Εμφάνιση μόνο
0:08
S… Speaker 1 (2026-04-12 15-16-43)
Wireshark is used for a lot more than just capturing packets.
0:12
S… Speaker 1 (2026-04-12 15-16-43)
It is really good at performing in -depth packet analysis
0:16
S… Speaker 2 (2026-04-12 15-16-43)
as well.
0:17
S… Speaker 1 (2026-04-12 15-16-43)
So now we're going to take a look at how some of that analysis works and
0:21
S… Speaker 1 (2026-04-12 15-16-43)
some of the features in Wireshark for packet analysis.
0:25
S… Speaker 1 (2026-04-12 15-16-43)
Now we're going to start out here with a bit more of the kind of basic
0:29
S… Speaker 1 (2026-04-12 15-16-43)
analysis as we progress through looking at
0:33
S… Speaker 1 (2026-04-12 15-16-43)
ways to recognize abnormal traffic,
0:36
S… Speaker 1 (2026-04-12 15-16-43)
we'll start getting into a little more of the advanced features that
0:40
S… Speaker 1 (2026-04-12 15-16-43)
Wireshark offers for analyzing packets.
0:43
S… Speaker 1 (2026-04-12 15-16-43)
So Wireshark has a number of features,
0:46
S… Speaker 1 (2026-04-12 15-16-43)
one of those which is called expert information,
0:49
S… Speaker 1 (2026-04-12 15-16-43)
and this basically gives a good overview.
0:53
S… Speaker 1 (2026-04-12 15-16-43)
of the type of traffic that was captured.
0:57
S… Speaker 1 (2026-04-12 15-16-43)
In this example,
0:58
S… Speaker 1 (2026-04-12 15-16-43)
we're talking about a imported file into Wireshark,
1:01
S… Speaker 1 (2026-04-12 15-16-43)
which is what we're going to be looking at here in a minute.
1:03
S… Speaker 1 (2026-04-12 15-16-43)
So the expert information section of Wireshark or option
1:08
S… Speaker 1 (2026-04-12 15-16-43)
or feature, whatever you want to call it,
1:09
S… Speaker 1 (2026-04-12 15-16-43)
is a good way to get a good overview of what type of traffic
1:13
S… Speaker 1 (2026-04-12 15-16-43)
and some of the information that's included in the capture.
1:17
S… Speaker 1 (2026-04-12 15-16-43)
You have a section called Captured File Properties,
1:20
S… Speaker 1 (2026-04-12 15-16-43)
which, as the name kind of implies,
1:22
S… Speaker 1 (2026-04-12 15-16-43)
it gives a summary of the actual capture file,
1:26
S… Speaker 1 (2026-04-12 15-16-43)
the time and date the capture was started,
1:29
S… Speaker 2 (2026-04-12 15-16-43)
when it ended,
1:30
S… Speaker 1 (2026-04-12 15-16-43)
the time frame it covers,
1:32
S… Speaker 1 (2026-04-12 15-16-43)
some information about the machine that performed the
1:36
S… Speaker 1 (2026-04-12 15-16-43)
capture, things like that.
1:37
S… Speaker 1 (2026-04-12 15-16-43)
And we'll take a look at all of these as well.
1:40
S… Speaker 1 (2026-04-12 15-16-43)
You have a section called Resolved Addresses,
1:43
S… Speaker 1 (2026-04-12 15-16-43)
which will attempt to map out addresses
1:48
S… Speaker 1 (2026-04-12 15-16-43)
to different names.
1:49
S… Speaker 1 (2026-04-12 15-16-43)
Now, we're not talking specifically about domain mapping,
1:53
S… Speaker 1 (2026-04-12 15-16-43)
but we're also talking about MAC addresses.
1:55
S… Speaker 1 (2026-04-12 15-16-43)
It'll take MAC addresses that it finds in the capture file and try to map
1:59
S… Speaker 1 (2026-04-12 15-16-43)
them to manufacturer information or specific device information,
2:03
S… Speaker 1 (2026-04-12 15-16-43)
depending what it has available in its database.
2:06
S… Speaker 1 (2026-04-12 15-16-43)
There's a section called protocol hierarchy,
2:08
S… Speaker 1 (2026-04-12 15-16-43)
which gives a good summary of what type of protocols were
2:13
S… Speaker 1 (2026-04-12 15-16-43)
captured in the file.
2:14
S… Speaker 1 (2026-04-12 15-16-43)
Things like it'll show the number of TCP packets and then the
2:18
S… Speaker 1 (2026-04-12 15-16-43)
breakdown of how many of those were HTTP and so
2:23
S… Speaker 1 (2026-04-12 15-16-43)
forth.
2:23
S… Speaker 1 (2026-04-12 15-16-43)
You know, it'll give you UDP and how many of them were DNS
2:28
S… Speaker 1 (2026-04-12 15-16-43)
ports and things like that.
2:30
S… Speaker 1 (2026-04-12 15-16-43)
So it gives you a good summary and breakdown of the protocols that were in
2:35
S… Speaker 1 (2026-04-12 15-16-43)
the capture.
