Packet forensics walkthrough
Rebuilding an incident timeline using only a capture file.
Network Analysis
Planned
Reading traffic at the packet level.
Logs show what an application decided to write down. A capture shows what actually crossed the wire. When the two disagree, the capture is right, and being able to read one is what separates explaining an incident from guessing at it.
Listed before it exists so you can tell the difference.
Rebuilding an incident timeline using only a capture file.
What's still visible in a TLS handshake and an IPsec/IKE negotiation.