Прикажувам само
0:08
S… Speaker 1 (2026-04-12 15-16-43)
Wireshark is used for a lot more than just capturing packets.
0:12
S… Speaker 1 (2026-04-12 15-16-43)
It is really good at performing in -depth packet analysis
0:16
S… Speaker 2 (2026-04-12 15-16-43)
as well.
0:17
S… Speaker 1 (2026-04-12 15-16-43)
So now we're going to take a look at how some of that analysis works and
0:21
S… Speaker 1 (2026-04-12 15-16-43)
some of the features in Wireshark for packet analysis.
0:25
S… Speaker 1 (2026-04-12 15-16-43)
Now we're going to start out here with a bit more of the kind of basic
0:29
S… Speaker 1 (2026-04-12 15-16-43)
analysis as we progress through looking at
0:33
S… Speaker 1 (2026-04-12 15-16-43)
ways to recognize abnormal traffic,
0:36
S… Speaker 1 (2026-04-12 15-16-43)
we'll start getting into a little more of the advanced features that
0:40
S… Speaker 1 (2026-04-12 15-16-43)
Wireshark offers for analyzing packets.
0:43
S… Speaker 1 (2026-04-12 15-16-43)
So Wireshark has a number of features,
0:46
S… Speaker 1 (2026-04-12 15-16-43)
one of those which is called expert information,
0:49
S… Speaker 1 (2026-04-12 15-16-43)
and this basically gives a good overview.
0:53
S… Speaker 1 (2026-04-12 15-16-43)
of the type of traffic that was captured.
0:57
S… Speaker 1 (2026-04-12 15-16-43)
In this example,
0:58
S… Speaker 1 (2026-04-12 15-16-43)
we're talking about a imported file into Wireshark,
1:01
S… Speaker 1 (2026-04-12 15-16-43)
which is what we're going to be looking at here in a minute.
1:03
S… Speaker 1 (2026-04-12 15-16-43)
So the expert information section of Wireshark or option
1:08
S… Speaker 1 (2026-04-12 15-16-43)
or feature, whatever you want to call it,
1:09
S… Speaker 1 (2026-04-12 15-16-43)
is a good way to get a good overview of what type of traffic
1:13
S… Speaker 1 (2026-04-12 15-16-43)
and some of the information that's included in the capture.
1:17
S… Speaker 1 (2026-04-12 15-16-43)
You have a section called Captured File Properties,
1:20
S… Speaker 1 (2026-04-12 15-16-43)
which, as the name kind of implies,
1:22
S… Speaker 1 (2026-04-12 15-16-43)
it gives a summary of the actual capture file,
1:26
S… Speaker 1 (2026-04-12 15-16-43)
the time and date the capture was started,
1:29
S… Speaker 2 (2026-04-12 15-16-43)
when it ended,
1:30
S… Speaker 1 (2026-04-12 15-16-43)
the time frame it covers,
1:32
S… Speaker 1 (2026-04-12 15-16-43)
some information about the machine that performed the
1:36
S… Speaker 1 (2026-04-12 15-16-43)
capture, things like that.
1:37
S… Speaker 1 (2026-04-12 15-16-43)
And we'll take a look at all of these as well.
1:40
S… Speaker 1 (2026-04-12 15-16-43)
You have a section called Resolved Addresses,
1:43
S… Speaker 1 (2026-04-12 15-16-43)
which will attempt to map out addresses
1:48
S… Speaker 1 (2026-04-12 15-16-43)
to different names.
1:49
S… Speaker 1 (2026-04-12 15-16-43)
Now, we're not talking specifically about domain mapping,
1:53
S… Speaker 1 (2026-04-12 15-16-43)
but we're also talking about MAC addresses.
1:55
S… Speaker 1 (2026-04-12 15-16-43)
It'll take MAC addresses that it finds in the capture file and try to map
1:59
S… Speaker 1 (2026-04-12 15-16-43)
them to manufacturer information or specific device information,
2:03
S… Speaker 1 (2026-04-12 15-16-43)
depending what it has available in its database.
2:06
S… Speaker 1 (2026-04-12 15-16-43)
There's a section called protocol hierarchy,
2:08
S… Speaker 1 (2026-04-12 15-16-43)
which gives a good summary of what type of protocols were
2:13
S… Speaker 1 (2026-04-12 15-16-43)
captured in the file.
2:14
S… Speaker 1 (2026-04-12 15-16-43)
Things like it'll show the number of TCP packets and then the
2:18
S… Speaker 1 (2026-04-12 15-16-43)
breakdown of how many of those were HTTP and so
2:23
S… Speaker 1 (2026-04-12 15-16-43)
forth.
2:23
S… Speaker 1 (2026-04-12 15-16-43)
You know, it'll give you UDP and how many of them were DNS
2:28
S… Speaker 1 (2026-04-12 15-16-43)
ports and things like that.
2:30
S… Speaker 1 (2026-04-12 15-16-43)
So it gives you a good summary and breakdown of the protocols that were in
2:35
S… Speaker 1 (2026-04-12 15-16-43)
the capture.
