Packets are ground truth. Once you can read Wireshark, phishing captures, malware beacons and broken apps all become readable stories.
Follow the steps β click any step card to replay the terminal demo from that point. Everything runs in a lab you control.
In your lab: capture on the host-only vboxnet interface for clean traffic.
Display filters are 90% of Wireshark skill. Learn 20 of them.
Reassembles the whole exchange β where cleartext credentials reveal themselves.
Long, random-looking DNS names = classic tunneling/exfil indicator.
Carve files right out of a pcap β a CTF forensics staple.
| http / dns / tcp | protocol display filters |
| ip.addr == x | traffic to/from a host |
| tcp.port == 445 | port filter |
| tcp.stream eq N | one conversation |
| frame contains 'pass' | find bytes/payload |
| -Y / -w (tshark) | cli filter / write |
Color rules: right-click a packet β Coloring Rules make evil pop visually.
CyberDefenders has dozens of free pcap labs β best practice exists.
Ctrl+Alt+T toggles time display format; seconds-since-previous kills in IR.
Statistics β Protocol Hierarchy shows who the capture is really about.
Use Wireshark only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β plenty of legal targets, zero risk.