analyzing-network-traffic-for-incidents

Featured

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic analysis, packet capture investigation, PCAP analysis, network forensics, C2 traffic detection, or exfiltration detection.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Analyzing Network Traffic for Incidents ## When to Use - SIEM alerts on anomalous network traffic patterns requiring deeper investigation - C2 beaconing is suspected and needs confirmation through packet-level analysis - Data exfiltration volume or destination must be quantified from network evidence - Lateral movement between systems needs to be traced through network connections - An IDS/IPS alert requires packet-level validation to confirm or dismiss **Do not use** for host-based forensic analysis (process execution, file system artifacts); use endpoint forensics tools instead. ## Prerequisites - Full packet capture (PCAP) infrastructure or on-demand capture capability (network tap, SPAN port) - Wireshark installed on the analysis workstation with appropriate display filters knowledge - Zeek (formerly Bro) deployed for network metadata generation (conn.log, dns.log, http.log, ssl.log) - NetFlow/IPFIX collection from network devices for traffic flow analysis - Network architecture diagram showing VLAN layout, firewall placement, and monitoring points - Threat intelligence feeds for correlating observed network indicators ## Workflow ### Step 1: Capture or Acquire Network Traffic Obtain the relevant traffic data for the investigation: **Live Capture (if incident is active):** ```bash # Capture on specific interface filtering by host tcpdump -i eth0 -w capture.pcap host 10.1.5.42 # Capture C2 traffic to specific external IP tcpdump -i eth0 -w c2_traffic.pcap host ...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

analyzing-network-traffic-with-wireshark

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.

12,642 Updated today
mukul975
AI & Automation Listed

analyzing-network-traffic-with-wireshark

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.

6 Updated today
26zl
AI & Automation Featured

performing-network-forensics-with-wireshark

Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.

12,642 Updated today
mukul975
AI & Automation Featured

analyzing-network-traffic-of-malware

Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding, malware PCAP analysis, or network-based malware detection.

12,642 Updated today
mukul975
AI & Automation Featured

performing-network-packet-capture-analysis

Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity.

12,642 Updated today
mukul975