Rinse and Repeat: threat hunting with CapLoader and Wireshark
When I was visiting TROOPERS17 in Heidelberg, Germany, I had the chance to follow a 2-day training in Network Forensics by Erik Hjelmvik. I'm glad I did! In this post I want to describe a technique I learned there. This technique is a nice way to investigate captured network traffic to find suspicious or malicious traffic. Although I dislike the term 'threat hunting', this is actually a neat and fast way to hunt for the weird and interesting stuff in a large PCAP-file!
The workflow I want to describe could be called "Rinse and repeat". I like it because it is elegant: simple and flexible, but powerful if used right.
Read more...