Wireshark Cheat Sheet
Network protocol analyzer. It uses the pcapng file format.
Settings
Datetime Format When Packets Sent
Select “View → Time Display Format → Date and Time of Day”.
Filters
Enter the following text in a filtering form.
Datetime
DNS
FTP
HTTP & HTTPS
ICMP
IP Address
SMB
SMTP
SSH
Detailed Information
Right click on the row item.
Select Follow -> TCP Stream. Another window opens.
Find information by clicking the arrow on the right of "Stream *".
More Information
Analyze -> Expert Information
Read the expert information.
Statistics -> Capture File Properties
Read the capture file comments.
Statistics → Conversations
List IP conversations. We can find IP addresses involved in the traffic.
Statistics → Protocol Hierarchy
Show usage of ports and services.
View -> Name Resolution
Resolve IP addresses.
Data Exfiltration via DNS
Enter "dns" in filter form
If you found a domain such as follow, you may be able to retrieve threats.
For example, decode "936...".
Data Exfiltration via HTTP
Open File -> Export Objects -> HTTP... .
Click "Save all".
Analyze steganographic files using tools like steghide.
WiFi Handshakes
When importing pcap file, then if we found the capture file is about WiFi handshakes, we can crack the WiFi password using this file.
Last updated