Wireshark notes

Filters and dissector workflows for forensic review.

This section will grow into a practical library of filters, protocol notes, and validated workflows that support the tools and book companion material.

Wireless management frames

Filters and workflows for beacon, probe, association, authentication, deauthentication, EAPOL, and PMF posture analysis.

Remote-access metadata

Flow classification, session timing, and investigation notes without unsupported payload-decryption claims.

Long-lived sessions

Workflows for reviewing persistent connections, keepalives, command channels, and endpoint correlation.

DNS and HTTP triage

Filters for suspicious domains, redirects, user agents, status codes, and staging infrastructure.

TLS review

Workflows for certificate fields, SNI, session metadata, timing, and endpoint behavior.

Report validation filters

Reusable filters that let analysts verify report claims directly in Wireshark.