2:35
S… Speaker 1 (2026-04-12 15-16-43)
There's a section called conversations,
2:37
S… Speaker 1 (2026-04-12 15-16-43)
which will give you a brief glimpse at what
2:42
S… Speaker 1 (2026-04-12 15-16-43)
machines communicated with other machines,
2:44
S… Speaker 1 (2026-04-12 15-16-43)
the protocols they use,
2:46
S… Speaker 1 (2026-04-12 15-16-43)
port numbers,
2:47
S… Speaker 1 (2026-04-12 15-16-43)
and things like that.
2:48
S… Speaker 2 (2026-04-12 15-16-43)
And of course,
2:49
S… Speaker 1 (2026-04-12 15-16-43)
we have display filters,
2:50
S… Speaker 1 (2026-04-12 15-16-43)
which we can use to just filter what information is currently being shown,
2:55
S… Speaker 1 (2026-04-12 15-16-43)
coupled with a feature known as follow stream,
2:58
S… Speaker 1 (2026-04-12 15-16-43)
which lets you pick up packets,
3:00
S… Speaker 1 (2026-04-12 15-16-43)
out of whatever communication you're looking at and it will follow that
3:04
S… Speaker 1 (2026-04-12 15-16-43)
communication stream from beginning to end.
3:07
S… Speaker 2 (2026-04-12 15-16-43)
And as we'll see,
3:08
S… Speaker 1 (2026-04-12 15-16-43)
the follow stream feature essentially just creates a
3:12
S… Speaker 1 (2026-04-12 15-16-43)
display filter and then it shows you the actual
3:16
S… Speaker 1 (2026-04-12 15-16-43)
packets and the communication in there in a much easier to read format.
3:21
S… Speaker 1 (2026-04-12 15-16-43)
kind of all on one screen instead of having to click on each
3:25
S… Speaker 1 (2026-04-12 15-16-43)
individual packet and piece together the communication that way.
3:29
S… Speaker 1 (2026-04-12 15-16-43)
Then we'll take a look at a lot of these features here in just a second.
3:32
S… Speaker 2 (2026-04-12 15-16-43)
And by just a second,
3:33
S… Speaker 2 (2026-04-12 15-16-43)
I mean right now.
3:34
S… Speaker 1 (2026-04-12 15-16-43)
We're going to go ahead and switch over to our lab environment and take a look at all of these.
3:39
S… Speaker 2 (2026-04-12 15-16-43)
Right, moving over to our lab environment,
3:41
S… Speaker 1 (2026-04-12 15-16-43)
we've got Wireshark opened up with a previously captured
3:46
S… Speaker 1 (2026-04-12 15-16-43)
file that I captured earlier.
3:47
S… Speaker 1 (2026-04-12 15-16-43)
This contains primarily HTTP traffic.
3:51
S… Speaker 2 (2026-04-12 15-16-43)
To be exact,
3:52
S… Speaker 1 (2026-04-12 15-16-43)
this was captured with a capture filter,
3:55
S… Speaker 1 (2026-04-12 15-16-43)
the only capturing HTTP and HTTPS.
4:00
S… Speaker 1 (2026-04-12 15-16-43)
I want to look at a very simplistic capture here because we're just taking an
4:04
S… Speaker 1 (2026-04-12 15-16-43)
overview of some of these features that can be used in Wireshark for analysis.
4:08
S… Speaker 1 (2026-04-12 15-16-43)
So let's start with looking at analyze and we're going to show the expert
4:13
S… Speaker 1 (2026-04-12 15-16-43)
information here and what that looks like.
4:15
S… Speaker 1 (2026-04-12 15-16-43)
So we have a summary here of the type of communication,
4:19
S… Speaker 1 (2026-04-12 15-16-43)
the overview of some events that happened within
4:23
S… Speaker 1 (2026-04-12 15-16-43)
this communication.
4:25
S… Speaker 1 (2026-04-12 15-16-43)
You can expand these to get more information.
4:28
S… Speaker 1 (2026-04-12 15-16-43)
We have information about all of the types of activities
4:32
S… Speaker 1 (2026-04-12 15-16-43)
that happen using things like HTTP.
4:35
S… Speaker 1 (2026-04-12 15-16-43)
We have connection establishment acknowledgement,
4:39
S… Speaker 1 (2026-04-12 15-16-43)
which is the SYNAC,
4:40
S… Speaker 1 (2026-04-12 15-16-43)
and so forth.
4:42
S… Speaker 1 (2026-04-12 15-16-43)
So we can see the kind of important events that happened within this packet,
4:46
S… Speaker 1 (2026-04-12 15-16-43)
the number of them that happened,
4:48
S… Speaker 1 (2026-04-12 15-16-43)
and the packet number that we can look at to kind
4:52
S… Speaker 1 (2026-04-12 15-16-43)
of narrow down a little bit further as well.
4:55
S… Speaker 1 (2026-04-12 15-16-43)
So that's the expert information.
4:57
S… Speaker 1 (2026-04-12 15-16-43)
A lot of these kind of features we're going to be looking at are good ways.
5:00
S… Speaker 2 (2026-04-12 15-16-43)
to get summary of the information.
