Network forensics resource hub

Learn, investigate, and document network evidence.

NetForensics brings together practical utilities, wireless and packet-capture labs, field guides, and books for analysts who need to investigate real network attacks.

PCAP analysis Wireless forensics Incident timelines Book companion resources
CapturePCAP, logs, metadata
DecodeProtocols, sessions, WLAN
CorrelateTimeline and artifacts
ReportEvidence and narrative
Why this site exists

A practical home for network forensics learning.

Wireless forensics is one major part of NetForensics, but the resource library is broader: packets, logs, malware traffic, protocol abuse, encrypted sessions, timelines, reporting, and repeatable investigation workflows.

The site pairs working utilities with field notes, labs, and book companion material so analysts can move from raw artifacts to validated conclusions.

01

Open utilities first

Use practical tools to extract evidence, review packet captures, and keep analysis notes tied to repeatable methods.

02

Books with companion resources

The books provide structured learning paths while the site gives readers practical utilities, labs, and reference notes.

03

Forensic workflows, not tricks

Every tool and guide should help an analyst preserve evidence, explain observations, and validate conclusions.

Featured utilities

Tools analysts can use today.

Live

Wireless PCAP Analyzer

Upload authorized captures, extract 802.11 events, review WPA/WPA3 posture, identify rogue AP candidates, and export reports.

Analyze a capture
In design

MAC and OUI Lookup

Normalize MAC addresses, classify local/global/multicast addresses, and explain vendor confidence for investigations.

View tool notes
In design

Wireshark Filter Builder

Generate common display filters for DNS, TLS, HTTP, EAPOL, deauthentication, beacon, and suspicious endpoint review.

View tool notes
Learning tracks

Use the site as a field guide.

Start with evidence

Understand PCAP sources, timestamps, hashes, chain of custody, and how to avoid overclaiming from incomplete captures.

Decode traffic

Move from protocols and endpoints to timelines, suspicious flows, wireless artifacts, malware traffic, and service abuse.

Write the report

Convert observations into a defensible investigation narrative with validation filters and supporting raw artifacts.

Books

Published network forensics references.

Nipun Jaswal's network forensics books are paired with practical companion material: utilities, labs, checklists, and topic pages that support hands-on study.

Open book hub
BPB PublicationsMastering Network Forensics2024

Mastering Network Forensics

A broader practical path through traffic analysis, logs, malware investigation, wireless forensics, and incident response.

Packt PublishingHands-On Network Forensics2019

Hands-On Network Forensics

A hands-on introduction to investigating network attacks and finding evidence with common forensic tools.