← Back to SOC Analyst - Blue Team Operations

Lesson 4 of 10

Network Traffic Analysis & IDS/IPS

Wireshark

  • Follow TCP stream, JA3, HTTP host extraction

Suricata/Snort

 alert http any any -> any any (msg:"Suspicious UA"; http.user_agent; content:"curl";)
  • Zeek, Suricata EVE