5:02
S… Speaker 2 (2026-04-12 15-16-43)
Again, we'll do more deep dives as we start looking at ways
5:06
S… Speaker 2 (2026-04-12 15-16-43)
to recognize abnormal traffic.
5:08
S… Speaker 2 (2026-04-12 15-16-43)
We're going to move over from the analyze to these statistics and look at the capture
5:12
S… Speaker 1 (2026-04-12 15-16-43)
file properties.
5:13
S… Speaker 2 (2026-04-12 15-16-43)
Again, this just shows us some information about the actual capture
5:18
S… Speaker 1 (2026-04-12 15-16-43)
itself.
5:19
S… Speaker 2 (2026-04-12 15-16-43)
So we can see the time of the first packet,
5:21
S… Speaker 2 (2026-04-12 15-16-43)
last packet,
5:22
S… Speaker 2 (2026-04-12 15-16-43)
and the amount of time that elapsed.
5:24
S… Speaker 2 (2026-04-12 15-16-43)
In this case, this was a very quick example of one second,
5:27
S… Speaker 2 (2026-04-12 15-16-43)
but it contains 249 packets that were captured
5:32
S… Speaker 2 (2026-04-12 15-16-43)
in that time.
5:33
S… Speaker 2 (2026-04-12 15-16-43)
Technically it was 1 .762 seconds.
5:36
S… Speaker 2 (2026-04-12 15-16-43)
So we can see very detailed information about how much was actually
5:40
S… Speaker 2 (2026-04-12 15-16-43)
captured in this file.
5:42
S… Speaker 2 (2026-04-12 15-16-43)
And then depending on the machine that was used,
5:44
S… Speaker 2 (2026-04-12 15-16-43)
some information may be here about what
5:48
S… Speaker 2 (2026-04-12 15-16-43)
data was captured.
5:49
S… Speaker 2 (2026-04-12 15-16-43)
This also will depend on the format that the capture
5:54
S… Speaker 2 (2026-04-12 15-16-43)
file was saved in.
5:56
S… Speaker 2 (2026-04-12 15-16-43)
So that is the capture file properties.
5:59
S… Speaker 2 (2026-04-12 15-16-43)
Next, we're going to look at the resolved addresses,
6:03
S… Speaker 2 (2026-04-12 15-16-43)
again,
6:03
S… Speaker 2 (2026-04-12 15-16-43)
in the statistics menu here.
6:05
S… Speaker 1 (2026-04-12 15-16-43)
And again,
6:06
S… Speaker 2 (2026-04-12 15-16-43)
a lot of information about MAC addresses that may be in here,
6:10
S… Speaker 2 (2026-04-12 15-16-43)
if there are any ports that were mapped out,
6:12
S… Speaker 2 (2026-04-12 15-16-43)
things like that.
6:13
S… Speaker 2 (2026-04-12 15-16-43)
This is showing this kind of summary of all of the possibilities,
6:18
S… Speaker 2 (2026-04-12 15-16-43)
not necessarily the ones that are included in this packet.
6:20
S… Speaker 2 (2026-04-12 15-16-43)
There are some additional information that we have to get first.
6:25
S… Speaker 2 (2026-04-12 15-16-43)
Moving on from there,
6:26
S… Speaker 1 (2026-04-12 15-16-43)
we're going to look at our protocol hierarchy.
6:29
S… Speaker 2 (2026-04-12 15-16-43)
To me,
6:30
S… Speaker 2 (2026-04-12 15-16-43)
this one is a much more useful one because it shows a summary of
6:34
S… Speaker 2 (2026-04-12 15-16-43)
the actual protocols that were used and kind of breaks them down
6:38
S… Speaker 1 (2026-04-12 15-16-43)
in a hierarchical manner,
6:41
S… Speaker 1 (2026-04-12 15-16-43)
as the name implies.
6:42
S… Speaker 2 (2026-04-12 15-16-43)
So we can see that all of our traffic here was IPv4
6:46
S… Speaker 1 (2026-04-12 15-16-43)
traffic.
6:46
S… Speaker 2 (2026-04-12 15-16-43)
There was no IPv6 traffic in here.
6:49
S… Speaker 2 (2026-04-12 15-16-43)
All of it was also TCP.
6:52
S… Speaker 2 (2026-04-12 15-16-43)
There's no UDP traffic in here.
6:54
S… Speaker 2 (2026-04-12 15-16-43)
Again, this is because of the capture filter I used,
6:57
S… Speaker 2 (2026-04-12 15-16-43)
only captured TCP traffic,
6:59
S… Speaker 2 (2026-04-12 15-16-43)
and you can see that TCP is 100 % of the
7:03
S… Speaker 1 (2026-04-12 15-16-43)
capture as well.
7:04
S… Speaker 2 (2026-04-12 15-16-43)
We do have some TLS in here,
7:07
S… Speaker 2 (2026-04-12 15-16-43)
37 % of the capture,
7:08
S… Speaker 2 (2026-04-12 15-16-43)
and then some clear text HTTP that also included
7:12
S… Speaker 2 (2026-04-12 15-16-43)
some XML and some media as well.
