02 / CASE STUDY
Network traffic triage
Turn Wireshark CSV counts into scoped investigative leads.
Open offline demo →Developed with AI coding assistance; validated through documented automated tests. I defined the project goals and reviewed the delivered results. AI agents assisted with implementation and executed the documented automated tests.

Challenge
Prioritize packet-export patterns while keeping aggregation scope and missing evidence explicit.
Environment
Offline Wireshark CSV analysis; local File API; 10 MiB / 50,000-row limits. Embedded fictional samples use reserved documentation addresses.
Built
CSV validation, full-capture dashboards, six configurable count rules, coverage indicators and alert filters. Destination-port diversity is counted per source–destination pair, not across unrelated destinations.
Tested
Existing tests cover CSV edges and exact threshold boundaries. Existing real-browser runs report 24 checks at each width, including File/DataTransfer import. The copied engine and portfolio demo path are re-exercised here.
Concepts
Entity-scoped aggregation, strict greater-than thresholds, evidence coverage and benign alternatives.
Outcomes
The normal fixture has 13 packets and no default alerts. The mixed lab has 139 packets and demonstrates all six rule types. Filters do not alter capture-wide totals.
Takeaways
Eleven ports spread across eleven destinations must not be confused with eleven ports on one destination. Duration and collection scope are prerequisites for interpretation.
Limitations
CSV only, not PCAP. No time-normalized rates, SYN inspection, baseline, malware verdict or risk score. Partial port coverage can undercount.