2:35
S… Speaker 1 (2026-04-12 15-16-43)
There's a section called conversations,
2:37
S… Speaker 1 (2026-04-12 15-16-43)
which will give you a brief glimpse at what
2:42
S… Speaker 1 (2026-04-12 15-16-43)
machines communicated with other machines,
2:44
S… Speaker 1 (2026-04-12 15-16-43)
the protocols they use,
2:46
S… Speaker 1 (2026-04-12 15-16-43)
port numbers,
2:47
S… Speaker 1 (2026-04-12 15-16-43)
and things like that.
2:48
S… Speaker 2 (2026-04-12 15-16-43)
And of course,
2:49
S… Speaker 1 (2026-04-12 15-16-43)
we have display filters,
2:50
S… Speaker 1 (2026-04-12 15-16-43)
which we can use to just filter what information is currently being shown,
2:55
S… Speaker 1 (2026-04-12 15-16-43)
coupled with a feature known as follow stream,
2:58
S… Speaker 1 (2026-04-12 15-16-43)
which lets you pick up packets,
3:00
S… Speaker 1 (2026-04-12 15-16-43)
out of whatever communication you're looking at and it will follow that
3:04
S… Speaker 1 (2026-04-12 15-16-43)
communication stream from beginning to end.
3:07
S… Speaker 2 (2026-04-12 15-16-43)
And as we'll see,
3:08
S… Speaker 1 (2026-04-12 15-16-43)
the follow stream feature essentially just creates a
3:12
S… Speaker 1 (2026-04-12 15-16-43)
display filter and then it shows you the actual
3:16
S… Speaker 1 (2026-04-12 15-16-43)
packets and the communication in there in a much easier to read format.
3:21
S… Speaker 1 (2026-04-12 15-16-43)
kind of all on one screen instead of having to click on each
3:25
S… Speaker 1 (2026-04-12 15-16-43)
individual packet and piece together the communication that way.
3:29
S… Speaker 1 (2026-04-12 15-16-43)
Then we'll take a look at a lot of these features here in just a second.
3:32
S… Speaker 2 (2026-04-12 15-16-43)
And by just a second,
3:33
S… Speaker 2 (2026-04-12 15-16-43)
I mean right now.
3:34
S… Speaker 1 (2026-04-12 15-16-43)
We're going to go ahead and switch over to our lab environment and take a look at all of these.
3:39
S… Speaker 2 (2026-04-12 15-16-43)
Right, moving over to our lab environment,
3:41
S… Speaker 1 (2026-04-12 15-16-43)
we've got Wireshark opened up with a previously captured
3:46
S… Speaker 1 (2026-04-12 15-16-43)
file that I captured earlier.
3:47
S… Speaker 1 (2026-04-12 15-16-43)
This contains primarily HTTP traffic.
3:51
S… Speaker 2 (2026-04-12 15-16-43)
To be exact,
3:52
S… Speaker 1 (2026-04-12 15-16-43)
this was captured with a capture filter,
3:55
S… Speaker 1 (2026-04-12 15-16-43)
the only capturing HTTP and HTTPS.
4:00
S… Speaker 1 (2026-04-12 15-16-43)
I want to look at a very simplistic capture here because we're just taking an
4:04
S… Speaker 1 (2026-04-12 15-16-43)
overview of some of these features that can be used in Wireshark for analysis.
4:08
S… Speaker 1 (2026-04-12 15-16-43)
So let's start with looking at analyze and we're going to show the expert
4:13
S… Speaker 1 (2026-04-12 15-16-43)
information here and what that looks like.
4:15
S… Speaker 1 (2026-04-12 15-16-43)
So we have a summary here of the type of communication,
4:19
S… Speaker 1 (2026-04-12 15-16-43)
the overview of some events that happened within
4:23
S… Speaker 1 (2026-04-12 15-16-43)
this communication.
4:25
S… Speaker 1 (2026-04-12 15-16-43)
You can expand these to get more information.
4:28
S… Speaker 1 (2026-04-12 15-16-43)
We have information about all of the types of activities
4:32
S… Speaker 1 (2026-04-12 15-16-43)
that happen using things like HTTP.
4:35
S… Speaker 1 (2026-04-12 15-16-43)
We have connection establishment acknowledgement,
4:39
S… Speaker 1 (2026-04-12 15-16-43)
which is the SYNAC,
4:40
S… Speaker 1 (2026-04-12 15-16-43)
and so forth.
4:42
S… Speaker 1 (2026-04-12 15-16-43)
So we can see the kind of important events that happened within this packet,
4:46
S… Speaker 1 (2026-04-12 15-16-43)
the number of them that happened,
4:48
S… Speaker 1 (2026-04-12 15-16-43)
and the packet number that we can look at to kind
4:52
S… Speaker 1 (2026-04-12 15-16-43)
of narrow down a little bit further as well.
4:55
S… Speaker 1 (2026-04-12 15-16-43)
So that's the expert information.
4:57
S… Speaker 1 (2026-04-12 15-16-43)
A lot of these kind of features we're going to be looking at are good ways.
5:00
S… Speaker 2 (2026-04-12 15-16-43)
to get summary of the information.
