Wireshark Analysis
zebbern/claude-code-guide
This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…
Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection…
$ npx skills add trilwu/secskills --skill analyzing-network-traffic -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills analyzing-network-traffic --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/analyzing-network-traffic .claude/skills/analyzing-network-traffic && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "analyzing-network-traffic" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-network-traffic into .claude/skills/analyzing-network-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-network-traffic", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-network-trafficType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill analyzing-network-traffic -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills analyzing-network-traffic --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-defense/skills/analyzing-network-traffic .agents/skills/analyzing-network-traffic && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "analyzing-network-traffic" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-network-traffic into .agents/skills/analyzing-network-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-network-traffic", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-network-traffic -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills analyzing-network-traffic --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-defense/skills/analyzing-network-traffic .cursor/skills/analyzing-network-traffic && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "analyzing-network-traffic" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-network-traffic into .cursor/skills/analyzing-network-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-network-traffic", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-defense/skills/analyzing-network-traffic--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill analyzing-network-traffic -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills analyzing-network-traffic --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-defense/skills/analyzing-network-traffic .gemini/skills/analyzing-network-traffic && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "analyzing-network-traffic" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-network-traffic into .gemini/skills/analyzing-network-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-network-traffic", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills analyzing-network-trafficInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill analyzing-network-traffic -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-defense/skills/analyzing-network-traffic .github/skills/analyzing-network-traffic && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-network-traffic" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-network-traffic into .github/skills/analyzing-network-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-network-traffic", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill analyzing-network-traffic -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills analyzing-network-traffic --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-defense/skills/analyzing-network-traffic .opencode/skills/analyzing-network-traffic && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "analyzing-network-traffic" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/analyzing-network-traffic into .opencode/skills/analyzing-network-traffic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "analyzing-network-traffic", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
analyzing-network-trafficAnalyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection…
Analyzing Network Traffic is an agent skill from trilwu/secskills. Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection, TLS/JA3 fingerprinting, HTTP and file carving, exfiltration hunting, and IOC handoff. Use when a .pcap or .pcapng capture lands on your desk, when a suspected C2 beacon needs confirming, when there is data exfiltration to investigate, when malware network behaviour must be characterized from what it emitted, when a…
Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Network security. It works with Wireshark. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
jqpython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
attack.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analyzing Network Traffic loads about 5.3k tokens when it runs. Until then it costs about 160 tokens; SKILL.md has 2,116 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 2,116 words, ~5,298 tokens.
.claude/skills/analyzing-network-traffic/SKILL.md (or your agent's skills folder).Packet capture is ground truth the endpoint can lie about but the wire cannot: every connection, DNS lookup, and byte transferred is recorded, whether or not the host's logs survived. The analysis is turning a flat capture into a story — who talked to whom, over what protocol, whether the pattern was human or automated, and what left the network. You are reconstructing intent from frames, not reading a verdict off a tool.
.pcap / .pcapng capture needs forensic review for intrusion evidencenotice.log or Suricata eve.json alert needs to be run down to a verdicthunting-threats; this skill dissects one
capture, a hunt spans data sourcesresponding-to-incidents; traffic
analysis is one evidence stream feeding that processanalyzing-malware;
come here to analyze the pcap it emitted, not to run the binaryinvestigating-aws-incidentstesting-web-applicationsGet the capture right or every later step inherits the gap. A truncated snaplen or a dropped-packet capture cannot be fixed after the fact.
# Full-frame capture, no name resolution, write to disk (never parse live)
tcpdump -i eth0 -nn -s 0 -w case.pcap
# -s 0 takes full frames; a default snaplen truncates payloads and breaks carving
# Ring buffer for long-running capture: 20 files of 200 MB, oldest recycled
tcpdump -i eth0 -nn -s 0 -w case-%Y%m%d-%H%M%S.pcap -G 3600 -C 200 -W 20
# Capture without dropping under load: raise the kernel buffer, filter tightly
tcpdump -i eth0 -nn -s 0 -B 4096 'not port 22' -w case.pcap
# Confirm drops after: the summary line reports "packets dropped by kernel"Check whether the capture is intact and what you are holding:
capinfos case.pcap # packet count, duration, drop stats, snaplen, file type
tshark -r case.pcap -q -z io,phs # protocol hierarchy — is the snaplen truncating?.pcap is a flat single-link format. editcap -F libpcap in.pcapng out.pcap downgrades for a tool that only reads pcap.editcap -c 1000000 big.pcap chunk.pcap (per packet count) or
editcap -i 600 big.pcap chunk.pcap (per 600 seconds).mergecap -w all.pcap a.pcap b.pcap (sorts by timestamp).editcap -A "2026-07-26 00:00:00" -B "2026-07-26 06:00:00" case.pcap window.pcap.tcprewrite/bittwiste to rewrite
addresses, or editcap -s <snaplen> to truncate each packet to the first
snaplen bytes (keeping headers, dropping trailing payload); TraceWrangler
for deeper header/payload sanitization. Record what you changed so the
recipient does not chase your rewrite as an artifact.Hash the original and work on copies. sha256sum case.pcap goes in the case
notes; the evidence file is read-only from here on.
