offline:wrccdc_pcaps_results
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
offline:wrccdc_pcaps_results [2018/05/12 23:50] – [Drilldown techniques] veera | offline:wrccdc_pcaps_results [2018/05/12 23:58] – [File Extraction] veera | ||
---|---|---|---|
Line 73: | Line 73: | ||
Once you have a fairly solid baseline you can go back and decide which paths you want to follow to drilldown further. You might be interested in first checking out the critical IDS alerts, or tracking down flows. This section introduces you to the tools you will use for the drilldowns. | Once you have a fairly solid baseline you can go back and decide which paths you want to follow to drilldown further. You might be interested in first checking out the critical IDS alerts, or tracking down flows. This section introduces you to the tools you will use for the drilldowns. | ||
==== Explore flows ==== | ==== Explore flows ==== | ||
+ | |||
+ | Most of the times you want to first drop down to the flow level. This can be accessed by " | ||
[{{ : | [{{ : | ||
==== Trisul EDGE: Graph analytics discover relationships ==== | ==== Trisul EDGE: Graph analytics discover relationships ==== | ||
+ | |||
+ | We recently added Graph Analytics to Trisul. This solves a common question that analysts ask from any " | ||
[{{ : | [{{ : | ||
==== File Extraction ==== | ==== File Extraction ==== | ||
- | |||
- | [{{ : | + | Trisul has the ability using the "Save Binaries" |
+ | [{{ : | ||
- | ==== Drilldown | + | The extracted files are stored by the app in ''/ |
- | |||
- | [{{ : | ||
- | |||
- | |||
- | ==== File extraction ==== | ||
< | < | ||
Line 105: | Line 104: | ||
</ | </ | ||
+ | |||
+ | |||
+ | |||
+ | ==== Drilldown to Packets ==== | ||
+ | |||
+ | |||
+ | [{{ : | ||
offline/wrccdc_pcaps_results.txt · Last modified: 2018/05/13 00:08 by veera