网流析患
原名:analyzing-network-traffic-for-incidents
分析网络流量捕获和流数据,以识别安全事件期间的对手活动,包括
- 分类
- 开发提效
- 版本
- v1.0.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-09-06
- TRACE 评分
- 3.4 / 5
内容概览
- SIEM alerts on anomalous network traffic patterns requiring deeper investigation - C2 beaconing is suspected and needs confirmation through packet-level analysis - Data exfiltration volume or destination must be quantified from network evidence - Lateral movement between systems needs to be traced through network connections - An IDS/IPS alert requires packet-level validation to confirm or dismiss Do not use for host-based forensic analysis (process execution, file system artifacts); use endpoint forensics tools instead. - Full packet capture (PCAP) infrastructure or on-demand capture capability (network tap, SPAN port) - Wireshark installed on the analysis workstation with appropriate display filters knowledge - Zeek (formerly Bro) deployed for network metadata generation (conn.log, dns.log, http.log, ssl.log) - NetFlow/IPFIX collection from network devices for traffic flow analysis -…