diff --git a/forensics/pcaps-analysis/README.md b/forensics/pcaps-analysis/README.md index 66532766..6af10f39 100644 --- a/forensics/pcaps-analysis/README.md +++ b/forensics/pcaps-analysis/README.md @@ -55,7 +55,7 @@ Xplico can **analyze** a **pcap** and extract information from it. For example, ### Install -```text +```bash sudo bash -c 'echo "deb http://repo.xplico.org/ $(lsb_release -s -c) main" /etc/apt/sources.list' sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 791C25CE sudo apt-get update @@ -77,6 +77,15 @@ Then create a **new case**, create a **new session** inside the case and **uploa Like Xplico it is a tool to analyze and extract objects from pcaps. It has a free edition that you can download [here](https://www.netresec.com/?page=NetworkMiner). +## [BruteShark](https://github.com/odedshimon/BruteShark) + +* Extracting and encoding usernames and passwords \(HTTP, FTP, Telnet, IMAP, SMTP...\) +* Extract authentication hashes and crack them using Hashcat \(Kerberos, NTLM, CRAM-MD5, HTTP-Digest...\) +* Build visual network diagram \(Network nodes & users\) +* Extract DNS queries +* Reconstruct all TCP & UDP Sessions +* File Carving + ## Other pcap analysis tricks * [DNSCat pcap analysis](dnscat-exfiltration.md)