Field guides

Network forensics field guides for practical investigations.

Each guide focuses on a concrete analysis question, explains the evidence to review, and links to related tools, book chapters, or labs where useful.

PCAP triageWireless forensicsWireshark filtersEvidence reportingMalware traffic
Guide library

Start with the current guide library.

Use these references to move from raw evidence to repeatable analysis steps, validation notes, and defensible reporting.

Wireless PCAP Analysis Methods

802.11 management frames, beacon timing, deauthentication, EAPOL review, WPA/WPA3 posture, and rogue AP candidate handling.

Wireless Forensics Lab

A practical lab path for working through wireless evidence and validating automated observations manually.

Guide topics

Field notes for repeatable analysis.

How to triage a PCAP

Start with metadata, endpoints, conversations, DNS, HTTP/TLS, alerts, and timeline anchors.

How to write a forensic report

Separate observations, evidence, assumptions, validation filters, and analyst conclusions.

How to inspect wireless attacks

Review deauthentication, rogue AP candidates, EAPOL sequences, beacon timing, and PMF posture.

Encrypted traffic clues

Explain SNI, certificates, JA3-style fingerprints, timing, volume, and endpoint behavior without payload decryption.

Malware traffic basics

Identify suspicious DNS, beacons, command-and-control patterns, staging, and exfiltration indicators.

Evidence checklist

Build defensible notes around source, hash, timezone, capture location, retention, and limitations.