What to look for in network forensics?

I have a dump (a .pcapng file) that I'm looking inside with Wireshark. Although, I'm not really sure what to look for. It's an endless list of connections between a router and a computer but I'm really just following random HTTP streams at the moment. What do you generally look for in a network dump? Do you have a certain workflow you like to follow?

Edited for more context.

submitted by /u/shadowbanbad
[link] [comments]

from hacking: security in practice https://ift.tt/37eWKtb

Comments