← Back to list

Wireshark: Traffic Analysis — Quick Summery

Nmap Scans

HackingSkills · 2023-06-04 04:13 · 0 claps · 1.9 min read
#tryhackme #blueteame #ecir #elearnsecurity #skills
Open on Medium ↗

Wireshark: Traffic Analysis — Quick Summery

Nmap Scans

Filters to detect nmap scans:

To detect TCP Connection Scan:-

tcp.flags.syn==1 and tcp.flags.ack==0 and tcp.window_size > 1024

To detect SYN Scan:-

tcp.flags.syn==1 and tcp.flags.ack==0 and tcp.window_size <= 1024

To detect closed UDP ports:-

icmp.type==3 and icmp.code==3

ARP Queries:-

(((http.request or tls.handshake.type == 1) and !(ssdp))) && (tls.handshake.extensions_server_name == “accounts.google.com”)


메타데이터
post_id
6f9ce9ab0f87
slug
wireshark-traffic-analysis-quick-summery-6f9ce9ab0f87
url
https://medium.com/@1cyb3rs3curity1/wireshark-traffic-analysis-quick-summery-6f9ce9ab0f87
canonical_url
https://medium.com/@1cyb3rs3curity1/wireshark-traffic-analysis-quick-summery-6f9ce9ab0f87
author_url
https://medium.com/@1cyb3rs3curity1
status
ok
fetched_at
2026-06-29 01:02:39