7:16
S… Speaker 2 (2026-04-12 15-16-43)
So a good kind of just summary of the protocols that
7:20
S… Speaker 2 (2026-04-12 15-16-43)
were used and the hierarchy in which they fall.
7:23
S… Speaker 1 (2026-04-12 15-16-43)
Next,
7:25
S… Speaker 2 (2026-04-12 15-16-43)
we will take a look at the conversations.
7:29
S… Speaker 2 (2026-04-12 15-16-43)
which shows that our communication happened between two different devices
7:33
S… Speaker 1 (2026-04-12 15-16-43)
right here.
7:34
S… Speaker 1 (2026-04-12 15-16-43)
However,
7:34
S… Speaker 2 (2026-04-12 15-16-43)
there are multiple different IP addresses.
7:36
S… Speaker 2 (2026-04-12 15-16-43)
It's showing only two devices here because this is a virtual machine.
7:39
S… Speaker 2 (2026-04-12 15-16-43)
In a typical capture,
7:42
S… Speaker 2 (2026-04-12 15-16-43)
you would have much more than this on a standard network that's not
7:47
S… Speaker 1 (2026-04-12 15-16-43)
virtualized.
7:47
S… Speaker 2 (2026-04-12 15-16-43)
But we have a number of IP addresses here that we
7:52
S… Speaker 2 (2026-04-12 15-16-43)
show where this communicated from.
7:54
S… Speaker 2 (2026-04-12 15-16-43)
So there's 192 .168 .187.
7:57
S… Speaker 2 (2026-04-12 15-16-43)
1 .187 is the machine we're on right now,
8:00
S… Speaker 2 (2026-04-12 15-16-43)
and it reached out to a number of other IPs.
8:02
S… Speaker 2 (2026-04-12 15-16-43)
We see how much data was transferred,
8:05
S… Speaker 2 (2026-04-12 15-16-43)
the direction of the packet transfer,
8:07
S… Speaker 1 (2026-04-12 15-16-43)
and so on.
8:09
S… Speaker 2 (2026-04-12 15-16-43)
That's on the IPv4 tab.
8:12
S… Speaker 2 (2026-04-12 15-16-43)
If there was any IPv6 traffic,
8:13
S… Speaker 1 (2026-04-12 15-16-43)
we would see it right here.
8:14
S… Speaker 2 (2026-04-12 15-16-43)
If there was any UDP traffic,
8:16
S… Speaker 1 (2026-04-12 15-16-43)
we would see it right here.
8:17
S… Speaker 2 (2026-04-12 15-16-43)
Again, because of the capture filter,
8:19
S… Speaker 2 (2026-04-12 15-16-43)
this only has TCP.
8:22
S… Speaker 2 (2026-04-12 15-16-43)
But we get more information about the TCP traffic
8:26
S… Speaker 1 (2026-04-12 15-16-43)
as well.
8:26
S… Speaker 2 (2026-04-12 15-16-43)
We see that there was communication on port 443 and
8:30
S… Speaker 1 (2026-04-12 15-16-43)
on port 80,
8:31
S… Speaker 2 (2026-04-12 15-16-43)
and this is the destination.
8:32
S… Speaker 2 (2026-04-12 15-16-43)
You have them labeled as port A and
8:37
S… Speaker 1 (2026-04-12 15-16-43)
port B here,
8:38
S… Speaker 2 (2026-04-12 15-16-43)
address A and address B.
8:40
S… Speaker 2 (2026-04-12 15-16-43)
In this case, address A is the source machine,
8:42
S… Speaker 2 (2026-04-12 15-16-43)
so the source port is going to be a randomized number.
8:46
S… Speaker 2 (2026-04-12 15-16-43)
the destination address,
8:48
S… Speaker 2 (2026-04-12 15-16-43)
and then the destination port.
8:49
S… Speaker 2 (2026-04-12 15-16-43)
So again, only HTTP and HTTPS traffic
8:54
S… Speaker 2 (2026-04-12 15-16-43)
were in this capture because of the filter I used.
8:59
S… Speaker 2 (2026-04-12 15-16-43)
So that is the conversations view.
9:02
S… Speaker 2 (2026-04-12 15-16-43)
Now, depending on the type of traffic you're looking at,
9:05
S… Speaker 2 (2026-04-12 15-16-43)
there's also another option here in the file menu for export
9:09
S… Speaker 2 (2026-04-12 15-16-43)
objects.
9:10
S… Speaker 2 (2026-04-12 15-16-43)
So in this case,
9:11
S… Speaker 2 (2026-04-12 15-16-43)
we can look at different
9:13
S… Speaker 2 (2026-04-12 15-16-43)
types of traffic that we can potentially export files out of.
9:17
S… Speaker 2 (2026-04-12 15-16-43)
Looking at HTTP,
9:19
S… Speaker 2 (2026-04-12 15-16-43)
we see that we can actually export some different types
9:23
S… Speaker 2 (2026-04-12 15-16-43)
of files, and as you click on each one,
9:24
S… Speaker 2 (2026-04-12 15-16-43)
it'll actually jump to that packet in the display in the background.
