#NetworkForensics

2025-11-01

Introduction to Network Threat Detection with @suricata by Lukas Sismis at @openalt in Brno.

Perfect start of the conference day with analysis of #pcap from #anyrun and @malware_traffic

#weekend #education #networkforensics #BlueTeam

Lukas Sismis and Introduction to Network Traffic Detection with Suricata, intro slideQuick intro to AnyRun user interface
2025-09-02

Get excited for SharkFest’25 EUROPE in Warsaw, packed with powerful sessions that will sharpen your packet analysis skills!

- From Full Capture to Criminal Evidence - A Real-World Case of Lawful Interception: Join Daniel Spiekermann as he walks through a forensic investigation using nothing but sustained packet captures and Wireshark.

- A Wireshark-driven approach to understanding + troubleshooting MPLS (Pierre Besombes & Juan Pablo Azar Ricciardi): Dive deep into MPLS troubleshooting with Wireshark as your guide. Explore packet structures, label exchanges, and real-world traffic engineering scenarios.

- HTTP deep dive: With HTTP/2 & HTTP/3 now ubiquitous, André Luyer demystifies modern HTTP traffic. Understand nuances like status codes, caching behavior, cookie quirks, compression, & API-troubleshooting.

Don’t miss these sessions and many more when we gather November 3–7, 2025 in Warsaw, Poland.

Secure your spot and explore the full agenda: sharkfest.wireshark.org/sfeu

#sf25eu #Wireshark #PacketAnalysis #NetworkForensics #MPLS #HTTP #Cybersecurity

ECS Infotech Pvt. Ltd.ecsinfotech
2025-08-14

Unmasking Cyber Threats in India

From tracking hackers to safeguarding sensitive data, network forensics is the frontline defense in the digital battlefield. 🚨

Discover its importance, must-have tools, and real-world applications in our ultimate guide. 🛡️

📖 Read more 👉 ecsinfotech.com/the-ultimate-g

The Ultimate Guide to Network Forensics in India: Importance, Tools, and Real-World Applications
2025-08-04

Heading to SharkFest’25 EUROPE in Warsaw? Here are just a few of the session highlights you won’t want to miss:

- From Full Capture to Criminal Evidence: A Real-World Case of Lawful Interception (Daniel Spiekermann)
- Talk with Your Packets: AI-Powered Natural Language Interaction with Packet Captures (John Capobianco)
- Shift the Conversation: Open Source is Free, But Not Free-Free (Kelley Misata)

Join us this November 3-7 in Poland and learn from some of the best in the field.

Register now: sharkfest.wireshark.org/sfeu

#sf25eu #Wireshark #PacketAnalysis #Cybersecurity #OpenSource #NetworkForensics

2025-06-07

Ein weiteres Tool, das ich nutze, ist #NetworkMiner

Es ist ein leistungsstarkes Open-Source-Tool für #NetworkForensics, das mir die Extraktion von Artefakten wie Dateien, Bildern, E-Mails und Passwörtern aus PCAP-Dateien ermöglicht. NetworkMiner kann auch live Netzwerkverkehr erfassen und detaillierte Informationen über jede IP-Adresse aggregieren, was für passive Asset-Discovery und Übersichten über kommunizierende Geräte nützlich ist.

Seit 2007 hat sich NetworkMiner zu einem beliebten Tool für Incident-Response-Teams und Strafverfolgungsbehörden entwickelt und wird weltweit eingesetzt.

Für mich ein unverzichtbares Werkzeug, um Netzwerkdaten effizient und präzise zu analysieren.

😀 ✌🏼

#CyberSecurity #OpenSource #DigitalForensics #InfoSec #NetworkAnalysis #DFIR

2024-11-18

#dfir #knowledgedrop #networkforensics

Came across this gem again: a nice network analysis framework
github.com/arkime/arkime

Ichinin :verified: :verified_paw: ✅🎯🙄Ichinin@infosec.exchange
2024-09-18

So there is an NDIS Capture driver in the virtual switches for Hyper-V... guess what you can do with those? :o) #pcap #packetcapture #networkforensics #dfir

2024-07-08

I had the pleasure to be at a #NetworkForensics training by @netresec last week.

If you have the opportunity to join a training, just do it!

