{"id":13647170,"url":"https://github.com/packetrat/packethunting","last_synced_at":"2025-04-22T02:30:59.445Z","repository":{"id":101863900,"uuid":"138781884","full_name":"packetrat/packethunting","owner":"packetrat","description":"Resources and materials for DEF CON 2018 Packet Hunting Workshop","archived":false,"fork":false,"pushed_at":"2018-08-12T20:27:50.000Z","size":42527,"stargazers_count":77,"open_issues_count":1,"forks_count":10,"subscribers_count":10,"default_branch":"master","last_synced_at":"2024-11-09T21:36:30.314Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/packetrat.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2018-06-26T19:10:37.000Z","updated_at":"2024-07-28T14:10:21.000Z","dependencies_parsed_at":null,"dependency_job_id":"886e658d-0426-4625-a999-3faf0b90e07c","html_url":"https://github.com/packetrat/packethunting","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/packetrat%2Fpackethunting","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/packetrat%2Fpackethunting/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/packetrat%2Fpackethunting/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/packetrat%2Fpackethunting/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/packetrat","download_url":"https://codeload.github.com/packetrat/packethunting/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":250163574,"owners_count":21385261,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-02T01:03:22.592Z","updated_at":"2025-04-22T02:30:59.434Z","avatar_url":"https://github.com/packetrat.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"# Packet Mining for Privacy Leakage\n\nPacket captures \u0026 commands for DEFCON 2018 Packet Mining Workshop:\u003cbr/\u003e\nhttps://defcon.org/html/defcon-26/dc-26-workshops.html#porcello\n\nSome packet capture traffic courtesy of chrissanders.org \u0026 wireshark.org:\u003cbr/\u003e\nhttps://github.com/chrissanders/packets\u003cbr/\u003e\nhttps://wiki.wireshark.org/SampleCaptures\n\n\n### Getting started\nInstall mining tools:\n```\n# apt update \u0026\u0026 apt install ngrep tcpflow xplico ssldump dsniff tshark p0f pads python-html2text\n```\nSet a variable for your capture file name:\n```\n# CAPFILE=CaptureFile.pcap\n```\n### Tcpdump basics\nBasic local capture:\n```\n# tcpdump -vvv -nn -i eth0 -w output.cap\n```\nReading a capture:\n```\n# tcpdump -vvv -nn -r output.cap\n```\nRemote capture through ssh (Capture on remote host's eth0):\n```\n# ssh dave@10.0.0.10 'sudo tcpdump -vUnni eth0 -w -' \u003e output.cap\n```\nShow HTTP traffic on port 80:\n```\n# tcpdump -vvvAnn -i eth0 port 80\n```\nShow SMTP/POP3 traffic for specific host:\n```\n# tcpdump -vvvAnn -i eth0 'host 10.0.0.10 and port (25 or 110)'\n```\nSave filtered traffic to a new file (Example: Save only DNS traffic to a new file):\n```\n# tcpdump -r $CAPFILE -w dns-only.cap port 53\n```\n### Ngrep basics\nPrint live web traffic to console:\n```\n# ngrep -d eth0 -W byline -q -t port 80\n```\nGrep live network traffic for \"password\"\n```\n# ngrep -d eth0 -q -t -i 'password'\n```\nGrep for HTTP GET/POST requests:\n```\n# ngrep -d eth0 -W byline -q -t '^(GET|POST)' port 80\n```\n### Tcpflow basics\nPrint ASCII packet data to console:\n```\n# tcpflow -c -s -r $CAPFILE\n```\nExtract all flows, objects, \u0026 files to output folder:\n```\n# mkdir