9:28
S… Speaker 2 (2026-04-12 15-16-43)
So we see we have an HTML file that we can look at
9:32
S… Speaker 2 (2026-04-12 15-16-43)
right here, and you can save these files off to for further examination
9:36
S… Speaker 2 (2026-04-12 15-16-43)
and analysis if you need to.
9:38
S… Speaker 1 (2026-04-12 15-16-43)
We have a JavaScript file,
9:40
S… Speaker 2 (2026-04-12 15-16-43)
and you can see some of the raw data back here in the right -hand pane in
9:44
S… Speaker 1 (2026-04-12 15-16-43)
the background.
9:45
S… Speaker 2 (2026-04-12 15-16-43)
We've got CSS files,
9:47
S… Speaker 2 (2026-04-12 15-16-43)
we have an image file,
9:48
S… Speaker 1 (2026-04-12 15-16-43)
a couple other image files,
9:49
S… Speaker 2 (2026-04-12 15-16-43)
an icon file.
9:51
S… Speaker 2 (2026-04-12 15-16-43)
So we can see all the individual files that were
9:55
S… Speaker 2 (2026-04-12 15-16-43)
kind of transferred here in this packet capture as
9:59
S… Speaker 1 (2026-04-12 15-16-43)
well.
10:00
S… Speaker 1 (2026-04-12 15-16-43)
which can be very helpful when we're doing any sort of threat hunting,
10:03
S… Speaker 1 (2026-04-12 15-16-43)
depending on the type of data we're looking at.
10:08
S… Speaker 1 (2026-04-12 15-16-43)
Alright, next thing I want to show you is going to be display filters.
10:12
S… Speaker 1 (2026-04-12 15-16-43)
Now remember, display filters are different than capture filters.
10:16
S… Speaker 1 (2026-04-12 15-16-43)
So if we wanted to do a capture filter
10:21
S… Speaker 1 (2026-04-12 15-16-43)
to only capture TCP port 80,
10:24
S… Speaker 1 (2026-04-12 15-16-43)
it would look like this,
10:25
S… Speaker 1 (2026-04-12 15-16-43)
TCP space port space 80.
10:27
S… Speaker 1 (2026-04-12 15-16-43)
And you can see there the red input bar that shows
10:32
S… Speaker 1 (2026-04-12 15-16-43)
this is not a valid filter because this is a capture filter and capture
10:36
S… Speaker 1 (2026-04-12 15-16-43)
filters are different.
10:38
S… Speaker 1 (2026-04-12 15-16-43)
than display filters.
10:39
S… Speaker 1 (2026-04-12 15-16-43)
Now, one thing you can see here is that as
10:44
S… Speaker 1 (2026-04-12 15-16-43)
you start typing,
10:44
S… Speaker 1 (2026-04-12 15-16-43)
you get suggestions,
10:46
S… Speaker 1 (2026-04-12 15-16-43)
including suggestions of ones that have been used recently,
10:49
S… Speaker 1 (2026-04-12 15-16-43)
depending on what you started typing.
10:51
S… Speaker 1 (2026-04-12 15-16-43)
So we can do TCP,
10:53
S… Speaker 1 (2026-04-12 15-16-43)
and it will just display all TCP traffic.
10:56
S… Speaker 1 (2026-04-12 15-16-43)
In the case of this packet capture,
11:00
S… Speaker 1 (2026-04-12 15-16-43)
it's not going to make any difference because it's only TCP
11:04
S… Speaker 1 (2026-04-12 15-16-43)
traffic.
11:05
S… Speaker 1 (2026-04-12 15-16-43)
However, we can narrow it down to a port,
11:07
S… Speaker 1 (2026-04-12 15-16-43)
and if you press period right there,
11:08
S… Speaker 1 (2026-04-12 15-16-43)
you can get kind of sub -information from TCP.
11:11
S… Speaker 1 (2026-04-12 15-16-43)
And you can see all of the possible options for
11:16
S… Speaker 1 (2026-04-12 15-16-43)
the display filter.
11:17
S… Speaker 1 (2026-04-12 15-16-43)
So if you're not 100 % sure what sort of display filter you're looking for,
11:22
S… Speaker 1 (2026-04-12 15-16-43)
You can either consult the Wireshark documentation,
11:25
S… Speaker 1 (2026-04-12 15-16-43)
or you can just start typing what you think may be relevant,
11:29
S… Speaker 1 (2026-04-12 15-16-43)
and you can start looking through this option.
11:31
S… Speaker 1 (2026-04-12 15-16-43)
As you can see,
11:32
S… Speaker 1 (2026-04-12 15-16-43)
I'm still scrolling.
11:33
S… Speaker 1 (2026-04-12 15-16-43)
There's a lot of types of display filters you
11:37
S… Speaker 1 (2026-04-12 15-16-43)
can do.
11:38
S… Speaker 1 (2026-04-12 15-16-43)
So for this,
11:39
S… Speaker 1 (2026-04-12 15-16-43)
we're going to do a TCP port 80,
11:43
S… Speaker 2 (2026-04-12 15-16-43)
and you can see kind of,
11:44
S… Speaker 2 (2026-04-12 15-16-43)
you know, cheating.
