Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Download the network_traffic.pcapng file, which was captured on one Kali box in the class infrastructure. Based on the network knowledge that you learned from this
Download the network_traffic.pcapng file, which was captured on one Kali box in the class infrastructure. Based on the network knowledge that you learned from this class so far, analyze the network traffic using Wireshark, and write a one-page report. From the packet capture, what activities can you infer about the users on the class network when the packets were captured? Please explain your answers with evidence you gather from the pcap file. Don't include screen shots. If you need to refer to packets, use the packet number you can observe from Wireshark. Please note that you will see many RDP related traffic which is not interesting, and you do not need to report anything regarding this traffic eth.addr == 00:11:11:00:11:15 ip.addr == 192.168.0.5 !(ip.addr == 192.168.0.5) tcp udp iCmp arp !(tcp.port == 53) tcp.port == 80 || udp.port == 80 http not arp and not (udp.port == 53) not (tcp.port == 80) and not (tcp.port == 25) and ip.addr == 192.168.0.5 Download the network_traffic.pcapng file, which was captured on one Kali box in the class infrastructure. Based on the network knowledge that you learned from this class so far, analyze the network traffic using Wireshark, and write a one-page report. From the packet capture, what activities can you infer about the users on the class network when the packets were captured? Please explain your answers with evidence you gather from the pcap file. Don't include screen shots. If you need to refer to packets, use the packet number you can observe from Wireshark. Please note that you will see many RDP related traffic which is not interesting, and you do not need to report anything regarding this traffic eth.addr == 00:11:11:00:11:15 ip.addr == 192.168.0.5 !(ip.addr == 192.168.0.5) tcp udp iCmp arp !(tcp.port == 53) tcp.port == 80 || udp.port == 80 http not arp and not (udp.port == 53) not (tcp.port == 80) and not (tcp.port == 25) and ip.addr == 192.168.0.5
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started