Overview
Wireshark decodes hundreds of protocols, follows TCP streams, and lets you filter down to a single conversation.\nIt is how you confirm whether credentials are really travelling in cleartext and what an implant is actually sending.\nCapture filters and display filters have different syntax, which trips up most beginners at least once.
Indicators of Compromise
Signals that suggest this is present on a system.
- Promiscuous-mode NIC activity on a workstation
- Captures containing HTTP Basic credentials
- Long-lived packet captures written to disk