The Basic
PCAP is always my favorite data source, I love it <3
1. Find the suspicious host
After you find the infected host -> you isolated the traffic
ip.addr eq <ip_address>Kerberos CNAME String for the username of the machine
Indicator of suspicious
Last updated