Analysis Tshark · AgentSecOps/SecOpsAgentKit

Analyze network packet captures for security investigations

Uses tshark, the command-line Wireshark tool, to inspect network traffic for authorized security investigations—filtering packets, extracting files, and spotting anomalies during incident response or forensic analysis.

Good for

  • Filter a pcap file for suspicious traffic
  • Extract files transferred over HTTP
  • Investigate a network incident during forensics
Category
Research

Open-source skills are maintained by their authors and listed as published, with attribution. Results depend on how well the skill fits your task and material.

A good place to start

Analyze this pcap file for signs of malware traffic using tshark.

Make your next great thing.

Bring a question, a file, or an idea that’s not quite there yet.