Goal

Interpret packet captures, understand protocol behavior and extract relevant information.

Concepts

  • TCP three-way handshake, retransmissions, flags
  • Payload analysis and data extraction
  • Filtering and BPF expressions

Tools

  • tcpdump, tshark, Wireshark
  • ngrep, scapy (for packet manipulation/generation)

Suggested labs

Lab 11 - MFA Bypass via AiTM

Simulation of an adversary-in-the-middle attack to capture session cookies and bypass MFA in an OT-ICS environment.

Advanced 90 min

Practical exercises

  • Capture the TCP handshake between client and server and identify SYN/ACK fields
  • Filter traffic by IP/port and export pcap for Wireshark analysis