SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsExtracting files from full packet captures can save security analysts a great deal of time.Time-consuming procedures, such as performing a complete forensic analysis on suspectmachines, can often be avoided if analysts are able to extract files from the networktraffic. There are several tools to perform this function, but they all have shortcomings.In order to make an informed assessment of packet captures, analysts must familiarizethemselves with these limitations. This paper compares the capabilities of currentlyavailable tools which automate this task, explores the process of manually extractingartifacts from packet captures, and offers a script to extend the functionality of TShark toinclude file extraction. This will familiarize new security analysts with current tools aswell as establish a baseline knowledge of how these tools function.