Learn, investigate, and document network evidence.
NetForensics brings together practical utilities, wireless and packet-capture labs, field guides, and books for analysts who need to investigate real network attacks.
A practical home for network forensics learning.
Wireless forensics is one major part of NetForensics, but the resource library is broader: packets, logs, malware traffic, protocol abuse, encrypted sessions, timelines, reporting, and repeatable investigation workflows.
The site pairs working utilities with field notes, labs, and book companion material so analysts can move from raw artifacts to validated conclusions.
Open utilities first
Use practical tools to extract evidence, review packet captures, and keep analysis notes tied to repeatable methods.
Books with companion resources
The books provide structured learning paths while the site gives readers practical utilities, labs, and reference notes.
Forensic workflows, not tricks
Every tool and guide should help an analyst preserve evidence, explain observations, and validate conclusions.
Tools analysts can use today.
Wireless PCAP Analyzer
Upload authorized captures, extract 802.11 events, review WPA/WPA3 posture, identify rogue AP candidates, and export reports.
Analyze a captureMAC and OUI Lookup
Normalize MAC addresses, classify local/global/multicast addresses, and explain vendor confidence for investigations.
View tool notesWireshark Filter Builder
Generate common display filters for DNS, TLS, HTTP, EAPOL, deauthentication, beacon, and suspicious endpoint review.
View tool notesUse the site as a field guide.
Start with evidence
Understand PCAP sources, timestamps, hashes, chain of custody, and how to avoid overclaiming from incomplete captures.
Decode traffic
Move from protocols and endpoints to timelines, suspicious flows, wireless artifacts, malware traffic, and service abuse.
Write the report
Convert observations into a defensible investigation narrative with validation filters and supporting raw artifacts.
Published network forensics references.
Nipun Jaswal's network forensics books are paired with practical companion material: utilities, labs, checklists, and topic pages that support hands-on study.
Open book hubMastering Network Forensics
A broader practical path through traffic analysis, logs, malware investigation, wireless forensics, and incident response.
Hands-On Network Forensics
A hands-on introduction to investigating network attacks and finding evidence with common forensic tools.