Start wide, narrow to the flows that matter. In Wireshark, work top-down:
Everything Wireshark does interactively, tshark does scriptably — which is how
you extract fields across a whole capture instead of clicking:
# Top talkers by bytes
tshark -r case.pcap -q -z conv,tcp
# Extract just the fields you want, tab-separated, for further processing
tshark -r case.pcap -T fields -E separator=/t \
-e frame.time_epoch -e ip.src -e ip.dst -e tcp.dstport -e frame.len \
-Y 'tcp.flags.syn==1 && tcp.flags.ack==0' # every connection attempt
# Every HTTP request: host, method, URI, user-agent
tshark -r case.pcap -T fields -e http.host -e http.request.method \
-e http.request.uri -e http.user_agent -Y http.requestDisplay filters are the scalpel. The highest-value ones:
| Filter | Surfaces |
|---|---|
http.request | Every outbound HTTP request — URIs, hosts, user agents |
dns | All DNS; add dns.flags.rcode == 3 for NXDOMAIN (DGA tell) |
tls.handshake.type == 1 | ClientHello only — SNI, JA3 input, offered ciphers |
tls.handshake.type == 2 | ServerHello — chosen cipher, JA3S input |
ip.addr == 10.0.0.5 | All traffic to or from a host (src/dst to pin direction) |
tcp.flags.syn==1 && tcp.flags.ack==0 | Connection attempts — scan and beacon cadence |
tcp.flags.reset==1 | RSTs — refused/closed, port-scan responses |
frame contains "password" | Byte-string search across payloads (cleartext creds, markers) |
tcp.stream eq 7 | Isolate one reassembled conversation by stream index |
tcp.analysis.retransmission | Loss/instability that skews timing analysis |
http.response.code == 200 && http.content_type contains "octet-stream" | File transfers over HTTP |
Chain them: ip.dst == 185.100.87.0/24 && dns scopes DNS to one suspect
netblock. dns.qry.name matches "[a-f0-9]{20,}" flags long hex labels.
Zeek turns a pcap into structured, queryable logs — the single highest-leverage move on any capture bigger than a few thousand packets.
zeek -r case.pcap
# Or add the community-id field for cross-tool pivoting:
zeek -r case.pcap policy/protocols/conn/community-id-logging
ls # conn.log dns.log http.log ssl.log x509.log files.log notice.log weird.log ...The log set and what each answers:
| Log | Answers |
|---|---|
conn.log | Every flow: duration, orig/resp bytes, state, service — the backbone of beacon and exfil analysis |
dns.log | Every query/response — tunneling, DGA, TXT/NULL abuse |
http.log | Host, URI, method, user-agent, status, referrer |
ssl.log | TLS version, SNI, JA3/JA3S, cert chain, validation status |
x509.log | Certificate subject, issuer, validity, self-signed flag |
files.log | Every file seen on the wire — MIME, size, MD5/SHA1, source flow |
notice.log | Zeek's own detections (SSL::Invalid_Server_Cert, scans, etc.) |
weird.log | Protocol violations — protocol-on-wrong-port, malformed frames |
Mine them with zeek-cut (field extraction by name, order-independent):
# Longest connections first — beacons and tunnels live at the top
cat conn.log | zeek-cut id.orig_h id.resp_h duration orig_bytes resp_bytes \
| sort -t$'\t' -k3 -rn | head
# Every distinct destination one host reached, with hit counts
cat conn.log | zeek-cut id.orig_h id.resp_h | grep '^10\.0\.0\.5' \
| sort | uniq -c | sort -rn
# DNS query names + types, to eyeball tunneling and DGA
cat dns.log | zeek-cut query qtype_name answers | sort | uniq -c | sort -rn | head -50
# Pivot a suspicious flow across all logs by its community-id
cat conn.log | zeek-cut community_id id.orig_h id.resp_h serviceThe community-id field is the same string across Zeek, Suricata, and many
EDRs for the same flow — use it to line up an alert with the packets.
Run signatures offline against the capture to see what a rule set flags:
# Run ET Open / community rules over the pcap, write structured events
suricata -r case.pcap -S /etc/suricata/rules/suricata.rules -l ./out/
# eve.json holds alerts, plus dns/http/tls/flow records if enabledExtract and rank the alerts:
jq -c 'select(.event_type=="alert") | {sig:.alert.signature, src:.src_ip, dst:.dest_ip}' \
out/eve.json | sort | uniq -c | sort -rnRead alerts as leads, not verdicts. A signature hit tells you where to look; it does not close the case, and its absence does not clear the capture.
