Incident response

Network traffic analysis for IR: Data collection and monitoring

Data collection and analysis for use by network engineers, security professionals and incident response has only exploded over the years with the growth of c

Network traffic analysis for Incident Response (IR): TLS decryption

Introduction to TLS When the internet was being created, security wasn’t much of an issue. The internet (and the Arpanet before it) was primarily being used

Network traffic analysis for IR: Address resolution protocol (ARP) with Wireshark

The Address Resolution Protocol (ARP) was first defined in RFC 826. As the name suggests, it is designed to resolve IP addresses into a form usable by other

Network traffic analysis for IR: Alternatives to Wireshark

It is almost impossible to leave a conversation with a cybersecurity professional, take an introductory networking class, or break into ethical hacking witho

Network traffic analysis for IR: Statistical analysis

Introduction to statistical analysis Statistical analysis is one of the three main categories of analysis that can be performed on network traffic data. It

Network traffic analysis for incident response (IR): What incident responders should know about networking

Introduction In this article, we’ll discuss the various things that incident responders must know about the operation of a network and how this can help imp

Network traffic analysis for IR: Event-based analysis

Introduction to event-based analysis Event-based analysis, as its name suggests, focuses on analysis of specific events that occur on the monitored network.

Network traffic analysis for IR: Connection analysis

Introduction to connection analysis Connection analysis is the highest-level type of network analysis that is used in incident response. Rather than develop

Network traffic analysis for IR: Data analysis for incident response

Introduction While no incident is the same, security professionals have come to rely on pre-established procedures and best practices to help contain a secu

Network traffic analysis for IR: Network mapping for incident response

Introduction to network mapping The concept of network mapping is not a new one. Creating network maps in the design phase of a network and updating them th