Wireshark Forensics Toolkit

By Rishikesh Bhide on 10 Nov 2021 @ Blackhat : Arsenal
πŸ’» Source Code πŸ”— Link
malware forensic
Focus Areas: Incident Response , Malware Analysis
This Tool Demo covers following tools where the speaker has contributed or authored
WIRESHARK FORENSICS TOOLKIT

Abstract

Wireshark is the most widely used network traffic analyzer. It is an important tool for both live traffic analysis & forensic analysis for forensic/malware analysts. Even though Wireshark provides incredibly powerful functionalities for protocol parsing & filtering, it does not provide any contextual information about network endpoints. For a typical analyst, who has to comb through GBs of PCAP files to identify malicious activity, it’s like finding a needle in a haystack.

Wireshark Forensics Toolkit is a cross-platform Wireshark plugin that correlates network traffic data with threat intelligence, asset categorization & vulnerability data to speed up network forensic analysis. It does it by extending Wireshark native search filter functionality to allow filtering based on these additional contextual attributes. It works with both PCAP files and real-time traffic captures.

This toolkit provides the following functionality