Extracting ZIP files from PCAP with Wireshhark & NetworkMiner, plus analysis with CyberChef

Опубликовано: 13 Июль 2021
на канале: Dr Josh Stroschein - The Cyber Yeti
11,553
like

Extracting files from network traffic is a common task. However, it isn't always as straight-forward as you may hope. In this video, we'll look at extracting a ZIP file from a PCAP. The ZIP file was a means of data exfiltration from some malware. We'll discuss how to extract the ZIP in Wireshark and NetworkMiner. We'll also discuss using CyberChef to convert the raw bytes from the network traffic, unzip the file and view the contents.

Cybersecurity, reverse engineering, malware analysis and ethical hacking content!
🎓 Courses on Pluralsight 👉🏻 https://www.pluralsight.com/authors/j...
🌶️ YouTube 👉🏻 Like, Comment & Subscribe!
🙏🏻 Support my work 👉🏻   / joshstroschein  
🌎 Follow me 👉🏻   / jstrosch  ,   / joshstroschein  
⚙️ Tinker with me on Github 👉🏻 https://github.com/jstrosch


Смотрите видео Extracting ZIP files from PCAP with Wireshhark & NetworkMiner, plus analysis with CyberChef онлайн без регистрации, длительностью часов минут секунд в хорошем качестве. Это видео добавил пользователь Dr Josh Stroschein - The Cyber Yeti 13 Июль 2021, не забудьте поделиться им ссылкой с друзьями и знакомыми, на нашем сайте его посмотрели 11,55 раз и оно понравилось lik людям.