ZEEK PCAP JSON JQ |
2023-03-28 | Jesse La Grew | Network Data Collector Placement Makes a Difference |
ZEEK |
2025-02-13/a> | Guy Bruneau | DShield SIEM Docker Updates |
2024-11-26/a> | Jesse La Grew | [Guest Diary] Using Zeek, Snort, and Grafana to Detect Crypto Mining Malware |
2023-03-28/a> | Jesse La Grew | Network Data Collector Placement Makes a Difference |
2023-02-12/a> | Jesse La Grew | PCAP Data Analysis with Zeek |
2022-02-03/a> | Johannes Ullrich | Keeping Track of Your Attack Surface for Cheap |
2021-04-10/a> | Guy Bruneau | Building an IDS Sensor with Suricata & Zeek with Logs to ELK |
PCAP |
2025-01-30/a> | Guy Bruneau | PCAPs or It Didn't Happen: Exposing an Old Netgear Vulnerability Still Active in 2025 [Guest Diary] |
2024-12-26/a> | Jesse La Grew | Capturing Honeypot Data Beyond the Logs |
2023-03-28/a> | Jesse La Grew | Network Data Collector Placement Makes a Difference |
2023-02-12/a> | Jesse La Grew | PCAP Data Analysis with Zeek |
2023-01-02/a> | Xavier Mertens | NetworkMiner 2.8 Released |
2022-11-14/a> | Jesse La Grew | Extracting 'HTTP CONNECT' Requests with Python |
2022-11-02/a> | Brad Duncan | Who put the "Dark" in DarkVNC? |
2021-12-22/a> | Brad Duncan | December 2021 Forensic Contest: Answers and Analysis |
2021-12-08/a> | Brad Duncan | December 2021 Forensic Challenge |
2021-11-04/a> | Brad Duncan | October 2021 Forensic Contest: Answers and Analysis |
2021-10-22/a> | Brad Duncan | October 2021 Contest: Forensic Challenge |
2021-06-30/a> | Brad Duncan | June 2021 Forensic Contest: Answers and Analysis |
2021-06-17/a> | Daniel Wesemann | Network Forensics on Azure VMs (Part #1) |
2021-05-23/a> | Didier Stevens | Video: Making Sense Of Encrypted Cobalt Strike Traffic |
2021-05-19/a> | Brad Duncan | May 2021 Forensic Contest: Answers and Analysis |
2021-05-05/a> | Brad Duncan | May 2021 Forensic Contest |
2021-04-18/a> | Didier Stevens | Decoding Cobalt Strike Traffic |
2021-04-12/a> | Didier Stevens | Example of Cleartext Cobalt Strike Traffic (Thanks Brad) |
2021-04-01/a> | Brad Duncan | April 2021 Forensic Quiz |
2021-03-07/a> | Didier Stevens | PCAPs and Beacons |
2021-01-30/a> | Guy Bruneau | PacketSifter as Network Parsing and Telemetry Tool |
2021-01-05/a> | Johannes Ullrich | Netfox Detective: An Alternative Open-Source Packet Analysis Tool |
2020-12-03/a> | Brad Duncan | Traffic Analysis Quiz: Mr Natural |
2020-11-11/a> | Brad Duncan | Traffic Analysis Quiz: DESKTOP-FX23IK5 |
2020-09-15/a> | Brad Duncan | Traffic Analysis Quiz: Oh No... Another Infection! |
2020-08-05/a> | Brad Duncan | Traffic Analysis Quiz: What's the Malware From This Infection? |
2020-07-15/a> | Brad Duncan | Word docs with macros for IcedID (Bokbot) |
2020-05-20/a> | Brad Duncan | Microsoft Word document with malicious macro pushes IcedID (Bokbot) |
2020-04-08/a> | Brad Duncan | German malspam pushes ZLoader malware |
2020-04-01/a> | Brad Duncan | Qakbot malspam sent from an infected Windows host |
2020-01-05/a> | Didier Stevens | etl2pcapng: Convert .etl Capture Files To .pcapng Format |
2019-12-24/a> | Brad Duncan | Malspam with links to Word docs pushes IcedID (Bokbot) |
2019-12-03/a> | Brad Duncan | Ursnif infection with Dridex |
2019-11-27/a> | Brad Duncan | Finding an Agent Tesla malware sample |
2019-10-29/a> | Xavier Mertens | Generating PCAP Files from YAML |
2019-10-09/a> | Brad Duncan | What data does Vidar malware steal from an infected host? |
2019-10-03/a> | Jim Clausing | Buffer overflows found in libpcap and tcpdump |
2019-05-22/a> | Johannes Ullrich | An Update on the Microsoft Windows RDP "Bluekeep" Vulnerability (CVE-2019-0708) [now with pcaps] |