5:02
S… Speaker 2 (2026-04-12 15-16-43)
Again, we'll do more deep dives as we start looking at ways
5:06
S… Speaker 2 (2026-04-12 15-16-43)
to recognize abnormal traffic.
5:08
S… Speaker 2 (2026-04-12 15-16-43)
We're going to move over from the analyze to these statistics and look at the capture
5:12
S… Speaker 1 (2026-04-12 15-16-43)
file properties.
5:13
S… Speaker 2 (2026-04-12 15-16-43)
Again, this just shows us some information about the actual capture
5:18
S… Speaker 1 (2026-04-12 15-16-43)
itself.
5:19
S… Speaker 2 (2026-04-12 15-16-43)
So we can see the time of the first packet,
5:21
S… Speaker 2 (2026-04-12 15-16-43)
last packet,
5:22
S… Speaker 2 (2026-04-12 15-16-43)
and the amount of time that elapsed.
5:24
S… Speaker 2 (2026-04-12 15-16-43)
In this case, this was a very quick example of one second,
5:27
S… Speaker 2 (2026-04-12 15-16-43)
but it contains 249 packets that were captured
5:32
S… Speaker 2 (2026-04-12 15-16-43)
in that time.
5:33
S… Speaker 2 (2026-04-12 15-16-43)
Technically it was 1 .762 seconds.
5:36
S… Speaker 2 (2026-04-12 15-16-43)
So we can see very detailed information about how much was actually
5:40
S… Speaker 2 (2026-04-12 15-16-43)
captured in this file.
5:42
S… Speaker 2 (2026-04-12 15-16-43)
And then depending on the machine that was used,
5:44
S… Speaker 2 (2026-04-12 15-16-43)
some information may be here about what
5:48
S… Speaker 2 (2026-04-12 15-16-43)
data was captured.
5:49
S… Speaker 2 (2026-04-12 15-16-43)
This also will depend on the format that the capture
5:54
S… Speaker 2 (2026-04-12 15-16-43)
file was saved in.
5:56
S… Speaker 2 (2026-04-12 15-16-43)
So that is the capture file properties.
5:59
S… Speaker 2 (2026-04-12 15-16-43)
Next, we're going to look at the resolved addresses,
6:03
S… Speaker 2 (2026-04-12 15-16-43)
again,
6:03
S… Speaker 2 (2026-04-12 15-16-43)
in the statistics menu here.
6:05
S… Speaker 1 (2026-04-12 15-16-43)
And again,
6:06
S… Speaker 2 (2026-04-12 15-16-43)
a lot of information about MAC addresses that may be in here,
6:10
S… Speaker 2 (2026-04-12 15-16-43)
if there are any ports that were mapped out,
6:12
S… Speaker 2 (2026-04-12 15-16-43)
things like that.
6:13
S… Speaker 2 (2026-04-12 15-16-43)
This is showing this kind of summary of all of the possibilities,
6:18
S… Speaker 2 (2026-04-12 15-16-43)
not necessarily the ones that are included in this packet.
6:20
S… Speaker 2 (2026-04-12 15-16-43)
There are some additional information that we have to get first.
6:25
S… Speaker 2 (2026-04-12 15-16-43)
Moving on from there,
6:26
S… Speaker 1 (2026-04-12 15-16-43)
we're going to look at our protocol hierarchy.
6:29
S… Speaker 2 (2026-04-12 15-16-43)
To me,
6:30
S… Speaker 2 (2026-04-12 15-16-43)
this one is a much more useful one because it shows a summary of
6:34
S… Speaker 2 (2026-04-12 15-16-43)
the actual protocols that were used and kind of breaks them down
6:38
S… Speaker 1 (2026-04-12 15-16-43)
in a hierarchical manner,
6:41
S… Speaker 1 (2026-04-12 15-16-43)
as the name implies.
6:42
S… Speaker 2 (2026-04-12 15-16-43)
So we can see that all of our traffic here was IPv4
6:46
S… Speaker 1 (2026-04-12 15-16-43)
traffic.
6:46
S… Speaker 2 (2026-04-12 15-16-43)
There was no IPv6 traffic in here.
6:49
S… Speaker 2 (2026-04-12 15-16-43)
All of it was also TCP.
6:52
S… Speaker 2 (2026-04-12 15-16-43)
There's no UDP traffic in here.
6:54
S… Speaker 2 (2026-04-12 15-16-43)
Again, this is because of the capture filter I used,
6:57
S… Speaker 2 (2026-04-12 15-16-43)
only captured TCP traffic,
6:59
S… Speaker 2 (2026-04-12 15-16-43)
and you can see that TCP is 100 % of the
7:03
S… Speaker 1 (2026-04-12 15-16-43)
capture as well.
7:04
S… Speaker 2 (2026-04-12 15-16-43)
We do have some TLS in here,
7:07
S… Speaker 2 (2026-04-12 15-16-43)
37 % of the capture,
7:08
S… Speaker 2 (2026-04-12 15-16-43)
and then some clear text HTTP that also included
7:12
S… Speaker 2 (2026-04-12 15-16-43)
some XML and some media as well.
