> For the complete documentation index, see [llms.txt](https://wiki.zacheller.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.zacheller.dev/network-security/untitled.md).

# Malware Traffic Analysis with Wireshark

![Follow a TCP Stream](https://1094113337-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-M3hoduT4ByoNaznkzhG%2F-M87Ue8GYHTwXdTb2Uw9%2F-M87chIrLUekyE3R4Uiz%2F1580472862324.png?alt=media\&token=1526da2b-1a49-4dba-b684-021a0ea3f164)

## Traffic Analysis Exercises

{% embed url="<http://www.malware-traffic-analysis.net/training-exercises.html>" %}

## Traffic Analysis Tutorials

{% embed url="<http://www.malware-traffic-analysis.net/tutorials/index.html>" %}

## Wireshark - How to Identify Hosts and Users

{% embed url="<https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users>" %}
