Network forensics
Network forensics reconstructs malicious activity from traffic: packet captures (PCAP), flows (NetFlow), and network logs (firewall, proxy, DNS). It’s key to identifying C2, exfiltration, and lateral movement, and is often the only evidence when the endpoint was cleaned.
Sources
Section titled “Sources”PCAP full packet capture (content) -> maximum detail, high volumeNetFlow flow metadata (who talked to whom, when, how much) -> scales betterLogs firewall, proxy (URLs), DNS (queries), IDS/IPS (alerts), NDRZeek generates rich logs from traffic (conn, dns, http, ssl, files...)PCAP analysis
Section titled “PCAP analysis”Wireshark deep inspection, follow stream, statistics, object exporttshark Wireshark in CLI to automate/filter at scaleZeek convert PCAP to structured logs (basis for detection/hunting)Suricata run signatures over the PCAP to detect known threatsNetworkMiner extract files, credentials, and sessions from the PCAPWhat to look for
Section titled “What to look for”C2 / beaconing periodic connections to a destination (jitter, similar sizes, see mal-c2)DNS queries to DGA/odd domains, anomalous TXT, volume (tunneling)Exfiltration large uploads to external destinations, covert channelsLateral SMB/RDP/WMI between internal hosts (see ad-lateral)TLS JA3/JA3S of known families, self-signed/anomalous certificatesFiles payloads/documents transferred (export objects)Beacon analysis and detection
Section titled “Beacon analysis and detection”RITA / Zeek traffic periodicity analysis -> detect C2 beaconing# correlate the destination with threat intel (cti-ioc) and with the endpoint process (dfir-win-art)Decryption and limitations
Section titled “Decryption and limitations”- TLS encrypts the content: with PCAP you only see metadata (SNI, JA3, sizes, timing)- decryption possible with session keys (SSLKEYLOGFILE) or authorized MITM (crypto-tls)- hence the value of JA3 and behavioral analysis over encrypted trafficBlue Team / DFIR
Section titled “Blue Team / DFIR”- Capture at key points (perimeter, between zones) and retain PCAP/NetFlow for retrospective IR.
- Zeek + Suricata + NDR turn traffic into actionable logs and alerts (Network hardening/SIEM).
- Correlate network ↔ endpoint ↔ identity: C2 seen on the network has a process behind it (Memory forensics).
Real-world cases
Section titled “Real-world cases”- Detecting Cobalt Strike via beaconing and JA3 is a classic network-forensics use case.
- DNS tunneling and domain fronting detected by query and volume analysis (Command & Control).
- Exfiltrations reconstructed from NetFlow/proxy when the endpoint had no evidence left.
Testing checklist
Section titled “Testing checklist”- Identify available sources (PCAP/NetFlow/logs/Zeek)
- Beacon analysis (RITA/Zeek) for C2
- Review DNS (DGA, TXT, volume) and TLS (JA3, certs)
- Look for exfiltration (large uploads, covert channels)
- Internal lateral movement (SMB/RDP/WMI)
- Extract files/payloads from the PCAP → triage (Malware triage)
- Correlate destinations with TI (IOCs & TTPs) and the endpoint