7:16
S… Speaker 2 (2026-04-12 15-16-43)
So a good kind of just summary of the protocols that
7:20
S… Speaker 2 (2026-04-12 15-16-43)
were used and the hierarchy in which they fall.
7:23
S… Speaker 1 (2026-04-12 15-16-43)
Next,
7:25
S… Speaker 2 (2026-04-12 15-16-43)
we will take a look at the conversations.
7:29
S… Speaker 2 (2026-04-12 15-16-43)
which shows that our communication happened between two different devices
7:33
S… Speaker 1 (2026-04-12 15-16-43)
right here.
7:34
S… Speaker 1 (2026-04-12 15-16-43)
However,
7:34
S… Speaker 2 (2026-04-12 15-16-43)
there are multiple different IP addresses.
7:36
S… Speaker 2 (2026-04-12 15-16-43)
It's showing only two devices here because this is a virtual machine.
7:39
S… Speaker 2 (2026-04-12 15-16-43)
In a typical capture,
7:42
S… Speaker 2 (2026-04-12 15-16-43)
you would have much more than this on a standard network that's not
7:47
S… Speaker 1 (2026-04-12 15-16-43)
virtualized.
7:47
S… Speaker 2 (2026-04-12 15-16-43)
But we have a number of IP addresses here that we
7:52
S… Speaker 2 (2026-04-12 15-16-43)
show where this communicated from.
7:54
S… Speaker 2 (2026-04-12 15-16-43)
So there's 192 .168 .187.
7:57
S… Speaker 2 (2026-04-12 15-16-43)
1 .187 is the machine we're on right now,
8:00
S… Speaker 2 (2026-04-12 15-16-43)
and it reached out to a number of other IPs.
8:02
S… Speaker 2 (2026-04-12 15-16-43)
We see how much data was transferred,
8:05
S… Speaker 2 (2026-04-12 15-16-43)
the direction of the packet transfer,
8:07
S… Speaker 1 (2026-04-12 15-16-43)
and so on.
8:09
S… Speaker 2 (2026-04-12 15-16-43)
That's on the IPv4 tab.
8:12
S… Speaker 2 (2026-04-12 15-16-43)
If there was any IPv6 traffic,
8:13
S… Speaker 1 (2026-04-12 15-16-43)
we would see it right here.
8:14
S… Speaker 2 (2026-04-12 15-16-43)
If there was any UDP traffic,
8:16
S… Speaker 1 (2026-04-12 15-16-43)
we would see it right here.
8:17
S… Speaker 2 (2026-04-12 15-16-43)
Again, because of the capture filter,
8:19
S… Speaker 2 (2026-04-12 15-16-43)
this only has TCP.
8:22
S… Speaker 2 (2026-04-12 15-16-43)
But we get more information about the TCP traffic
8:26
S… Speaker 1 (2026-04-12 15-16-43)
as well.
8:26
S… Speaker 2 (2026-04-12 15-16-43)
We see that there was communication on port 443 and
8:30
S… Speaker 1 (2026-04-12 15-16-43)
on port 80,
8:31
S… Speaker 2 (2026-04-12 15-16-43)
and this is the destination.
8:32
S… Speaker 2 (2026-04-12 15-16-43)
You have them labeled as port A and
8:37
S… Speaker 1 (2026-04-12 15-16-43)
port B here,
8:38
S… Speaker 2 (2026-04-12 15-16-43)
address A and address B.
8:40
S… Speaker 2 (2026-04-12 15-16-43)
In this case, address A is the source machine,
8:42
S… Speaker 2 (2026-04-12 15-16-43)
so the source port is going to be a randomized number.
8:46
S… Speaker 2 (2026-04-12 15-16-43)
the destination address,
8:48
S… Speaker 2 (2026-04-12 15-16-43)
and then the destination port.
8:49
S… Speaker 2 (2026-04-12 15-16-43)
So again, only HTTP and HTTPS traffic
8:54
S… Speaker 2 (2026-04-12 15-16-43)
were in this capture because of the filter I used.
8:59
S… Speaker 2 (2026-04-12 15-16-43)
So that is the conversations view.
9:02
S… Speaker 2 (2026-04-12 15-16-43)
Now, depending on the type of traffic you're looking at,
9:05
S… Speaker 2 (2026-04-12 15-16-43)
there's also another option here in the file menu for export
9:09
S… Speaker 2 (2026-04-12 15-16-43)
objects.
9:10
S… Speaker 2 (2026-04-12 15-16-43)
So in this case,
9:11
S… Speaker 2 (2026-04-12 15-16-43)
we can look at different
9:13
S… Speaker 2 (2026-04-12 15-16-43)
types of traffic that we can potentially export files out of.
9:17
S… Speaker 2 (2026-04-12 15-16-43)
Looking at HTTP,
9:19
S… Speaker 2 (2026-04-12 15-16-43)
we see that we can actually export some different types
9:23
S… Speaker 2 (2026-04-12 15-16-43)
of files, and as you click on each one,
9:24
S… Speaker 2 (2026-04-12 15-16-43)
it'll actually jump to that packet in the display in the background.
