User Tools

Site Tools


offline:defcon26ctf

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Next revisionBoth sides next revision
offline:defcon26ctf [2018/11/12 22:58] – [Top flows] veeraoffline:defcon26ctf [2018/11/12 22:59] – [Conversations of a particular hosts] veera
Line 78: Line 78:
 Click on //Retro > Retro Counters// to view a Timeline showing traffic bandwidth. Here we see between 10 and 100Mbps spanning a 3-day period of the competition. From here you can select any timewindow and drill down into Counters.  Click on //Retro > Retro Counters// to view a Timeline showing traffic bandwidth. Here we see between 10 and 100Mbps spanning a 3-day period of the competition. From here you can select any timewindow and drill down into Counters. 
  
-{{:offline:dc26-1.png?600|}}+{{:offline:dc26-1.png?800|}}
  
  
Line 87: Line 87:
  
  
-{{:offline:dc26-2.png?600|}}+{{:offline:dc26-2.png?800|}}
  
  
Line 118: Line 118:
 Select //Alerts > Show All > IDS// to show the IDS alert categories seen.  You can then click on an alert to drill down further or pull up PCAPs.   Select //Alerts > Show All > IDS// to show the IDS alert categories seen.  You can then click on an alert to drill down further or pull up PCAPs.  
  
-{{:offline:dc26-6.png?600|}}+{{:offline:dc26-6.png?800|}}
  
  
Line 125: Line 125:
 Trisul lets you seamlessly pivot from any analysis point to PCAPs. You can pull down entire PCAP or use the super nifty "PCAP Headers" to only see the top of the PCAP. In the PCAP headers, we show the 'strings' seen in the PCAP header, the actual Hexdump, and a TSHARK like packet summary.   Trisul lets you seamlessly pivot from any analysis point to PCAPs. You can pull down entire PCAP or use the super nifty "PCAP Headers" to only see the top of the PCAP. In the PCAP headers, we show the 'strings' seen in the PCAP header, the actual Hexdump, and a TSHARK like packet summary.  
  
-{{:offline:dc26-7.png?600|}}+{{:offline:dc26-7.png?800|}}
  
  
Line 133: Line 133:
  
  
-{{:offline:dc26-8.png?600|}}+{{:offline:dc26-8.png?800|}}
  
  
offline/defcon26ctf.txt · Last modified: 2018/11/12 23:00 by veera