Help!! Network fore...
 
Notifications
Clear all

Help!! Network forensics: WireShark: detecting an intrusion

4 Posts
3 Users
0 Likes
599 Views
(@ryanvanderberg)
Posts: 2
New Member
Topic starter
 

I am faced with the task of detecting an intrusion (either internal or external) using packet analysis techniques with WireShark packet analysis tool. Please may someone explain to me how I may go about this / things I should look out for. Thanks!

 
Posted : 28/02/2020 1:53 pm
 BDME
(@bdme)
Posts: 10
Active Member
 

Is this for school?

Anyway, if you already have your logs allow Wireshark to parse the logs, then filter the Event IDs. I would go through and if you are unfamiliar with what the event ID is referencing then google that event ID. Once you become more familiar with what Wireshark is parsing out for you then filter by time and look for event IDs pertaining to what you are looking for. I don't have it installed on my computer at this moment but it may give an explanation of what the event IDs are referencing, however I recall them sometimes being unhelpful.

 
Posted : 28/02/2020 3:26 pm
(@ryanvanderberg)
Posts: 2
New Member
Topic starter
 

Is this for school?

Anyway, if you already have your logs allow Wireshark to parse the logs, then filter the Event IDs. I would go through and if you are unfamiliar with what the event ID is referencing then google that event ID. Once you become more familiar with what Wireshark is parsing out for you then filter by time and look for event IDs pertaining to what you are looking for. I don't have it installed on my computer at this moment but it may give an explanation of what the event IDs are referencing, however I recall them sometimes being unhelpful.

Thank you for your response, which I shall print and attempt to follow. Thanks for taking the time to write such a detailed response.

 
Posted : 28/02/2020 4:27 pm
doublezero
(@doublezero)
Posts: 12
Active Member
 

look for ARP and MAC flooding in the network, as they are common in intrusions.
Loads of ICMP packets are also common in recon of private network though ping scans.

 
Posted : 23/03/2020 7:21 pm
Share: