What problem does it solve?
This Skill helps you investigate PCAP files when you need to understand what happened on a network, recover useful artifacts, and spot suspicious traffic patterns.
Core Features & Use Cases
- Packet and stream analysis: Use Wireshark filters and follow-stream workflows to inspect HTTP, DNS, FTP, SMTP, TLS, USB HID, WiFi, and ICMP traffic.
- Evidence extraction: Recover files, credentials, email content, payloads, and other artifacts from captured sessions.
- Detection and triage: Identify covert channels, tunneling, exfiltration, and other anomalous patterns through protocol-specific heuristics.
- Repair and decryption workflows: Fix damaged captures, convert between capture formats, and decrypt TLS traffic when key material is available.
- Use Case: A security analyst receives a suspicious capture and uses this Skill to determine whether it contains credential theft, DNS tunneling, or file transfer evidence.
Quick Start
Use this skill to inspect the attached capture, identify the main protocols, and guide me through the fastest path to recover meaningful evidence.