Locating sample captures
While learning about packet analysis, it's important to study a variety of captures until you are proficient at knowing what to look for in a file. This may take a while, but it will be well worth the effort.
First, let's see how PacketLife.net
provides a handy way to open and examine a packet capture, right in CS.
Examining captures
When working with packet captures, you may want to learn about an unfamiliar protocol with your team. Today there are many places to obtain packet captures; one site I visit often is https://packetlife.net/.
Once at PacketLife.net
, navigate to http://packetlife.net/captures/, where you can search for captures. For example, I found snmp-ipv4.pcap
, as shown in the following screenshot:
After you have found a packet capture, you can open it directly in CS, as shown here: