Network Forensics & Packet Interception
Network forensics investigation capturing and analysing live traffic from a promiscuous-mode virtual machine. Used Wireshark display filters to isolate and follow suspicious flows, applied to an NSPX30 / Blackwood APT case study to reconstruct attacker behaviour from packet captures. Built and ran the capture environment under VMware, documenting the interception methodology and findings.
Stack
WiresharkVMware