← All projects

02 / CASE STUDY

Network traffic triage

Turn Wireshark CSV counts into scoped investigative leads.

Open offline demo →

Developed with AI coding assistance; validated through documented automated tests. I defined the project goals and reviewed the delivered results. AI agents assisted with implementation and executed the documented automated tests.

Actual network traffic triage interface with a fictional training sample
Real Firefox screenshot · fictional bundled data only.

Challenge

Prioritize packet-export patterns while keeping aggregation scope and missing evidence explicit.

Environment

Offline Wireshark CSV analysis; local File API; 10 MiB / 50,000-row limits. Embedded fictional samples use reserved documentation addresses.

Built

CSV validation, full-capture dashboards, six configurable count rules, coverage indicators and alert filters. Destination-port diversity is counted per source–destination pair, not across unrelated destinations.

Tested

Existing tests cover CSV edges and exact threshold boundaries. Existing real-browser runs report 24 checks at each width, including File/DataTransfer import. The copied engine and portfolio demo path are re-exercised here.

Concepts

Entity-scoped aggregation, strict greater-than thresholds, evidence coverage and benign alternatives.

Outcomes

The normal fixture has 13 packets and no default alerts. The mixed lab has 139 packets and demonstrates all six rule types. Filters do not alter capture-wide totals.

Takeaways

Eleven ports spread across eleven destinations must not be confused with eleven ports on one destination. Duration and collection scope are prerequisites for interpretation.

Limitations

CSV only, not PCAP. No time-normalized rates, SYN inspection, baseline, malware verdict or risk score. Partial port coverage can undercount.