Automated callbacks betray themselves in the timing and the shape, not the
content. Look in conn.log for a source/destination pair that recurs at a
regular interval, with small and roughly constant request sizes, over a long
span. Human traffic is bursty and varied; a beacon is a metronome.
# Inter-arrival deltas for one src/dst pair — near-constant gaps = beacon
tshark -r case.pcap -T fields -e frame.time_epoch \
-Y 'ip.src==10.0.0.5 && ip.dst==185.100.87.202' \
| awk 'NR>1{print $1-prev} {prev=$1}' | sort -n | uniq -cAutomate the scoring with RITA or a beacon-analysis tool over Zeek logs —
they compute interval and size consistency across every pair so you are not
eyeballing one at a time:
rita import --database case --logs ./ && rita view case beacon:'>=90'DNS is the covert channel of choice because it is rarely blocked and often
unlogged. In dns.log, two distinct patterns:
Tunneling — DNS used as a data pipe:
MFRGG43FMQ.tunnel.evil.com, base32/hex-looking subdomainsTXT and NULL record types carrying encoded payload upstream/downstream# Subdomain cardinality per parent domain — a tunnel spikes on one domain
cat dns.log | zeek-cut query | rev | cut -d. -f1-2 | rev \
| sort | uniq -c | sort -rn | head
# TXT queries only — legitimate use is sparse; volume is a flag
cat dns.log | zeek-cut query qtype_name | awk -F'\t' '$2=="TXT"' | wc -lDGA — algorithmically generated rendezvous domains:
NXDOMAIN rate (rcode 3) as the malware cycles through dead namescat dns.log | zeek-cut rcode_name query | awk -F'\t' '$1=="NXDOMAIN"' \
| wc -l # a burst of NXDOMAIN from one host is a DGA tellScore label entropy or use a DGA classifier to separate cdn-3f2a.example
(benign hash) from qwzjxkbvmn.info (generated). Volume plus entropy plus
NXDOMAIN together make the case; any one alone has benign explanations.
You cannot read the plaintext without keys, but the handshake still fingerprints the client, the server, and the intent. Encryption hides content, not metadata.
ssl.log carries ja3/ja3s; correlate against public and internal
known-bad lists.ssl.log / x509.log look for: self-signed certs, SNI that does not
match the certificate CN/SAN, absurd validity windows (1000-year or
same-day certs), empty/garbage subject fields, and SNI pointing at
suspicious or newly-registered domains.# Self-signed or validation-failed TLS, with the SNI and JA3
cat ssl.log | zeek-cut server_name validation_status ja3 ja3s \
| grep -iv '\bok$' | sort | uniq -c | sort -rn
# SNI vs certificate subject mismatch — join ssl.log and x509.log on cert id
cat x509.log | zeek-cut certificate.subject certificate.issuer \
certificate.not_valid_before certificate.not_valid_afterWhen you legitimately hold the session keys (a lab detonation with
SSLKEYLOGFILE set, or an exported master secret), decrypt in Wireshark:
Preferences > Protocols > TLS > (Pre)-Master-Secret log filename, or
tshark -r case.pcap -o tls.keylog_file:keys.log -Y http2. Never assume you can
decrypt production TLS you have no keys for — you are fingerprinting, not
reading.
Cleartext HTTP (and decrypted TLS) exposes the whole exchange:
python-requests, an empty UA, a typo'd browser string) on outbound traffic
is a common malware tell. Stack UAs and investigate the rare ones.http.log — base64-looking paths, long random query
strings, .php endpoints on a raw IP, or POSTs of opaque blobs.Carve transferred files and hash them for pivoting:
# Zeek extracts files automatically when configured; otherwise from files.log:
cat files.log | zeek-cut fuid mime_type filename md5 sha1 tx_hosts rx_hosts
# Carve without Zeek:
foremost -i case.pcap -o carved/ # signature-based file recovery
tcpflow -r case.pcap -o flows/ # reassemble every TCP stream to a file
# NetworkMiner (GUI/CLI) reassembles files, images, and credentials from a pcapHash every carved artifact and pivot suspicious ones to analyzing-malware:
sha256sum carved/* — a file that appeared on the wire and matches nothing
benign is the next sample to detonate.
Data leaving is the outcome that matters most. In conn.log, sort by
orig_bytes descending — large outbound flows are the headline, and the
direction (orig = the internal host sending) is the whole point.
