Talk With an Expert

Extracting Files from Network Packet Captures

Extracting Files from Network Packet Captures (PDF, 3.07MB)Published: 28 Dec, 2015
Created by:
Rebecca Deck

Extracting files from full packet captures can save security analysts a great deal of time.Time-consuming procedures, such as performing a complete forensic analysis on suspectmachines, can often be avoided if analysts are able to extract files from the networktraffic. There are several tools to perform this function, but they all have shortcomings.In order to make an informed assessment of packet captures, analysts must familiarizethemselves with these limitations. This paper compares the capabilities of currentlyavailable tools which automate this task, explores the process of manually extractingartifacts from packet captures, and offers a script to extend the functionality of TShark toinclude file extraction. This will familiarize new security analysts with current tools aswell as establish a baseline knowledge of how these tools function.

Extracting Files from Network Packet Captures