9:28
S… Speaker 2 (2026-04-12 15-16-43)
So we see we have an HTML file that we can look at
9:32
S… Speaker 2 (2026-04-12 15-16-43)
right here, and you can save these files off to for further examination
9:36
S… Speaker 2 (2026-04-12 15-16-43)
and analysis if you need to.
9:38
S… Speaker 1 (2026-04-12 15-16-43)
We have a JavaScript file,
9:40
S… Speaker 2 (2026-04-12 15-16-43)
and you can see some of the raw data back here in the right -hand pane in
9:44
S… Speaker 1 (2026-04-12 15-16-43)
the background.
9:45
S… Speaker 2 (2026-04-12 15-16-43)
We've got CSS files,
9:47
S… Speaker 2 (2026-04-12 15-16-43)
we have an image file,
9:48
S… Speaker 1 (2026-04-12 15-16-43)
a couple other image files,
9:49
S… Speaker 2 (2026-04-12 15-16-43)
an icon file.
9:51
S… Speaker 2 (2026-04-12 15-16-43)
So we can see all the individual files that were
9:55
S… Speaker 2 (2026-04-12 15-16-43)
kind of transferred here in this packet capture as
9:59
S… Speaker 1 (2026-04-12 15-16-43)
well.
10:00
S… Speaker 1 (2026-04-12 15-16-43)
which can be very helpful when we're doing any sort of threat hunting,
10:03
S… Speaker 1 (2026-04-12 15-16-43)
depending on the type of data we're looking at.
10:08
S… Speaker 1 (2026-04-12 15-16-43)
Alright, next thing I want to show you is going to be display filters.
10:12
S… Speaker 1 (2026-04-12 15-16-43)
Now remember, display filters are different than capture filters.
10:16
S… Speaker 1 (2026-04-12 15-16-43)
So if we wanted to do a capture filter
10:21
S… Speaker 1 (2026-04-12 15-16-43)
to only capture TCP port 80,
10:24
S… Speaker 1 (2026-04-12 15-16-43)
it would look like this,
10:25
S… Speaker 1 (2026-04-12 15-16-43)
TCP space port space 80.
10:27
S… Speaker 1 (2026-04-12 15-16-43)
And you can see there the red input bar that shows
10:32
S… Speaker 1 (2026-04-12 15-16-43)
this is not a valid filter because this is a capture filter and capture
10:36
S… Speaker 1 (2026-04-12 15-16-43)
filters are different.
10:38
S… Speaker 1 (2026-04-12 15-16-43)
than display filters.
10:39
S… Speaker 1 (2026-04-12 15-16-43)
Now, one thing you can see here is that as
10:44
S… Speaker 1 (2026-04-12 15-16-43)
you start typing,
10:44
S… Speaker 1 (2026-04-12 15-16-43)
you get suggestions,
10:46
S… Speaker 1 (2026-04-12 15-16-43)
including suggestions of ones that have been used recently,
10:49
S… Speaker 1 (2026-04-12 15-16-43)
depending on what you started typing.
10:51
S… Speaker 1 (2026-04-12 15-16-43)
So we can do TCP,
10:53
S… Speaker 1 (2026-04-12 15-16-43)
and it will just display all TCP traffic.
10:56
S… Speaker 1 (2026-04-12 15-16-43)
In the case of this packet capture,
11:00
S… Speaker 1 (2026-04-12 15-16-43)
it's not going to make any difference because it's only TCP
11:04
S… Speaker 1 (2026-04-12 15-16-43)
traffic.
11:05
S… Speaker 1 (2026-04-12 15-16-43)
However, we can narrow it down to a port,
11:07
S… Speaker 1 (2026-04-12 15-16-43)
and if you press period right there,
11:08
S… Speaker 1 (2026-04-12 15-16-43)
you can get kind of sub -information from TCP.
11:11
S… Speaker 1 (2026-04-12 15-16-43)
And you can see all of the possible options for
11:16
S… Speaker 1 (2026-04-12 15-16-43)
the display filter.
11:17
S… Speaker 1 (2026-04-12 15-16-43)
So if you're not 100 % sure what sort of display filter you're looking for,
11:22
S… Speaker 1 (2026-04-12 15-16-43)
You can either consult the Wireshark documentation,
11:25
S… Speaker 1 (2026-04-12 15-16-43)
or you can just start typing what you think may be relevant,
11:29
S… Speaker 1 (2026-04-12 15-16-43)
and you can start looking through this option.
11:31
S… Speaker 1 (2026-04-12 15-16-43)
As you can see,
11:32
S… Speaker 1 (2026-04-12 15-16-43)
I'm still scrolling.
11:33
S… Speaker 1 (2026-04-12 15-16-43)
There's a lot of types of display filters you
11:37
S… Speaker 1 (2026-04-12 15-16-43)
can do.
11:38
S… Speaker 1 (2026-04-12 15-16-43)
So for this,
11:39
S… Speaker 1 (2026-04-12 15-16-43)
we're going to do a TCP port 80,
11:43
S… Speaker 2 (2026-04-12 15-16-43)
and you can see kind of,
11:44
S… Speaker 2 (2026-04-12 15-16-43)
you know, cheating.
11:44
S… Speaker 1 (2026-04-12 15-16-43)
It's already displayed right there because I have used it recently.
