Packet analysis tools – Wireshark, TCPdump, and others
As we all know that at Open Source Interconnection (OSI) layer-3, which is also known as the network layer, the whole communication from one machine to another is in the form of packets. These packets contain the actual information carried over the network channels.
So, the term packet analysis is known as the interception or sniffing of ongoing data to analyze the information, to perform attacks such as a Man in the Middle (MITM) attack, information theft, and forensic analysis. Packet analysis has proved to be very important during red-team operations, especially while bypassing initial network security controls such as Network Access Control (NAC) and performing lateral movements.
The following are some aspects where packet analysis can be very useful:
- To analyze the issues in a network such as bandwidth choking and communication issues.
- To identify whether a network is compromised and an attacker is...