From the course: Wireshark: Malware and Forensics

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Using statistics

Using statistics - Wireshark Tutorial

From the course: Wireshark: Malware and Forensics

Start my 1-month free trial

Using statistics

- [Instructor] When doing malware analysis, it's good practice to explore Wireshark Statistics menu choice. We can see that there are many options for analyzing a packet capture. When looking at the statistics choices, we see that there are general statistics that include capture file properties, protocol hierarchy, conversations, endpoints, and IO graphs. In addition, there are protocols specific and advanced statistics. Those include service response times, DNS and HTTP, IP version 4 and IP version 6, flow graphs, and TCP stream graphs. When doing malware analysis, I take a look at a couple of the choices including endpoints. Now this is traffic to and from a single IP address. Conversations, this is traffic between two endpoints. And protocol hierarchy, this helps us to analyze unusual or suspicious protocols on the network. When I met this packet capture, and here I've gotten this capture from a client who…

Contents