Back to all posts
Lab 37Monday, October 5, 20262 min read

Triage a Training Packet Capture with Wireshark

cybersecuritywiresharkpacketanalysisnetworksecurityincidentresponselabslearningprocess
View original post

Lab Objective

Practise the first stage of network triage: turn a packet capture into a short, evidence-based observation that another analyst can reproduce.

This is a training exercise using a supplied capture. Do not capture or inspect traffic you are not authorised to handle.

Setup

  • Wireshark installed on a lab machine
  • The course-provided sample.pcap file
  • A notes file for recording frame number, timestamp, endpoints, protocol, and uncertainty

On Windows, packet capture may require an approved driver such as Npcap. The course screenshot showed Wireshark warning that no packet-capture driver was installed on that environment; opening an existing capture does not require starting a new live capture.

Procedure

  1. Open sample.pcap in Wireshark.
  2. Confirm the packet count and note the columns visible in the packet list.
  3. Identify a row labelled SSH or another protocol relevant to the exercise.
  4. Select the row and expand Ethernet, Internet Protocol, Transmission Control Protocol, and the application protocol sections.
  5. Record the frame number, timestamp, source and destination addresses, transport ports, protocol, and packet length.
  6. Compare the selected frame with nearby frames to establish direction and sequence.
  7. If using a display filter, write down the exact filter and verify that it changes the displayed set as expected.
  8. Write two separate conclusions: what the packet proves, and what additional evidence would be needed to decide whether the traffic is suspicious.

Expected Evidence

The supplied exercise contains a 200-packet view with visible SSH/TCP traffic. A valid result should include a selected frame and a short record such as:

Observed: the selected frame decodes as Ethernet -> IPv4 -> TCP -> SSH.
Observed: the transport conversation uses TCP port 22 on one side.
Not proved: whether the session was authorised or malicious.

Do not publish real endpoint identities or credentials. Use synthetic labels in your notes if the capture contains identifying data.

Security Takeaway

Packet analysis is strongest when it separates observation from interpretation. A protocol label can guide the investigation, but it is not a verdict about intent or compromise.