SOC LAB / LOCAL-FIRST

Network Traffic Triage

From packet counts to better investigative questions.

1. Load a capture

Awaiting CSV. No data loaded.

2. Set investigative thresholds

Strictly greater than, capture-wide counts—not packets per second. Severity means investigative priority, not a verdict.

Full capture dashboard

Metrics and top-10 rankings always describe the entire loaded capture, unaffected by alert filters.

3. Filter investigative alerts

How to Think Like an Analyst

  1. Confirm authorization and capture scope.
  2. Establish duration, collection point and expected host roles.
  3. Check completeness and unavailable fields before drawing conclusions.
  4. Compare full-capture counts with normal operational behavior.
  5. Inspect an alert’s packets, protocols and peers in Wireshark.
  6. Seek benign explanations; correlate authorized logs and activity.
  7. Record evidence, uncertainty and next steps—never label a host malicious from a count alone.

Export from Wireshark

Open an authorized capture. Choose File → Export Packet Dissections → As CSV. Choose all packets or a deliberately scoped displayed subset. Include Source, Destination and Protocol columns; Length, Info, Time and No. are optional. Disable address/port name resolution for numeric port details. Explicit destination port columns are preferred. CSV is not PCAP or PCAPNG.

ICMP and ICMPv6 are combined for the ICMP rule (including neighbor discovery). DNS counts are packets, including responses and retries—not necessarily queries. Port rules use explicit numeric destination ports or numeric TCP/UDP “source > destination” Info prefixes only; coverage can be partial. Missing length makes mean length unassessable. Missing reliable port data makes the port rule unassessable. SYN/TCP flag analysis is deferred.