Extracting ZIP files from PCAP with Wireshhark & NetworkMiner, plus analysis with CyberChef

Поділитися
Вставка
  • Опубліковано 14 січ 2025

КОМЕНТАРІ • 16

  • @jstrosch
    @jstrosch  Рік тому +1

    Getting started on your cyber security journey? Click the subscribe button, I have a lot of content already here to help you get started and more on the way! If you're looking for full courses, consider checking out my content on Pluralsight - www.pluralsight.com/authors/josh-stroschein

  • @stunnx4421
    @stunnx4421 Рік тому +1

    This was a good one. I didn't know that unzip was also available in cyberchef. Thanks!

  • @ryanleong6266
    @ryanleong6266 Рік тому +2

    Well explained and easy to follow! Definitely going to check out your other videos

  • @Manavetri
    @Manavetri 8 місяців тому +1

    In every video I learn something new !!!, I'm really appreciate this, thank you

    • @jstrosch
      @jstrosch  8 місяців тому

      That's great to hear - thank you for the feedback!

  • @SasidharanCS
    @SasidharanCS Рік тому +2

    This protocol used in Enthiran (Robot) Movie 😅

    • @jstrosch
      @jstrosch  Рік тому

      Oh cool - I haven't heard of that movie before!

  • @kunalforvideos
    @kunalforvideos 7 місяців тому

    The extraction and the unzip functions, where is the difference? Is the extraction based on extracting application data bytes after separating delimiters, null/padding values etc from raw data? I mean when I run an Hex through extraction which is supposedly a PKZIP, it gives out doc files, so are there overlapping functionalities?

  • @mtan0001
    @mtan0001 2 роки тому +2

    Hi Josh,
    thanks for the video.
    I'm new to Wireshark. I wonder how to extract a PDF file from a .PCAP file?
    Cheers!
    Michael

    • @jstrosch
      @jstrosch  2 роки тому +2

      Michael - if the PDF file is downloaded over a non-TLS connection, you'll be able to extract it using File->Export Objects-> - so HTTP would be a common protocol to look into. If it's downloaded over TLS, you won't be able to decrypt the TLS session without the appropriate keys. Let me know if this helps!

    • @mtan0001
      @mtan0001 2 роки тому +1

      @@jstrosch Thank you Josh for your reply. I couldn’t use HTTP as it’s FTP protocol.
      When I “Follow TCP Stream”, I see a string of data and there was a .docx document.
      How can I “extract” or “recover” the document to something readable ie to a normal textual image document that I can read?
      I’m not sure if I should “save as” ASCII data or “raw” and the appropriate file format.
      I tried saving it to Word but I wonder how can I decode the TCP Stream to something readable?

    • @jstrosch
      @jstrosch  2 роки тому +1

      Hi! This is a pretty good tutorial from Unit42 that covers extracting files from FTP datan - unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/. This should get you there, if not close. If not let me know, happy to try to help more!

    • @mtan0001
      @mtan0001 2 роки тому +1

      @@jstrosch Thanks Josh. I’ll check out the video 🙏.