11:47
S… Speaker 1 (2026-04-12 15-16-43)
But if we're looking for TCP port,
11:50
S… Speaker 1 (2026-04-12 15-16-43)
If we're looking for a specific TCP port,
11:52
S… Speaker 1 (2026-04-12 15-16-43)
you do TCP .port,
11:54
S… Speaker 1 (2026-04-12 15-16-43)
and then if you're looking to equal a specific port,
11:57
S… Speaker 1 (2026-04-12 15-16-43)
you do two equal signs and then the port number.
11:59
S… Speaker 1 (2026-04-12 15-16-43)
And you can see this is now a valid display filter because it is green.
12:03
S… Speaker 1 (2026-04-12 15-16-43)
We press enter,
12:04
S… Speaker 1 (2026-04-12 15-16-43)
and now we see we only have HTTP traffic
12:09
S… Speaker 1 (2026-04-12 15-16-43)
for port 80,
12:11
S… Speaker 1 (2026-04-12 15-16-43)
as is the display filter showing.
12:13
S… Speaker 1 (2026-04-12 15-16-43)
We can change that to be 443.
12:17
S… Speaker 1 (2026-04-12 15-16-43)
And we see we only have TLS type of traffic.
12:21
S… Speaker 1 (2026-04-12 15-16-43)
So there's many,
12:23
S… Speaker 1 (2026-04-12 15-16-43)
many different types of file or display filters,
12:28
S… Speaker 2 (2026-04-12 15-16-43)
excuse me,
12:29
S… Speaker 2 (2026-04-12 15-16-43)
that you can do,
12:29
S… Speaker 1 (2026-04-12 15-16-43)
including combining multiple different types.
12:32
S… Speaker 1 (2026-04-12 15-16-43)
You can do TCP port 80 or TCP or UDP port
12:37
S… Speaker 1 (2026-04-12 15-16-43)
80.
12:37
S… Speaker 1 (2026-04-12 15-16-43)
There's many different types you can do.
12:40
S… Speaker 1 (2026-04-12 15-16-43)
And if you want to reset it,
12:42
S… Speaker 1 (2026-04-12 15-16-43)
you can either clear the box and just press enter,
12:44
S… Speaker 1 (2026-04-12 15-16-43)
which will set it back to no display filter,
12:47
S… Speaker 1 (2026-04-12 15-16-43)
or we'll just select a preset one here.
12:51
S… Speaker 1 (2026-04-12 15-16-43)
And then actually display it.
12:55
S… Speaker 2 (2026-04-12 15-16-43)
There we go.
12:55
S… Speaker 1 (2026-04-12 15-16-43)
And you have the X button over here on the far right
12:59
S… Speaker 1 (2026-04-12 15-16-43)
hand side of the input,
13:00
S… Speaker 1 (2026-04-12 15-16-43)
which will clear any display filter as well.
13:03
S… Speaker 1 (2026-04-12 15-16-43)
So that's the ways you can do display filters.
13:08
S… Speaker 1 (2026-04-12 15-16-43)
So what we're going to do next is take a look at a feature known as follow
13:12
S… Speaker 1 (2026-04-12 15-16-43)
stream.
13:13
S… Speaker 1 (2026-04-12 15-16-43)
So following stream is a good way to just kind of follow
13:17
S… Speaker 1 (2026-04-12 15-16-43)
the communication and see what was transferred.
13:20
S… Speaker 1 (2026-04-12 15-16-43)
So just as an example,
13:21
S… Speaker 1 (2026-04-12 15-16-43)
we're going to do a follow stream on this TLS connection here.
13:24
S… Speaker 1 (2026-04-12 15-16-43)
To do that,
13:25
S… Speaker 1 (2026-04-12 15-16-43)
you right -click on whatever individual packet you're looking at,
13:29
S… Speaker 1 (2026-04-12 15-16-43)
go down to follow right here,
13:31
S… Speaker 1 (2026-04-12 15-16-43)
and then you'll have different options depending on what the communication is.
13:37
S… Speaker 1 (2026-04-12 15-16-43)
For this,
13:37
S… Speaker 1 (2026-04-12 15-16-43)
we have TCP and TLS.
13:39
S… Speaker 1 (2026-04-12 15-16-43)
We're going to look at TCP stream,
13:40
S… Speaker 1 (2026-04-12 15-16-43)
and you can see,
13:41
S… Speaker 2 (2026-04-12 15-16-43)
well,
13:42
S… Speaker 1 (2026-04-12 15-16-43)
this is nothing at all because this is TLS.
13:46
S… Speaker 1 (2026-04-12 15-16-43)
This is encrypted traffic.
13:47
S… Speaker 1 (2026-04-12 15-16-43)
This is what you're going to see with encrypted traffic in Wireshark.
13:51
S… Speaker 1 (2026-04-12 15-16-43)
Nothing useful at all unless you have
13:55
S… Speaker 1 (2026-04-12 15-16-43)
the proper keys to be able to decrypt it,
13:58
S… Speaker 1 (2026-04-12 15-16-43)
in which case...
14:00
S… Speaker 1 (2026-04-12 15-16-43)
There are ways to do that.
