Tshark によるプロトコル解析では、packet capture を readable conversation と structured evidence に変える protocol-aware command-line workflow を学びます。3 個の guided lab で capture/display filter、TCP stream reconstruction、field extraction、CSV を扱い、最後の challenge で prepared PCAP から command-and-control activity を特定します。
isolated Ubuntu 22.04 VM で local traffic と準備済み capture を使用します。packet summary を手作業で追う代わりに、decoded HTTP/DNS field を query し、analysis artifact を保存し、shell や downstream system が利用できる output を作ります。
学習内容
- Tshark で traffic を capture し、PCAP evidence を保存して collection と offline analysis を区別
- protocol-aware display filter で HTTP、DNS、IP、request traffic を分離
- protocol hierarchy statistics で capture の構成を評価
- TCP stream index を特定し、完全な HTTP request-response conversation を再構築
- reconstructed stream を text evidence として保存し、GET/POST activity を解釈
- frame、IP、DNS、HTTP URI、host、User-Agent field を clean CSV-style output に抽出
- DNS query を deduplicate し、suspicious domain と download URI を分離する threat-hunting workflow を自動化
このコースの対象者
packet の基礎を理解し、raw capture summary より豊かな protocol analysis を求める SOC 学習者、Security Analyst、network investigator、Linux user 向けです。tcpdump 入門の次に適しますが、同等経験でも受講できます。
前提知識: 基本的な Linux shell pipeline/redirection と、IP、TCP stream、DNS、HTTP、port、PCAP の知識。Tshark/Wireshark 経験は不要です。
学習環境: ブラウザー Ubuntu 22.04 VM で行う 4 個の独立 activity(3 guided lab、1 challenge)。Tshark、local DNS/HTTP traffic、sample capture、prepared suspicious PCAP が用意され、Wireshark desktop GUI は使いません。
よくある質問
tcpdump の packet analysis course と何が違いますか?
tcpdump course は interface capture、BPF、raw payload、PCAP を重視します。本 course は Tshark の Wireshark dissector/display filter で named field、TCP conversation、protocol statistics、structured export を扱います。
Wireshark graphical application は必要ですか?
不要です。すべて Tshark を terminal で使用します。Wireshark の protocol decoding engine は使いますが、desktop GUI は必要なく、学習対象でもありません。
challenge は live malware を解析したり実在 C2 に接続したりしますか?
いいえ。simulated DNS/HTTP evidence を含む prepared suspicious_traffic.pcap を読みます。malware を実行せず、external command-and-control system に通信しません。
HTTPS などの encrypted session を decrypt しますか?
いいえ。decoded metadata と意図的に readable な DNS/HTTP traffic を調べます。session key は提供せず TLS decryption も扱わないため、encrypted application payload は対象外です。





