Wireshark is an efficient utility packed with an advanced set of features that assist security professionals in performing passive analysis of network traffic to identify and point out malicious packets and anomalies.
This chapter will guide you through how to use Wireshark to analyze security issues, such as analyzing malware traffic and footprinting attempts. We will cover the following topics:
- Analyzing port scanning, footprinting, and attack/exploitation network traffic
- Dissecting malicious ARP traffic
- Analyzing brute force attacks
- Inspecting malicious traffic
- Creating display and capture filter signatures for malicious traffic
Using real-life scenarios simulated in a virtual network infrastructure, we will capture and understand malicious traffic patterns and replicate attacks such as information gathering and exploitation attempts. We will...