Question: Use Wireshark, tcpdump, ngrep, and / or other network tools to answer the following quesEons about the packet capture file charade _ capture.pcap, found in
Use Wireshark, tcpdump, ngrep, andor other network tools to answer the following quesEons about
the packet capture file charadecapture.pcap, found in the following folder on you Cyber Range
Forensics Environment.
$ cd homestudentDesktopcasesNetworkCaptures
What is the start date and Eme for the capture?
How many total packets are captured?
What is the top most used applicaEonlayer protocol in the capture?
Find the first DHCP request in the capture.
a What is the hostname of the requesEng system?
CS Digital Forensics
Term: Winter
b What IP address was assigned to the requester?
c Can you idenEfy the manufacturer of the client system? How?
d What is the IP address of the DNS server idenEfied in the DHCP response?
e What is the duraEon of the lease?
Websites:
a List a few websites visited by the computer at the IP listed above.
b Is there any indicaEon from web traffic that the user was looking for a new job? If so list those
websites.
There are three emails from the address inidrthrt@aol.com.
a What is the name of the apparent owner of that email address?
b Who are the recipients of those three emails?
c One of the emails contains an image file. What is the name of the file?
d Can you carve the image from the network traffic? What is the address of the locaEon
depicted in the image?
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
