"Hey, we think Fred in accounting smuggled some important company files to a competitor over the internet. Can you find out?" There are several ways one could try and do that; one of the most useful (and fun!) methods is to use Network Forensics. This talk will focus on: a brief description of what network forensics is, some basic network forensics skills, and some more advanced topics including carving files from network streams, capturing credentials, decrypting SSL traffic and more! With the knowledge from this talk you can track cyber criminals on your LAN, keep tabs on where files are being transferred, and ensure company policies are being enforced. Did Fred sell company data to a competitor? I,ve got a PCAP, let,s find out!
Lucas (Luke) Gorczyca is an Associate Technical Analyst at an energy company in Mid-Michigan, where he works on applications and systems that support power generation and distribution. He is also an infosec enthusiast who dabbles in all areas of security but whose primary interests are malware analysis, and digital forensics.
If you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.
Copyright 2020, IronGeek