14:01
S… Speaker 1 (2026-04-12 15-16-43)
We will get into that later in this course,
14:04
S… Speaker 1 (2026-04-12 15-16-43)
though. And as you can see,
14:05
S… Speaker 1 (2026-04-12 15-16-43)
when we did the follow stream,
14:07
S… Speaker 1 (2026-04-12 15-16-43)
it actually created a display filter for
14:11
S… Speaker 1 (2026-04-12 15-16-43)
us.
14:11
S… Speaker 1 (2026-04-12 15-16-43)
TCP .stream equals zero.
14:14
S… Speaker 1 (2026-04-12 15-16-43)
So EQ can be used also depending on,
14:18
S… Speaker 2 (2026-04-12 15-16-43)
or if you can,
14:18
S… Speaker 1 (2026-04-12 15-16-43)
you know, you can do EQ or the two equal signs.
14:21
S… Speaker 1 (2026-04-12 15-16-43)
It just depends.
14:22
S… Speaker 1 (2026-04-12 15-16-43)
So we'll clear out this filter.
14:26
S… Speaker 1 (2026-04-12 15-16-43)
And let's find some HTTP traffic.
14:30
S… Speaker 2 (2026-04-12 15-16-43)
Here we go.
14:31
S… Speaker 1 (2026-04-12 15-16-43)
So we got HTTP traffic right here.
14:34
S… Speaker 1 (2026-04-12 15-16-43)
I'm going to right -click here,
14:35
S… Speaker 2 (2026-04-12 15-16-43)
go to follow,
14:36
S… Speaker 1 (2026-04-12 15-16-43)
and you see now we have TCP stream and HTTP
14:40
S… Speaker 1 (2026-04-12 15-16-43)
stream.
14:41
S… Speaker 1 (2026-04-12 15-16-43)
I want to follow the HTTP.
14:42
S… Speaker 1 (2026-04-12 15-16-43)
And you can see here,
14:44
S… Speaker 1 (2026-04-12 15-16-43)
we've got a lot more usable and readable information.
14:48
S… Speaker 1 (2026-04-12 15-16-43)
So you can see the very first thing,
14:50
S… Speaker 1 (2026-04-12 15-16-43)
and these are all of the HTML commands.
14:53
S… Speaker 1 (2026-04-12 15-16-43)
the get information,
14:55
S… Speaker 1 (2026-04-12 15-16-43)
the server responses.
14:57
S… Speaker 1 (2026-04-12 15-16-43)
So when you can see down here,
14:59
S… Speaker 1 (2026-04-12 15-16-43)
it's a little difficult to see,
15:02
S… Speaker 1 (2026-04-12 15-16-43)
but at the bottom left -hand side of the window,
15:04
S… Speaker 1 (2026-04-12 15-16-43)
it actually will tell you the color code for how it's
15:08
S… Speaker 1 (2026-04-12 15-16-43)
displayed.
15:08
S… Speaker 1 (2026-04-12 15-16-43)
So red displayed text is client communication,
15:12
S… Speaker 1 (2026-04-12 15-16-43)
blue is server communication.
15:14
S… Speaker 1 (2026-04-12 15-16-43)
And you can kind of infer that from the HTML command.
15:17
S… Speaker 1 (2026-04-12 15-16-43)
We're doing a get here on the root of the directory.
15:21
S… Speaker 1 (2026-04-12 15-16-43)
And we have some information about the headers as well.
15:25
S… Speaker 1 (2026-04-12 15-16-43)
And then we have the HTTP reply.
15:28
S… Speaker 1 (2026-04-12 15-16-43)
And you can see as you click on each section,
15:30
S… Speaker 1 (2026-04-12 15-16-43)
it follows the packet in the background.
15:34
S… Speaker 1 (2026-04-12 15-16-43)
You can also see we have a TCP stream equals 7 as
15:38
S… Speaker 1 (2026-04-12 15-16-43)
a display filter.
15:41
S… Speaker 1 (2026-04-12 15-16-43)
And we can see this is running on an Nginx server on
15:45
S… Speaker 1 (2026-04-12 15-16-43)
Ubuntu and some other information about the content
15:49
S… Speaker 1 (2026-04-12 15-16-43)
and the HTML headers.
15:51
S… Speaker 1 (2026-04-12 15-16-43)
Followed up,
15:52
S… Speaker 1 (2026-04-12 15-16-43)
because we were doing a GET request on this HTTP server,
15:56
S… Speaker 1 (2026-04-12 15-16-43)
we have our HTML code,
15:58
S… Speaker 1 (2026-04-12 15-16-43)
which is shown here in plain text because this is not encrypted traffic.
16:02
S… Speaker 1 (2026-04-12 15-16-43)
And this is one that I specifically went to.
16:06
S… Speaker 1 (2026-04-12 15-16-43)
httpforever .com because it is not in,
16:09
S… Speaker 1 (2026-04-12 15-16-43)
it is not a TLS site.
16:11
S… Speaker 1 (2026-04-12 15-16-43)
It is not encrypted.
16:12
S… Speaker 1 (2026-04-12 15-16-43)
And it shows,
16:13
S… Speaker 1 (2026-04-12 15-16-43)
you know, all of the HTML code.