11:44
S… Speaker 1 (2026-04-12 15-16-43)
It's already displayed right there because I have used it recently.
11:47
S… Speaker 1 (2026-04-12 15-16-43)
But if we're looking for TCP port,
11:50
S… Speaker 1 (2026-04-12 15-16-43)
If we're looking for a specific TCP port,
11:52
S… Speaker 1 (2026-04-12 15-16-43)
you do TCP .port,
11:54
S… Speaker 1 (2026-04-12 15-16-43)
and then if you're looking to equal a specific port,
11:57
S… Speaker 1 (2026-04-12 15-16-43)
you do two equal signs and then the port number.
11:59
S… Speaker 1 (2026-04-12 15-16-43)
And you can see this is now a valid display filter because it is green.
12:03
S… Speaker 1 (2026-04-12 15-16-43)
We press enter,
12:04
S… Speaker 1 (2026-04-12 15-16-43)
and now we see we only have HTTP traffic
12:09
S… Speaker 1 (2026-04-12 15-16-43)
for port 80,
12:11
S… Speaker 1 (2026-04-12 15-16-43)
as is the display filter showing.
12:13
S… Speaker 1 (2026-04-12 15-16-43)
We can change that to be 443.
12:17
S… Speaker 1 (2026-04-12 15-16-43)
And we see we only have TLS type of traffic.
12:21
S… Speaker 1 (2026-04-12 15-16-43)
So there's many,
12:23
S… Speaker 1 (2026-04-12 15-16-43)
many different types of file or display filters,
12:28
S… Speaker 2 (2026-04-12 15-16-43)
excuse me,
12:29
S… Speaker 2 (2026-04-12 15-16-43)
that you can do,
12:29
S… Speaker 1 (2026-04-12 15-16-43)
including combining multiple different types.
12:32
S… Speaker 1 (2026-04-12 15-16-43)
You can do TCP port 80 or TCP or UDP port
12:37
S… Speaker 1 (2026-04-12 15-16-43)
80.
12:37
S… Speaker 1 (2026-04-12 15-16-43)
There's many different types you can do.
12:40
S… Speaker 1 (2026-04-12 15-16-43)
And if you want to reset it,
12:42
S… Speaker 1 (2026-04-12 15-16-43)
you can either clear the box and just press enter,
12:44
S… Speaker 1 (2026-04-12 15-16-43)
which will set it back to no display filter,
12:47
S… Speaker 1 (2026-04-12 15-16-43)
or we'll just select a preset one here.
12:51
S… Speaker 1 (2026-04-12 15-16-43)
And then actually display it.
12:55
S… Speaker 2 (2026-04-12 15-16-43)
There we go.
12:55
S… Speaker 1 (2026-04-12 15-16-43)
And you have the X button over here on the far right
12:59
S… Speaker 1 (2026-04-12 15-16-43)
hand side of the input,
13:00
S… Speaker 1 (2026-04-12 15-16-43)
which will clear any display filter as well.
13:03
S… Speaker 1 (2026-04-12 15-16-43)
So that's the ways you can do display filters.
13:08
S… Speaker 1 (2026-04-12 15-16-43)
So what we're going to do next is take a look at a feature known as follow
13:12
S… Speaker 1 (2026-04-12 15-16-43)
stream.
13:13
S… Speaker 1 (2026-04-12 15-16-43)
So following stream is a good way to just kind of follow
13:17
S… Speaker 1 (2026-04-12 15-16-43)
the communication and see what was transferred.
13:20
S… Speaker 1 (2026-04-12 15-16-43)
So just as an example,
13:21
S… Speaker 1 (2026-04-12 15-16-43)
we're going to do a follow stream on this TLS connection here.
13:24
S… Speaker 1 (2026-04-12 15-16-43)
To do that,
13:25
S… Speaker 1 (2026-04-12 15-16-43)
you right -click on whatever individual packet you're looking at,
13:29
S… Speaker 1 (2026-04-12 15-16-43)
go down to follow right here,
13:31
S… Speaker 1 (2026-04-12 15-16-43)
and then you'll have different options depending on what the communication is.
13:37
S… Speaker 1 (2026-04-12 15-16-43)
For this,
13:37
S… Speaker 1 (2026-04-12 15-16-43)
we have TCP and TLS.
13:39
S… Speaker 1 (2026-04-12 15-16-43)
We're going to look at TCP stream,
13:40
S… Speaker 1 (2026-04-12 15-16-43)
and you can see,
13:41
S… Speaker 2 (2026-04-12 15-16-43)
well,
13:42
S… Speaker 1 (2026-04-12 15-16-43)
this is nothing at all because this is TLS.
13:46
S… Speaker 1 (2026-04-12 15-16-43)
This is encrypted traffic.
13:47
S… Speaker 1 (2026-04-12 15-16-43)
This is what you're going to see with encrypted traffic in Wireshark.
13:51
S… Speaker 1 (2026-04-12 15-16-43)
Nothing useful at all unless you have
13:55
S… Speaker 1 (2026-04-12 15-16-43)
the proper keys to be able to decrypt it,
13:58
S… Speaker 1 (2026-04-12 15-16-43)
in which case...
