博客
关于我
强烈建议你试试无所不能的chatGPT,快点击我
Analyze network packet files very carefully
阅读量:4703 次
发布时间:2019-06-09

本文共 1486 字,大约阅读时间需要 4 分钟。

As a professional forensic guy, you can not be too careful to anlyze the evidence. Especially when the case is about malware or hacker. Protect your workstation is your responsibility. You are a professional forensic examiner, so don't get infected when examining the evidence file or network packet files. A friend of mine, she is also a forensic examiner, became victim yesterday. It's too ridiculous!!! She was very embrassing. The reason why she got infected was that she extracted a zip file from a suspicious network packet file and "accessed" that zip file. Then something happened. What a tragedy~

 

Let me show you how to analyze network packet files by using Network Miner. Import the network packet file you captured from the victim's workstation. See the tab "Credentials" we could find some important clue about accout and password.

 

See tab "Files" Network Miner could extract files inside the network packet file. It's very convenient for forensic guys to identify the files transfered.

 

Right click on the suspicious file and you could see where the file is by "Open folder".

 

Now you know where it is. Don't be too exciting. Curiosity killed cats!!!

 

"Life was like a box of chocolates. You never know what you're gonna get." Similarly a forensic guy never know whether any suspicious malware or virus is inside the file or not. So you have to conduct a malware analysis on it. Let me show you the verify result as below:

 

转载于:https://www.cnblogs.com/pieces0310/p/5838773.html

你可能感兴趣的文章
jquery之遍历与事件
查看>>
js对象
查看>>
网页状态码
查看>>
Native开发与JNI机制详解
查看>>
TreeSet基本用法
查看>>
Linux cmus
查看>>
MySQL面试题
查看>>
Storm-0.9.3新特性
查看>>
基于visual Studio2013解决面试题之0503取最大数字字符串
查看>>
RTX基础教程目录
查看>>
instr
查看>>
centos6.9 安装mysql8
查看>>
AX2009使用NPOI导出EXCEL
查看>>
CocoaChina六年了,记我的这六年——六年汇总
查看>>
angular4 ionic3 app
查看>>
HDU 2036 改革春风吹满地 数学题
查看>>
[ActionScript 3.0] AS3 绘制正八面体(线条)
查看>>
.Module高内聚低耦合的思考
查看>>
最短路模板(SPFA POJ2387)
查看>>
windows用户态和内核态
查看>>