SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsWhen was the last time you faced a packet trace file, and hoped to remember all the different filters used to detect anomalous network activities? Were you typing in the filters as you progress, and hoping for an alternate solution? This paper discusses some basic features in Wireshark, and the advanced techniques for creating simple to complex Display filters for Coloring rules, using it to identify network reconnaissance, attacks and recovering evidence from within the packet trace files.