14:00
S… Speaker 1 (2026-04-12 15-16-43)
There are ways to do that.
14:01
S… Speaker 1 (2026-04-12 15-16-43)
We will get into that later in this course,
14:04
S… Speaker 1 (2026-04-12 15-16-43)
though. And as you can see,
14:05
S… Speaker 1 (2026-04-12 15-16-43)
when we did the follow stream,
14:07
S… Speaker 1 (2026-04-12 15-16-43)
it actually created a display filter for
14:11
S… Speaker 1 (2026-04-12 15-16-43)
us.
14:11
S… Speaker 1 (2026-04-12 15-16-43)
TCP .stream equals zero.
14:14
S… Speaker 1 (2026-04-12 15-16-43)
So EQ can be used also depending on,
14:18
S… Speaker 2 (2026-04-12 15-16-43)
or if you can,
14:18
S… Speaker 1 (2026-04-12 15-16-43)
you know, you can do EQ or the two equal signs.
14:21
S… Speaker 1 (2026-04-12 15-16-43)
It just depends.
14:22
S… Speaker 1 (2026-04-12 15-16-43)
So we'll clear out this filter.
14:26
S… Speaker 1 (2026-04-12 15-16-43)
And let's find some HTTP traffic.
14:30
S… Speaker 2 (2026-04-12 15-16-43)
Here we go.
14:31
S… Speaker 1 (2026-04-12 15-16-43)
So we got HTTP traffic right here.
14:34
S… Speaker 1 (2026-04-12 15-16-43)
I'm going to right -click here,
14:35
S… Speaker 2 (2026-04-12 15-16-43)
go to follow,
14:36
S… Speaker 1 (2026-04-12 15-16-43)
and you see now we have TCP stream and HTTP
14:40
S… Speaker 1 (2026-04-12 15-16-43)
stream.
14:41
S… Speaker 1 (2026-04-12 15-16-43)
I want to follow the HTTP.
14:42
S… Speaker 1 (2026-04-12 15-16-43)
And you can see here,
14:44
S… Speaker 1 (2026-04-12 15-16-43)
we've got a lot more usable and readable information.
14:48
S… Speaker 1 (2026-04-12 15-16-43)
So you can see the very first thing,
14:50
S… Speaker 1 (2026-04-12 15-16-43)
and these are all of the HTML commands.
14:53
S… Speaker 1 (2026-04-12 15-16-43)
the get information,
14:55
S… Speaker 1 (2026-04-12 15-16-43)
the server responses.
14:57
S… Speaker 1 (2026-04-12 15-16-43)
So when you can see down here,
14:59
S… Speaker 1 (2026-04-12 15-16-43)
it's a little difficult to see,
15:02
S… Speaker 1 (2026-04-12 15-16-43)
but at the bottom left -hand side of the window,
15:04
S… Speaker 1 (2026-04-12 15-16-43)
it actually will tell you the color code for how it's
15:08
S… Speaker 1 (2026-04-12 15-16-43)
displayed.
15:08
S… Speaker 1 (2026-04-12 15-16-43)
So red displayed text is client communication,
15:12
S… Speaker 1 (2026-04-12 15-16-43)
blue is server communication.
15:14
S… Speaker 1 (2026-04-12 15-16-43)
And you can kind of infer that from the HTML command.
15:17
S… Speaker 1 (2026-04-12 15-16-43)
We're doing a get here on the root of the directory.
15:21
S… Speaker 1 (2026-04-12 15-16-43)
And we have some information about the headers as well.
15:25
S… Speaker 1 (2026-04-12 15-16-43)
And then we have the HTTP reply.
15:28
S… Speaker 1 (2026-04-12 15-16-43)
And you can see as you click on each section,
15:30
S… Speaker 1 (2026-04-12 15-16-43)
it follows the packet in the background.
15:34
S… Speaker 1 (2026-04-12 15-16-43)
You can also see we have a TCP stream equals 7 as
15:38
S… Speaker 1 (2026-04-12 15-16-43)
a display filter.
15:41
S… Speaker 1 (2026-04-12 15-16-43)
And we can see this is running on an Nginx server on
15:45
S… Speaker 1 (2026-04-12 15-16-43)
Ubuntu and some other information about the content
15:49
S… Speaker 1 (2026-04-12 15-16-43)
and the HTML headers.
15:51
S… Speaker 1 (2026-04-12 15-16-43)
Followed up,
15:52
S… Speaker 1 (2026-04-12 15-16-43)
because we were doing a GET request on this HTTP server,
15:56
S… Speaker 1 (2026-04-12 15-16-43)
we have our HTML code,
15:58
S… Speaker 1 (2026-04-12 15-16-43)
which is shown here in plain text because this is not encrypted traffic.
16:02
S… Speaker 1 (2026-04-12 15-16-43)
And this is one that I specifically went to.
16:06
S… Speaker 1 (2026-04-12 15-16-43)
httpforever .com because it is not in,
16:09
S… Speaker 1 (2026-04-12 15-16-43)
it is not a TLS site.