2019-03-18/a> | Didier Stevens | Wireshark 3.0.0 and Npcap: Some Remarks |
2019-03-11/a> | Didier Stevens | Wireshark 3.0.0 and Npcap |
2018-11-18/a> | Guy Bruneau | Multipurpose PCAP Analysis Tool |
2018-08-15/a> | Xavier Mertens | Truncating Payloads and Anonymizing PCAP files |
2018-06-06/a> | Xavier Mertens | Converting PCAP Web Traffic to Apache Log |
2018-01-18/a> | Xavier Mertens | Comment your Packet Captures! |
2017-09-28/a> | Xavier Mertens | The easy way to analyze huge amounts of PCAP data |
2017-05-26/a> | Lorna Hutcheson | File2pcap - A new tool for your toolkit! |
2017-01-28/a> | Lorna Hutcheson | Packet Analysis - Where do you start? |
2014-06-04/a> | Richard Porter | p0f, Got Packets? |
2013-12-01/a> | Richard Porter | BPF, PCAP, Binary, hex, why they matter? |
2013-06-05/a> | Richard Porter | Wireshark 1.10.0 Stable Released http://www.wireshark.org/download.html |
2011-10-23/a> | Guy Bruneau | tcpdump and IPv6 |
2010-07-04/a> | Manuel Humberto Santander Pelaez | New Winpcap Version |
2010-03-27/a> | Guy Bruneau | Create a Summary of IP Addresses from PCAP Files using Unix Tools |
2009-11-25/a> | Jim Clausing | Updates to my GREM Gold scripts and a new script |
2009-08-13/a> | Jim Clausing | Tools for extracting files from pcaps |
2009-06-28/a> | Guy Bruneau | IP Address Range Search with libpcap |
JSON |
2024-06-15/a> | Didier Stevens | Overview of My Tools That Handle JSON Data |
2024-06-13/a> | Guy Bruneau | The Art of JQ and Command-line Fu [Guest Diary] |
2024-04-17/a> | Rob VandenBrink | The CVE's They are A-Changing! |
2024-02-15/a> | Jesse La Grew | [Guest Diary] Learning by doing: Iterative adventures in troubleshooting |
2023-04-05/a> | Jesse La Grew | Exploration of DShield Cowrie Data with jq |
2023-03-29/a> | Didier Stevens | Extracting Multiple Streams From OLE Files |
2023-03-28/a> | Jesse La Grew | Network Data Collector Placement Makes a Difference |
2023-01-21/a> | Guy Bruneau | DShield Sensor JSON Log to Elasticsearch |
2023-01-08/a> | Guy Bruneau | DShield Sensor JSON Log Analysis |
2022-12-28/a> | Rob VandenBrink | Playing with Powershell and JSON (and Amazon and Firewalls) |
2022-08-08/a> | Johannes Ullrich | JSON All the Logs! |
2022-04-03/a> | Didier Stevens | jo |
2022-04-02/a> | Didier Stevens | curl 7.82.0 Adds --json Option |
2021-12-10/a> | Xavier Mertens | Python Shellcode Injection From JSON Data |
2021-08-29/a> | Guy Bruneau | Filter JSON Data by Value with Linux jq |
2020-11-22/a> | Didier Stevens | Quick Tip: Extracting all VBA Code from a Maldoc - JSON Format |
2018-07-15/a> | Didier Stevens | Video: Retrieving and processing JSON data (BTC example) |
2018-07-14/a> | Didier Stevens | Retrieving and processing JSON data (BTC example) |
2017-11-13/a> | Guy Bruneau | jsonrpc Scanning for root account |
JQ |
2024-06-13/a> | Guy Bruneau | The Art of JQ and Command-line Fu [Guest Diary] |
2024-05-16/a> | Rob VandenBrink | Why yq? Adventures in XML |
2024-01-17/a> | Jesse La Grew | Number Usage in Passwords |
2023-11-09/a> | Guy Bruneau | Routers Targeted for Gafgyt Botnet [Guest Diary] |
2023-07-24/a> | Rob VandenBrink | JQ: Another Tool We Thought We Knew |
2023-04-05/a> | Jesse La Grew | Exploration of DShield Cowrie Data with jq |
2023-03-28/a> | Jesse La Grew | Network Data Collector Placement Makes a Difference |
2022-05-23/a> | Johannes Ullrich | Attacker Scanning for jQuery-File-Upload |
2022-01-08/a> | Didier Stevens | TShark & jq |
2021-08-29/a> | Guy Bruneau | Filter JSON Data by Value with Linux jq |