16:15
S… Speaker 1 (2026-04-12 15-16-43)
This is exactly the same information you would see if you
16:19
S… Speaker 1 (2026-04-12 15-16-43)
right -clicked and viewed page source.
16:22
S… Speaker 1 (2026-04-12 15-16-43)
And it continues the communication.
16:24
S… Speaker 1 (2026-04-12 15-16-43)
We have additional files that this root file directed us to
16:28
S… Speaker 1 (2026-04-12 15-16-43)
get. So we're getting what looks like a JavaScript file right here.
16:31
S… Speaker 1 (2026-04-12 15-16-43)
It's returning the JavaScript file.
16:34
S… Speaker 1 (2026-04-12 15-16-43)
We see the JavaScript code.
16:35
S… Speaker 1 (2026-04-12 15-16-43)
We also see what looks like some CSS code as we scroll
16:39
S… Speaker 1 (2026-04-12 15-16-43)
further down.
16:40
S… Speaker 1 (2026-04-12 15-16-43)
So there's a lot of different
16:44
S… Speaker 1 (2026-04-12 15-16-43)
information that it's getting.
16:46
S… Speaker 1 (2026-04-12 15-16-43)
We'll scroll past that giant box of text.
16:48
S… Speaker 1 (2026-04-12 15-16-43)
We see that we are pulling image files as well.
16:52
S… Speaker 1 (2026-04-12 15-16-43)
And it shows all of that information.
16:58
S… Speaker 1 (2026-04-12 15-16-43)
One other thing I wanted to show here is
17:03
S… Speaker 1 (2026-04-12 15-16-43)
the kind of two different panes here at the bottom.
17:06
S… Speaker 1 (2026-04-12 15-16-43)
So we are highlighted on this 200 OK.
17:10
S… Speaker 1 (2026-04-12 15-16-43)
This is the response from the HTML server.
17:13
S… Speaker 1 (2026-04-12 15-16-43)
And we can expand these fields down here to get more information.
17:17
S… Speaker 1 (2026-04-12 15-16-43)
And this is exactly what we saw in the follow stream
17:22
S… Speaker 1 (2026-04-12 15-16-43)
window as well.
17:23
S… Speaker 1 (2026-04-12 15-16-43)
So you can view it in many different ways.
17:27
S… Speaker 1 (2026-04-12 15-16-43)
depending on what your preference is and kind of what information you're
17:31
S… Speaker 1 (2026-04-12 15-16-43)
looking at.
17:32
S… Speaker 1 (2026-04-12 15-16-43)
So you can see if we expand this,
17:34
S… Speaker 1 (2026-04-12 15-16-43)
it's not going to show all of the information.
17:36
S… Speaker 1 (2026-04-12 15-16-43)
It only shows 100 lines here.
17:37
S… Speaker 1 (2026-04-12 15-16-43)
But this is still the HTML code that
17:42
S… Speaker 1 (2026-04-12 15-16-43)
we saw previously,
17:43
S… Speaker 1 (2026-04-12 15-16-43)
just in a little more difficult way to
17:47
S… Speaker 1 (2026-04-12 15-16-43)
view it and just slightly worse formatting.
17:51
S… Speaker 1 (2026-04-12 15-16-43)
But it is meant to show it in more of a raw format as
17:55
S… Speaker 1 (2026-04-12 15-16-43)
well.
17:56
S… Speaker 1 (2026-04-12 15-16-43)
So many different ways to display
18:00
S… Speaker 1 (2026-04-12 15-16-43)
information in Wireshark,
18:01
S… Speaker 1 (2026-04-12 15-16-43)
to search for information,
18:04
S… Speaker 1 (2026-04-12 15-16-43)
to get a summary of the information in Wireshark.
18:07
S… Speaker 1 (2026-04-12 15-16-43)
And again, we're just barely scratching the surface
18:12
S… Speaker 1 (2026-04-12 15-16-43)
of some of the packet analysis features here in Wireshark.
18:16
S… Speaker 1 (2026-04-12 15-16-43)
We'll get more in -depth on some of the ways you can search for
18:20
S… Speaker 1 (2026-04-12 15-16-43)
specific traffic and kind of what to look for in the analysis
18:25
S… Speaker 1 (2026-04-12 15-16-43)
as we start getting into more of the ways
18:29
S… Speaker 1 (2026-04-12 15-16-43)
to recognize abnormal or suspicious traffic.

Αυτό το αντίγραφο δημιουργήθηκε από τον AI (αυτόματη αναγνώριση ομιλίας). Μπορεί να περιέχει σφάλματα Πολιτική AI

❤️ Σου αρέσει το STT.ai; Πες το στους φίλους σου!
Περίληψη
Κάντε κλικ στο Summarize για να δημιουργήσετε μια περίληψη AI αυτής της μεταγραφής.
Συνοψίζοντας...
Ρωτήστε τον Αλ γι' αυτό το σενάριο.
Ρωτήστε οτιδήποτε σχετικά με αυτό το αντίγραφο, το AI θα βρει σχετικές ενότητες και θα απαντήσει.