Skip to content

Network forensics

Network forensics reconstructs malicious activity from traffic: packet captures (PCAP), flows (NetFlow), and network logs (firewall, proxy, DNS). It’s key to identifying C2, exfiltration, and lateral movement, and is often the only evidence when the endpoint was cleaned.

PCAP full packet capture (content) -> maximum detail, high volume
NetFlow flow metadata (who talked to whom, when, how much) -> scales better
Logs firewall, proxy (URLs), DNS (queries), IDS/IPS (alerts), NDR
Zeek generates rich logs from traffic (conn, dns, http, ssl, files...)
Wireshark deep inspection, follow stream, statistics, object export
tshark Wireshark in CLI to automate/filter at scale
Zeek convert PCAP to structured logs (basis for detection/hunting)
Suricata run signatures over the PCAP to detect known threats
NetworkMiner extract files, credentials, and sessions from the PCAP
C2 / beaconing periodic connections to a destination (jitter, similar sizes, see mal-c2)
DNS queries to DGA/odd domains, anomalous TXT, volume (tunneling)
Exfiltration large uploads to external destinations, covert channels
Lateral SMB/RDP/WMI between internal hosts (see ad-lateral)
TLS JA3/JA3S of known families, self-signed/anomalous certificates
Files payloads/documents transferred (export objects)
RITA / Zeek traffic periodicity analysis -> detect C2 beaconing
# correlate the destination with threat intel (cti-ioc) and with the endpoint process (dfir-win-art)
- TLS encrypts the content: with PCAP you only see metadata (SNI, JA3, sizes, timing)
- decryption possible with session keys (SSLKEYLOGFILE) or authorized MITM (crypto-tls)
- hence the value of JA3 and behavioral analysis over encrypted traffic
  • Capture at key points (perimeter, between zones) and retain PCAP/NetFlow for retrospective IR.
  • Zeek + Suricata + NDR turn traffic into actionable logs and alerts (Network hardening/SIEM).
  • Correlate network ↔ endpoint ↔ identity: C2 seen on the network has a process behind it (Memory forensics).
  • Detecting Cobalt Strike via beaconing and JA3 is a classic network-forensics use case.
  • DNS tunneling and domain fronting detected by query and volume analysis (Command & Control).
  • Exfiltrations reconstructed from NetFlow/proxy when the endpoint had no evidence left.
  • Identify available sources (PCAP/NetFlow/logs/Zeek)
  • Beacon analysis (RITA/Zeek) for C2
  • Review DNS (DGA, TXT, volume) and TLS (JA3, certs)
  • Look for exfiltration (large uploads, covert channels)
  • Internal lateral movement (SMB/RDP/WMI)
  • Extract files/payloads from the PCAP → triage (Malware triage)
  • Correlate destinations with TI (IOCs & TTPs) and the endpoint