Wireshark is one of the most popular packet capture analysis tool available to incident response analysts. In addition to the ability to capture packets, there are a great many features that are available. As entire volumes and training courses are built around this platform, it is impossible to identify every feature. Therefore, this chapter will focus on some of the key features of Wireshark that are most applicable to an incident investigation.
Because Wireshark ...