16:11
S… Speaker 1 (2026-04-12 15-16-43)
It is not encrypted.
16:12
S… Speaker 1 (2026-04-12 15-16-43)
And it shows,
16:13
S… Speaker 1 (2026-04-12 15-16-43)
you know, all of the HTML code.
16:15
S… Speaker 1 (2026-04-12 15-16-43)
This is exactly the same information you would see if you
16:19
S… Speaker 1 (2026-04-12 15-16-43)
right -clicked and viewed page source.
16:22
S… Speaker 1 (2026-04-12 15-16-43)
And it continues the communication.
16:24
S… Speaker 1 (2026-04-12 15-16-43)
We have additional files that this root file directed us to
16:28
S… Speaker 1 (2026-04-12 15-16-43)
get. So we're getting what looks like a JavaScript file right here.
16:31
S… Speaker 1 (2026-04-12 15-16-43)
It's returning the JavaScript file.
16:34
S… Speaker 1 (2026-04-12 15-16-43)
We see the JavaScript code.
16:35
S… Speaker 1 (2026-04-12 15-16-43)
We also see what looks like some CSS code as we scroll
16:39
S… Speaker 1 (2026-04-12 15-16-43)
further down.
16:40
S… Speaker 1 (2026-04-12 15-16-43)
So there's a lot of different
16:44
S… Speaker 1 (2026-04-12 15-16-43)
information that it's getting.
16:46
S… Speaker 1 (2026-04-12 15-16-43)
We'll scroll past that giant box of text.
16:48
S… Speaker 1 (2026-04-12 15-16-43)
We see that we are pulling image files as well.
16:52
S… Speaker 1 (2026-04-12 15-16-43)
And it shows all of that information.
16:58
S… Speaker 1 (2026-04-12 15-16-43)
One other thing I wanted to show here is
17:03
S… Speaker 1 (2026-04-12 15-16-43)
the kind of two different panes here at the bottom.
17:06
S… Speaker 1 (2026-04-12 15-16-43)
So we are highlighted on this 200 OK.
17:10
S… Speaker 1 (2026-04-12 15-16-43)
This is the response from the HTML server.
17:13
S… Speaker 1 (2026-04-12 15-16-43)
And we can expand these fields down here to get more information.
17:17
S… Speaker 1 (2026-04-12 15-16-43)
And this is exactly what we saw in the follow stream
17:22
S… Speaker 1 (2026-04-12 15-16-43)
window as well.
17:23
S… Speaker 1 (2026-04-12 15-16-43)
So you can view it in many different ways.
17:27
S… Speaker 1 (2026-04-12 15-16-43)
depending on what your preference is and kind of what information you're
17:31
S… Speaker 1 (2026-04-12 15-16-43)
looking at.
17:32
S… Speaker 1 (2026-04-12 15-16-43)
So you can see if we expand this,
17:34
S… Speaker 1 (2026-04-12 15-16-43)
it's not going to show all of the information.
17:36
S… Speaker 1 (2026-04-12 15-16-43)
It only shows 100 lines here.
17:37
S… Speaker 1 (2026-04-12 15-16-43)
But this is still the HTML code that
17:42
S… Speaker 1 (2026-04-12 15-16-43)
we saw previously,
17:43
S… Speaker 1 (2026-04-12 15-16-43)
just in a little more difficult way to
17:47
S… Speaker 1 (2026-04-12 15-16-43)
view it and just slightly worse formatting.
17:51
S… Speaker 1 (2026-04-12 15-16-43)
But it is meant to show it in more of a raw format as
17:55
S… Speaker 1 (2026-04-12 15-16-43)
well.
17:56
S… Speaker 1 (2026-04-12 15-16-43)
So many different ways to display
18:00
S… Speaker 1 (2026-04-12 15-16-43)
information in Wireshark,
18:01
S… Speaker 1 (2026-04-12 15-16-43)
to search for information,
18:04
S… Speaker 1 (2026-04-12 15-16-43)
to get a summary of the information in Wireshark.
18:07
S… Speaker 1 (2026-04-12 15-16-43)
And again, we're just barely scratching the surface
18:12
S… Speaker 1 (2026-04-12 15-16-43)
of some of the packet analysis features here in Wireshark.
18:16
S… Speaker 1 (2026-04-12 15-16-43)
We'll get more in -depth on some of the ways you can search for
18:20
S… Speaker 1 (2026-04-12 15-16-43)
specific traffic and kind of what to look for in the analysis
18:25
S… Speaker 1 (2026-04-12 15-16-43)
as we start getting into more of the ways
18:29
S… Speaker 1 (2026-04-12 15-16-43)
to recognize abnormal or suspicious traffic.

Овој препис беше создаден од МА (автоматско препознавање на говорот). Може да содржи грешки — потврда против оригиналниот аудио за критична употреба. Политика на ВИ

❤️ Љубов STT.ai?
Кратка резиме
Кликнете на Summarize за да генерирате AI резиме на овој транскрипт.
Сумирам...
Прашај го ВИ за овој текст
Прашај било што за овој препис — АИ ќе најде релевантни делови и одговор.