Packet capture analysis

  • Filter HTTP traffic for POST requests

  • Check for requests with absurdly large lengths

ftp.request.method && frame.len > 750
  • Select the suspicious capture and follow HTTP stream to know more

Last updated