tcpflow\n# tcpflow -a -r $CAPFILE -o tcpflow/\n```\n### Connection stats\nTop 10 source IPs:\n```\n# tcpdump -nn -r $CAPFILE |grep \" IP \" | awk '{print$3}' |cut -d. -f -4 |sort |uniq -c |sort -nr |head\n```\nTop 10 destination IPs:\n```\n# tcpdump -nn -r $CAPFILE |grep \" IP \" | awk '{print$5}' |cut -d. -f -4 |sort |uniq -c |sort -nr |head\n```\nTop connection pairs:\n```\n# tcpdump -nn -r $CAPFILE |grep \" IP \" | awk '{print$3,$4,$5}' |sort |uniq -c |sort -nr |head\n```\nTop IP protocols:\n```\n# tcpdump -nn -v -r $CAPFILE |grep \" IP \" |awk -F, '{print$6}' |sort |uniq -c |sort -nr\n```\nTop 10 destination ports (based on SYN packets):\n```\n# tcpdump -nn -r $CAPFILE |grep \" IP \" |grep \"Flags \\[S\\]\" |awk '{print$5}' |cut -d. -f 5- |sort |uniq -c |sort -nr |head\n```\n### DNS digging\nTop domains:\n```\n# tcpdump -nn -r $CAPFILE port 53 | egrep \" A\\? \" | awk '{print$8}' | egrep -io \"[a-z0-9]*\\.[a-z]*\\.$\" | sort | uniq -ic | sort -nr | head\n```\nTop subdomains:\n```\n# tcpdump -nn -r $CAPFILE port 53 | egrep \" A\\? \" | awk '{print$8}' |sort |uniq -c |sort -nr |head\n```\n### Private IP/MAC address leakage\nGrep for private IPs in packet data:\n```\n# ngrep -q -t -W byline -I $CAPFILE '10\\.([0-9]{1,3}\\.){2}[0-9]{1,3}|192\\.168\\.[0-9]{1,3}\\.[0-9]{1,3}|172\\.([0-9]{1,3}\\.){2}[0-9]{1,3}'\n```\nGrep for MACs in packet data:\n```\n# ngrep -q -t -W byline -I $CAPFILE '([0-9a-fA-F][0-9a-fA-F]:){5}([0-9a-fA-F][0-9a-fA-F])' not port 5353\n```\n### Passive OS/app profiling\nOS/app summary via p0f:\n```\n# p0f -r $CAPFILE |egrep \"^\\| (os|app)\" |sort |uniq\n```\nOS/app list via PADS:\n```\n# pads -v -r $CAPFILE -w assets.csv port 80\n```\n### Profiling HTTP traffic\nTop 10 websites:\n```\n# ngrep -I $CAPFILE -W byline -q -t '^(GET|POST)' port 80 | grep \"^Host:\" | sort |uniq -ic |sort -nr |head\n```\nTop 10 referrers:\n```\n# ngrep -I $CAPFILE -W byline -q -t '^(GET|POST)' port 80 | egrep \"^Referer: \" |sort |uniq -ic | sort -nr |head\n```\nTop 10 GET requests (URLs):\n```\n# ngrep -I $CAPFILE -W byline -q -t '^(GET )' port 80 | grep \"^GET \" | sort |uniq -ic | sort -nr |head\n```\nHTTP POSTs \u0026 POST data:\n```\n# ngrep -I $CAPFILE -W byline -q -t '^(POST )' port 80 | egrep \"^POST|^\u003c|^[a-z]\"\n```\nURL log with timestamps:\n```\n# ngrep -I $CAPFILE -W byline -q -t '^(GET|POST)' port 80 |egrep \"^T |^(GET|POST)|^Host:|^$\"\n```\nUnique cookies:\n```\n# tcpflow -r $CAPFILE -c -s port 80 | grep -v \"\\.\\.\" | grep \"^Set-Cookie\" | sort |uniq\n```\nUnique session IDs/UUIDs:\n```\n# tcpflow -r $CAPFILE -c -s port 80 | grep -v \"\\.\\.\" | egrep -i \"session.id|sessionid|session.token|SESSID|UUID|oauth|Authorization:\"    ### Add some --color if needed!\n```\nUser-Agent profiling:\n```\n# ngrep -I $CAPFILE -W byline -q -t port 80 | egrep \"^User-Agent: \" |sort |uniq -ic | sort -nr\n```\n### Extracting objects/files\nExtract all objects/files \u0026 decode HTML:\n```\n# tcpflow -a -r $CAPFILE -o tcpflow/\n```\nBreakdown by file type:\n```\n# find tcpflow/ |egrep -o \"\\.[a-zA-Z]*$\" |sort |uniq -ic |sort -nr\n```\nExtracting \u0026 decoding with xplico:\n```\n# xplico -m pcap -f $CAPFILE\n```\n### Content profiling\nSearch engine queries:\n```\n# ngrep -I $CAPFILE -W byline -q -t port 80 | egrep 'GET \\/search\\?q=' |sort |uniq\n```\nURL \"keyword\" strings:\n```\n# ngrep -I $CAPFILE -W byline -q -t '^(GET|POST)' port 80 | egrep \"^GET |^POST |^Referer: \" | egrep -o \"[a-z-]*\" | egrep \"[a-z-]*-[a-z-]*-\" | egrep -v \"(^-|-$)\" |sort | uniq -ic |sort -nr |head\n```\nTop words from HTML content:\n```\n# cat tcpflow/*.html |html2text | egrep -o '\\w{4,}' |sort |uniq -c |sort -nr |head -n25\n```\n### Personal contact info\nEmail addresses with common TLDs:\n```\n# tcpflow -r $CAPFILE  -c -s | egrep -i --color '\\w+@[a-zA-Z_]+?\\.(com|org|net|gov|mil|edu|co|biz|info)'\n```\nEmail addresses with *any* TLD (more false positives): \n```\n# tcpflow -r $CAPFILE  -c -s | egrep -i --color '\\w+@[a-zA-Z_]+?\\.[a-zA-Z]{2,6}'\n```\n\"Dashed\" phone numbers:\n```\n# tcpflow -r \"$CAPFILE\" -c -s port 80 | grep --color -P \"\\d{3}-\\d{3}-\\d{4}\"\n```\nDashed or dotted phone numbers (more false positives):\n```\n# tcpflow -r \"$CAPFILE\" -c -s port 80 | grep --color -P \"\\d{3}[-.]\\d{3}[-.]\\d{4}\"\n```\n### Email traffic\nEmail senders, recipients, \u0026 email subjects:\n```\n# ngrep -q -t -W byline -I $CAPFILE port 25 or port 110 |egrep \"^To:|^From:|^Subject\"\n```\nEmail client apps \u0026 AV scanners:\n```\n# tcpflow -c -s -r $CAPFILE port 25 or port 110 |egrep -A1 \"^User-Agent:|X-Antivirus\" |sort -u\n```\nExtract emails to console:\n```\n# tcpflow -c -s -r $CAPFILE port 25 or port 110\n```\nExtract emails to disk:\n```\n# tcpflow -a -r $CAPFILE port 25 or port 110  -o tcpflow/\n```\nExtracting email attachments:\n```\n# tcpflow -C -0 -r $CAPFILE port 25 or port 110\n# cat base64.txt | base64 -d \u003e file.xxx\n# file file.xxx   ### Verify file is correct type\n```\n### Password hunting\nFTP, Telnet, SMTP, POP3, HTTP, etc:\n```\n# ngrep -I $CAPFILE -W byline -q -t | egrep --color \"[Pp]assword[=:]|\u0026[Pp]ass=|[Ss]ecret=|pwd=|^PASS|^USER |^AUTH |login:|^Authorization:\"\n```\nDecoding HTTP Basic auth, SMTP, POP3 (base64): \n```\n# echo 'QWxhZGRpbjpPcGVuU2VzYW1l'  | base64 -d\n```\nFinding SNMP community strings:\n```\n# tcpdump -A -nn -r $CAPFILE port 161\n```\n### Digging for PII \u0026 confidential data\nCredit card numbers:\n```\n# tcpflow -c -s -r $CAPFILE | grep -P --color '(6011|5[1-5]\\d{2}|4\\d{3}|3\\d{3})[- ]\\d{4}[- ]\\d{4}[- ]\\d{4}'\n```\nSocial security numbers:\n```\ntcpflow -c -s -r $CAPFILE | grep -P --color '[ ^]([0-6]\\d\\d|7[0-256]\\d|73[0-3]|77[0-2])[- ]\\d{2}[- ]\\d{4}'\n```\nDOB/License/Passport numbers:\n```\n# tcpflow -c -s -r $CAPFILE | grep -v Cookie |egrep --color 'DOB[:= ]|[Pp]assport[:= ]|[Ll]icense number'\n```\nClassified/tagged documents:\n```\n# tcpflow -c -s -r $CAPFILE | grep -v Cookie |egrep --color -i 'CONFIDENTIAL|PROTECTED|INTERNAL USE ONLY|TOP SECRET|CLASSIFIED'\n```\n### Parsing SMB/CIFS traffic\nSMB users, domains, \u0026 password hashes:\n```\n# tshark -nn -r $CAPFILE -V -Y tcp.port==445 |egrep \"Lan Manager Response|NTLM Response|NTLMv2 Response|Domain name|User name|Host name\"\n```\nSMB share \u0026 file access timeline:\n```\n# tshark -nn -r $CAPFILE -V -Y tcp.port==445 |egrep \"Arrival Time: |Tree Id: |\\[Account: |\\[Domain: |\\[Host: |NT Status: |Command: |GUID handle File: \"\n```\nCarving files out of SMB traffic:\n```\n# tshark -nn -r $CAPFILE -q --export-objects smb,tmpfolder\n```\n### Parsing SQL traffic\nMySQL password hashes, queries, \u0026 responses:\n```\n# tshark -nn -r $CAPFILE -V -Y tcp.port==3306 | egrep 'Username:|Password:|Statement:|text:'\n```\nMSSQL queries \u0026 responses:\n```\n# tshark -nn -r $CAPFILE -V -Y tcp.port==1433 | egrep \"Query:|Data:|Data \\[truncated\\]:\"\n```\n### Hardware/mobile device profiling\nDevice info via HTTP:\n```\n# ngrep -I \"$CAPFILE\" -W byline -q -t port 80 | egrep --color \"device_name=|device_type=|os_version=|dev=|X-Device-Info:|Device:|DEVICE:|deviceId=|deviceModel=\"\n```\nDevice info via mDNS:\n```\n# tshark -nn -r $CAPFILE -V -Y udp.port==5353 |egrep \"Name: |product=|model=\" |sort |uniq |egrep -v \"Domain Name:|Name: _\"\n```\nWindows error reporting: Hardware vendor, model, BIOS/firmware versions, running processes, exe/dll versions, \u0026 connected USB devices:\n```\n# ngrep -I \"$CAPFILE\" -W byline -q -t '^(GET|POST)' port 80 |egrep \"^T |^GET|^Host:\" |egrep -B2 \"watson.microsoft.com.$\"\n```\nCell carrier codes:\n```\n# ngrep -I \"$CAPFILE\" -W byline -q -t port 80 | egrep --color \"mcc=|mnc=|csc=|mccmnc\"\n```\nApple plist files: extract with tcpflow, decode with plistutil:\n```\n# grep \"plist version\" tcpflow/*\n# apt install libplist-utils\n# plistutil -i \u003cplistfile\u003e\n```\n### Location tracking data\nVia Apple default weather app, Wunderground, etc:\n```\n# ngrep -I \"$CAPFILE\" -W byline -q -t '^(GET|POST|HTTP/)' port 80 |egrep \"%2Clatitude%2|maxlat=|latitude=|latlon\"\n```\nVia Windows default weather app:\n```\n# ngrep -I \"$CAPFILE\" -W byline -q -t 'weather.microsoft.com' port 80 |egrep --color \"DisplayName=\"\n```\n### Mobile apps\nAndroid apps, versions, usage, etc:\n```\n# ngrep -I $CAPFILE -W byline -q -t '^(GET )' port 80 | egrep \"^GET |^Host:\" |grep --color -A1 \"ap_an=\"\n```\nAndroid app traffic (via Dalvik agent):\n```\n# ngrep -I $CAPFILE -W byline -q -t 'User-Agent: Dalvik' port 80\n```\nApple apps/store traffic:\n```\n# ngrep -I $CAPFILE -W byline -q -t port 80 | egrep -B1 \"bundleId=|dpkg.ipa|^[Xx]-[Aa]pple\"\n```\niTunes audio downloads:\n```\n# ngrep -I $CAPFILE -W byline -q -t port 80 | egrep -B6 \"User-Agent: AppleCoreMedia\"\n```\nKindle app traffic (\"key=\" indicates ASIN of each ebook)\n```\n# ngrep -q -t -I $CAPFILE -W byline | grep --color 'type=\"EBOK\" key='\n```\nPrime video streaming file downloads:\n```\n# ngrep -q -t -I $CAPFILE -W byline | grep -B6 'Prime%20Video'\n```\n### Inspecting SSL traffic\nExtract SSL certificates with tcpflow:\n```\n# tcpflow -a -r $CAPFILE -o tcpflow/ port 443\n```\nExtract SSL websites via Server Name Indication (SNI):\n```\n# ngrep -I $CAPFILE -q -t -W byline port 443 |egrep -o \"[a-z0-9]*\\.[a-z0-9]*\\.(com|org|net|gov|mil|edu|co|biz|info)\" |sort -u\n```\nSessions using weak cipher suites:\n```\n# ssldump -n -r $CAPFILE | grep \"cipherSuite\" | egrep -i \"RC4|MD5|EXP|NULL|_DES|ANON|64\"\n```\nSessions using weak SSL protocol versions:\n```\n# ssldump -n -r $CAPFILE | grep Version |sort -u\n```\nDecrypting SSL traffic using a known private key:\n```\n# tshark -r SSL-decryption.pcap -q -o \"ssl.keys_list:192.168.56.101,443,http,server.pem\" -z \"follow,ssl,ascii,2\"\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpacketrat%2Fpackethunting","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fpacketrat%2Fpackethunting","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fpacketrat%2Fpackethunting/lists"}