# Biggest outbound transfers from internal hosts
cat conn.log | zeek-cut id.orig_h id.resp_h resp_p orig_bytes duration \
| awk -F'\t' '$4>10000000' | sort -t$'\t' -k4 -rn*.s3.amazonaws.com,
*.blob.core.windows.net), paste sites (pastebin, ghostbin), and
file-share domains as the destination of a large upload from a server that
has no business reason to use them.Attackers hide traffic on the wrong port and in the wrong protocol:
conn.log's service field is Zeek's detected protocol,
independent of port number.conn.log (service disagrees with id.resp_p) and in weird.log.# Detected service does not match the port — tunneling / evasion
cat conn.log | zeek-cut id.resp_p service | awk -F'\t' \
'($1=="443" && $2!="ssl") || ($1=="53" && $2!="dns")' | sort | uniq -cframe contains "PASS " in Wireshark, or NetworkMiner's credentials
tab, pulls them straight out.The capture's value is what you extract for reuse. Tier indicators the way you would from any source — behaviour outlives infrastructure — and route each output:
.yar in writing-yara-rules
against structure, not the URI it happened to use.producing-threat-intelligence.writing-sigma-rules
for log-based rules and engineering-detections for the broader rule
pipeline (a Suricata signature for the JA3, a Zeek notice for the beacon
cadence, a Sigma rule for the DNS pattern).reporting-security-findings.Record for every indicator: the flow it came from, the timestamp, and your confidence. An IP with no context is noise to whoever receives it.
<!-- attack:start -->
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
Command and Control (TA0011)
analyzing-malware, engineering-detectionsengineering-detections, hunting-threatstransferring-files, analyzing-malwareanalyzing-malware, hunting-threatsanalyzing-malware, engineering-detectionsExfiltration (TA0010)
transferring-files, hunting-threatsDetection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.
<!-- attack:end -->
hunting-threats — proactive, hypothesis-driven search across many telemetry
sources, of which network data is oneresponding-to-incidents — the incident process this evidence stream feedsanalyzing-malware — detonate the sample to produce traffic, and receive
carved files from this skill for analysisinvestigating-aws-incidents — when the evidence is cloud control-plane logs
rather than packetswriting-yara-rules — file signatures from carved artifactsproducing-threat-intelligence — packaging extracted IOCs into a productreporting-security-findings — the stakeholder write-uptshark and capinfos — interactive and scripted dissectionzeek-cut and community-id — structured logs from any capturetcpdump — capture; editcap / mergecap — split, merge, trim, and convert© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-defense/skills/analyzing-network-traffic of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Analyzing Network Traffic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Analyzing Network Traffic this skilltrilwu/secskills | 157 | — | ~5.3k | Automated safety check: Pass | MIT | |
| Wireshark Analysiszebbern/claude-code-guide | 4.7k | 8 repos | ~3k | Automated safety check: Pass | MIT | |
| IotnetBrownFineSecurity/iothackbot | 859 | 1 repos | ~1k | Automated safety check: Notes | MIT | |
| Netzhinkgit/embeddedskills | 734 | — | ~1.1k | Automated safety check: Pass | MIT | |
| Performing Network Forensics With Wiresharkmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | |
| Performing Network Traffic Analysis With Zeekmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 |
zebbern/claude-code-guide
This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network…
BrownFineSecurity/iothackbot
IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications.
zhinkgit/embeddedskills
嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills.
mukul975/Anthropic-Cybersecurity-Skills
Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control…
mukul975/Anthropic-Cybersecurity-Skills
Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and…
mukul975/Anthropic-Cybersecurity-Skills
Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations…
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Categories
Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection…. Analyzing Network Traffic is an agent skill from trilwu/secskills. Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection, TLS/JA3 fingerprinting, HTTP and file carving, exfiltration hunting, and IOC handoff.
Analyzing Network Traffic fits situations like: .pcapng capture lands on your desk; A suspected C2 beacon needs confirming; there is data exfiltration to investigate; malware network behaviour must be characterized from what it emitted.
Run `npx skills add trilwu/secskills --skill analyzing-network-traffic -a claude-code`. Or copy the skill folder (secskills-defense/skills/analyzing-network-traffic in trilwu/secskills) into .claude/skills/analyzing-network-traffic in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill analyzing-network-traffic -a codex`. Or copy the skill folder (secskills-defense/skills/analyzing-network-traffic in trilwu/secskills) into .agents/skills/analyzing-network-traffic in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill analyzing-network-traffic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-network-traffic, .gemini/skills/analyzing-network-traffic, .github/skills/analyzing-network-traffic and .opencode/skills/analyzing-network-traffic in your project.
Going by SKILL.md and its folder, Analyzing Network Traffic needs the command-line tools its instructions call (jq and python3).
SKILL.md names 1 domain. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Analyzing Network Traffic is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Analyzing Network Traffic: Wireshark Analysis (zebbern/claude-code-guide, 4.7k stars), Iotnet (BrownFineSecurity/iothackbot, 859 stars), Net (zhinkgit/embeddedskills, 734 stars) and Performing Network Forensics With Wireshark (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.