Skip to content

Posts tagged: #pcap

How to read DNS in a packet capture: queries and responses, result codes, rare and random-looking domains, and high-level signs of DNS tunnelling, with limits.
What a JA3 fingerprint is, how JA4 differs, why Chrome's extension-order randomization broke JA3 stability, and how defenders use TLS fingerprints in triage.
A fair comparison of Wireshark, tshark, NetworkMiner, Zeek, Zui and PCAP Parser for pcap analysis: strengths, limits, and which tool fits which job.
Why packet captures are sensitive under GDPR and client contracts, how in-browser WebAssembly analysis avoids uploads, and how to verify nothing leaves.
Step-by-step guide to PCAP Parser: load a capture, then read conversations, protocol hierarchy, DNS, HTTP, TLS, extracted files and IOCs, and export results.
How to open a pcap or pcapng file online without installing anything: upload vs in-browser viewers, formats that fail, and what a browser tool can't do.
PCAP vs PCAPNG compared block by block: headers, interfaces, timestamp resolution, metadata, which tools write which format and how to convert safely.