It has been very intense, in-depth and was a lot of fun. You'll learn a lot and you can even win a t-shirt!

#dfir #forensics #DigitalForensics #infosec

A black t-shirt with the silhouette of a RJ-45 port.

Text inside the port: 

PCAP or it didn't happen
www.netresec.com
Tedi Heriyantotedi@infosec.exchange
2024-06-05

Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics. : github.com/mikeroyal/Digital-F

#digitalforensics #mobileforensics #networkforensics #databaseforensics

2024-03-26

If you want to create your custom #packetsniffer based on #Scapy, the recent webcast by #ActiveCountermeasures could be a good starting point.
Bill provided nice explanation and his sniffer template is available on GitHub.

github.com/activecm/sniffer-te

youtube.com/watch?v=gO3OjyyLN4

#networkmonitoring #networkanalysis #networkforensics #networking

2024-03-25

Top 10 #Networking #Tools & Techniques by #ActiveCountermeasures.

I have lot of fun watching this video and there are several useful tips&tricks by Chris and Bill.
Especially recommended to see use cases for #tshark, #tcpdump with #BPF and counting connections per hour from PCAP an #zeek logs

youtube.com/watch?v=0I6W175cUQ

#networkanalysis #networktraffic #networkforensics

2023-07-11

I will present our @civilsphere AI VPN this week at the 20th Conference on Detection of Intrusions and Malware & Vulnerability Assessment Arsenal in Hamburg.

The AI VPN is an AI-based traffic analysis tool to detect and block threats, ensuring enhanced privacy protection automatically. It offers modular management of VPN accounts, automated network traffic analysis, and incident reporting. Using the free-software IDS system, Slips, the AI VPN employs machine learning and threat intelligence for comprehensive traffic analysis. Multiple VPN technologies, such as OpenVPN and Wireguard, are supported, and in-line blocking technologies like Pi-hole provide additional protection.

dimva2023.de #networkdefense #networkforensics

2023-04-25

We're ready for you, #RSA! Here are 5 things to do and see at #RSAC2023:

1. Get the coolest shirt at RSA ➡️ Are you ready to rock?! 🤘 Come get your "Metadata, Master of Packets" signature t-shirt at Corelight booth #1555. Book a demo with our experts to claim your tee >> corelight.com/resources/events

2. Disrupt a cyberattack ➡️ #Cyber defenders, try your hand at our #NetworkForensics CTF simulation today at 10:00 a.m. PST in the Dark Arts Village. Sign up to join us >> corelight.com/resources/events

3. Read our latest announcement — GPT-4 ➡️ ... then see us at booth #1555 to learn how our full range of AI and ML models enable #SOC teams to detect a wider range of sophisticated #cyberattacks >> corelight.com/company/coreligh

4. Reduce risk and cost ➡️ Swing by booth #1555 to learn how to enable your SOC with Corelight + @crowdstrike, @mandiant, and more >> corelight.com/resources/events

5. Eat tacos and drink wine ➡️ Join us and our friends at @mandiant for Taco Tuesday 🌮 and Wine Down Wednesday 🍷. Sign up for the events here >> corelight.com/resources/events

#RSAConference #NetworkSecurity #MachineLearning #ArtificialIntelligence #CyberDefense #DFIR

2023-04-06

Join us at Nuvias booth D043 in hall 7 during Cybersec Europe 2023. We'll be presenting "The Best Cybersecurity Defense is Great Evidence" in the booth on:

- April 19 at 2:00 p.m. GMT+2
- April 20 at 11:00 a.m. GMT+2

Register to join our @corelight session today! mailchi.mp/dlnews.be/cybersec-

#Cybersecurity #CyberDefence #CyberEvent #Cyber #DFIR #NetworkForensics #NetworkSecurity

2023-03-07

Too often I think organizations focus on only protecting compute endpoints. This is a good reminder #APT #ThreatActors do still like to #compromise network devices.

Nice write up on #HiatusRAT #malware compromising routers.

#DFIR #NetworkForensics
blog.lumen.com/new-hiatusrat-r

2023-02-20

If you're keen to learn more about #NetworkForensics or #NSM's, blogs like this which walk you through using #SecurityOnion, with a malicious sample from the wild, are great to practice your skills.

#DFIR

blog.securityonion.net/2023/02

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst