Blue Team Investigation with Wireshark (Forensics)

Blue Team Investigation with Wireshark (Forensics)

You are a blue team analyst investigating a network attack on SafeDrive Insurance captured in a PCAP file. Using Wireshark, you will analyze attacker behavior including port scanning, brute force authentication, SQL injection, IDOR enumeration, and XSS attacks. This lab teaches systematic PCAP analysis techniques to reconstruct attack timelines and identify exploitation methods.

By CyberTask · Easy level · 4.0 (9 ratings)

45 Tasks
9 Sections
650 Points
1 hr Duration

What You'll Learn

  • Analyze packet captures using display filters
  • Identify attacker IP and reconnaissance activity
  • Detect brute force and credential attacks
  • Investigate SQL injection and IDOR vulnerabilities
  • Reconstruct attack timeline and methodology
  • Quantify data breach scope and impact

Prerequisites

  • Basic networking concepts and protocols
  • Understanding of HTTP request methods
  • Familiarity with common web vulnerabilities
  • Basic SQL injection concepts
  • TCP/IP fundamentals
Tools & Technologies
Wireshark

Ready to Begin?

Sign in or create an account to start this lab and earn points.

Login to Start
Loading...