of information at a good summary.
6:23
S… Speaker 2 (2026-04-13 00-06-31)
Now again, this isn't going to show you necessarily all of the information
6:27
S… Speaker 2 (2026-04-13 00-06-31)
included in the packet.
6:29
S… Speaker 2 (2026-04-13 00-06-31)
An application like Network Miner is good to
6:33
S… Speaker 2 (2026-04-13 00-06-31)
get a summary of the data.
6:36
S… Speaker 2 (2026-04-13 00-06-31)
to see what you're looking at in a packet capture before
6:40
S… Speaker 2 (2026-04-13 00-06-31)
really diving deep and examining it,
6:43
S… Speaker 2 (2026-04-13 00-06-31)
looking for IOCs and trying to hunt whatever it is you're hunting for
6:48
S… Speaker 2 (2026-04-13 00-06-31)
in the network threat hunt.
6:50
S… Speaker 2 (2026-04-13 00-06-31)
It's a good application to get that high -level summary before
6:54
S… Speaker 2 (2026-04-13 00-06-31)
diving in deeper.

ข้อความที่แปลเป็นภาษาอังกฤษนี้ถูกสร้างขึ้นโดย AI (การรับรู้เสียงอัตโนมัติ) อาจมีข้อผิดพลาด - ตรวจสอบกับเสียงต้นฉบับเพื่อใช้อย่างสำคัญ ข้อกำหนด AI

❤️ ชอบ STT.ai ไหม? บอกต่อเพื่อน ๆ ของคุณสิ!
สรุป
คลิกที่ ทำสรุป เพื่อสร้างสรุป AI ของการแปลนี้
ขอสรุป...
ถาม AI เกี่ยวกับการแปลนี้
ถามอะไรก็ได้เกี่ยวกับบทบันทึกนี้ เอไอจะหาส่วนที่เกี่ยวข้องและตอบ