Threat hunting

Network forensic tools

Profiles to Wireshark
Unzip and import into the Wireshark profiles folder (Restart Wireshark)

I offer a 2 day traning course in Wireshark and huntning with Wireshark and other tools. A lot of personal in CERT, SAC and SOC teams often find it usefull for analyst to known how to use Wireshark and other tools for pcap analysis. I encounter verry often that a lot of analyst don't know how to detect evil traffic in capture files. They quite often have a hard time just to know the basic in traffic analysis.

This basis course will help analyst to know what to look for, even if they dont know what they are looking for.

JA3 and JA3S
When hunting for malware there are using TLS, then it is nice to know the JA3 ore the JA3S of the TLS connection. This is possible with a plugin from Github. I have made this aviable as an easy packet, to implement in your own Wireshark here as a plugin. Be aware that this ONLY covers TCP port 443

Extract the
zip file and copy to your Wireshark profiles folder "\AppData\Roaming\Wireshark"
I have also made a
Wireshark JA3 profile as well. This just needs to be implemented as a regular profile.

IcedID TLS Inspection
Hunting for the malware framework IcedID it is nessary to look for what names a certificate was issued with. Quite often it it a self signed certificate with bogus names. like this on with the name "localhost".


GQUIC Profile (Updated 07-01-2021)
Hunting for GQUIC connections setups can be quite a task, if you cant find the CHLO packet. This is made easy to find with this profile.. Even if this is a fully encrypted protocoal we can til see usefull information about the domain, user agents, time, IP and port.

ICMP Profile
Hunting for ICMP tunneling is quite easy with this Wireshark profile. Exampel of a pTunnel running below.

iSCSI profile
Hunting for iSCSI auth traffic and authentications. Easy to spot with this profile 

DHCP Profile (Updated 03-01-2021)
Often you will hunt for a rough DHCP server placed on your network. This profile will make this very easy.
Optimized for Wiresharek 3.x versions.

DNS Profile
This will make DNS identification easy and bring DNS traffic to life in Wireshark

SMB Profile (Many updates for this profile as of 02-01-2020)
This will bring the analysis of SMB, SMB2 and SMB3 network traffic to life in Wireshark. What you typically is looking for, is right there...
More information about MS implementation

DDOS profile
Based on my work for an ISP and the manage of Advanced DDOS mitigation. This is based on known DDOS attacks. You can analyze the type of attack quite fast. Tested Wireshark V2.6.3

Magic numbers profile
Based on file types and there magic numbers it is easy to look for different file types in network traffic like exe files and so on, hidden in network traffic. Tested Wireshark V2.6.3

Geolite2 databases for Wireshark
Wireshark can do name resolution on captured traffic.
To get the free updated
Maxmind databases you need to sign up for a profile first. (please do so)
You can get an older Maxmind databease
from here.