BigHugger
sk Skill · mukul975

implementing-network-traffic-analysis-with-arkime

Queries Arkime (formerly Moloch) full packet capture via its API to search sessions, download PCAPs, detect C2 beaconing through connection interval/jitter stats, spot DNS tunneling via query-length analysis, and flag known-bad TLS certificate issuers, using the bundled scripts/agent.py. Use when investigating suspicious network flows or doing full-packet-capture forensics against an Arkime deployment.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashPythonnetwork-forensicspcap-analysisntafull-packet-capturearkimenetwork-security
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python