CHAPTER 06 35 MIN READ INTERMEDIATE

Network Forensics: Packet Capture, NetFlow & C2 Traffic Reconstruction

Host-level evidence from chapters 2 through 5 tells you what happened on a machine. Network evidence tells you how it got there and where it talked to next. This chapter covers reading that evidence, from flow records down to individual packets.

packet analysisNetFlowC2 detectionprotocol reconstruction

Sources of Network Evidence

Network evidence comes in several forms, each trading detail for cost and retention. Knowing which source answers your question saves hours of pulling the wrong data.

SourceDetail LevelTypical Retention
Full packet capture / pcapEvery byte, includes payloadStorage-heavy, so often short retention
NetFlow / IPFIXMetadata only: who talked to whom, how much, no payloadMuch cheaper to retain, often kept far longer
Proxy and firewall logsConnection-level with some request detailRetained per organizational policy
DNS logsWhat domains were resolved, whenVaries, often retained alongside other logs

Most investigations start with the cheapest, longest-retained source and work toward full packet capture only where it's still available. NetFlow can tell you a host talked to a suspicious IP for weeks; pcap tells you exactly what was sent, but only if someone was capturing at the time.

Note: By the time an investigation starts, the packet capture for an incident from three months ago may simply not exist. NetFlow or firewall logs covering that period usually still do.

Packet Analysis Fundamentals

Raw packet captures are large and mostly irrelevant to any given question. The skill is narrowing down to what matters and rebuilding the conversation from the pieces.

  • Display filters narrow a capture to relevant traffic, by IP, port, protocol, or a specific field value, so you're not scrolling through unrelated packets.
  • Stream following reconstructs a single TCP or UDP conversation end to end, showing both sides in order rather than interleaved individual packets.
  • Object extraction pulls files or transferred objects (a downloaded executable, an exfiltrated document) directly out of a capture for separate analysis.

Wireshark is the well-known GUI tool for this kind of analysis, with a command-line counterpart for scripted or headless work. Zeek takes a different approach: instead of showing raw packets, it watches traffic and generates structured logs (connections, DNS queries, HTTP requests) that are easier to search at scale.

Note: Zeek logs are a good middle ground between NetFlow's bare metadata and a full pcap's raw payload. They're structured enough to query quickly but carry more protocol detail than flow records alone.

Protocol and Session Reconstruction

Reconstructing a session means rebuilding the actual exchange from captured packets. For HTTP, that's pairing a request with its response. For DNS, it's matching a query to its answer.

Session TypeWhat Reconstruction Rebuilds
HTTPThe request (method, URI, headers, body) paired with its response (status, headers, body)
DNSThe query name and type matched to the answer records returned

TLS encryption hides the request and response content, but it doesn't hide everything. The Server Name Indication (SNI) field in the handshake reveals the hostname being requested on most traffic, certificate details are visible, and traffic timing and volume are observable regardless of encryption. Encrypted Client Hello, a newer extension some providers and browsers now support, can hide SNI too, so an investigator can't assume it's always there.

JA3 and JA3S are documented fingerprinting techniques that identify client and server software from characteristics of the TLS handshake itself, such as the offered cipher suites and extensions. This works even when the encrypted payload is completely opaque, though newer clients that randomize their handshake extensions degrade JA3's reliability, which is why the successor fingerprint JA4 is increasingly used alongside it.

Note: A JA3 hash matching known malware families doesn't confirm malicious traffic on its own, but it's a strong pivot point when combined with unusual destination infrastructure or timing.

Identifying C2 Traffic in Captures

Command-and-control traffic often looks different from normal user traffic once you know what to look for, even when the payload itself is encrypted.

IndicatorWhy It Matters
Regular-interval beaconing callbacksAutomated malware checks in on a schedule; human-driven browsing doesn't produce that regularity
Unusual or mismatched user-agent stringsA user-agent claiming one browser while the TLS fingerprint or timing pattern suggests something else is a red flag
Jitter patternsSmall randomized delays added to beacon intervals, designed to evade simple fixed-interval detection
Domain fronting or unusual destination infrastructureTraffic routed through legitimate-looking front domains or newly registered, oddly hosted infrastructure often indicates deliberate evasion
Note: This chapter covers spotting C2 indicators in captured traffic; for the broader hunt methodology behind building and testing a hypothesis like this, see the Threat Hunting module.

Network Forensics Workflow

Working a network forensics question follows a consistent order, moving from what's available to what actually answers the question.

1Identify Capture PointsDetermine what's available: perimeter, internal, or endpoint capture.
→
2Select the Right SourceNetFlow for scope across time, pcap for detail on a specific window.
→
3Extract and ReconstructPull the relevant sessions and rebuild the conversations that matter.
→
4Correlate with Host ArtifactsMatch network findings against what earlier chapters found on the host.

Network evidence is strongest when it corroborates what chapters 3 and 4 already found on the host, turning a suspected connection into a confirmed one.

Key Takeaways

  • NetFlow is cheap and long-retained but metadata-only; full packet capture has the detail but is expensive to keep, so investigations usually start with flow data and escalate.
  • Packet analysis means filtering down to relevant traffic, following a stream to rebuild a conversation, and extracting transferred objects for separate analysis.
  • Wireshark and its command-line counterpart read raw packets; Zeek generates structured logs from traffic instead, which is easier to search at scale.
  • TLS hides request and response content but usually still exposes the SNI hostname, certificate details, and traffic timing and volume, though Encrypted Client Hello can hide SNI too.
  • JA3/JA3S fingerprinting identifies client and server software from the TLS handshake itself without decrypting the payload; JA4 is the newer successor fingerprint as clients randomize handshakes more.
  • C2 traffic often stands out through regular beaconing intervals, jitter, mismatched user-agents, or unusual destination infrastructure, and network findings are strongest when they corroborate host-level evidence.

Knowledge Check

Click an answer to reveal the explanation.

An investigator needs to determine whether a host has been beaconing to a suspicious IP over the past three months, but full packet capture for that period no longer exists. What's the best source to check next?

Correct answer: B. NetFlow is metadata-only and far cheaper to store, so it's commonly retained for months or longer after full pcap has aged out, making it the right place to look for connection history over that timeframe.

Which characteristic most reliably distinguishes automated C2 beaconing from normal human-driven web browsing?

Correct answer: B. Malware checking in on a schedule produces regular-interval callbacks, sometimes with jitter added to evade simple detection. Human browsing is irregular by nature, which is what makes consistent timing stand out.

A session is encrypted with TLS. Which of the following is still visible to an investigator without decrypting the traffic?

Correct answer: B. TLS encrypts the actual request and response content, but the SNI field, certificate details, and traffic timing and volume remain observable, which is also what JA3/JA3S fingerprinting relies on.