Analogy: A network packet is an envelope within an envelope. The postman (L2) only looks at the physical address, the branch (L3) at the city, the office (L4) at the room number, and only at the end someone opens the letter itself (L7). A good analyst knows in which envelope the problem is hidden.
The frame has four layers: L2 Ethernet with MAC addresses (where ARP spoofing appears), L3 IP with source and destination addresses (scanning and DDoS), L4 TCP/UDP with ports and flags (SYN flood and port scan — SYN without ACK), and L7 payload with HTTP, DNS and SMB (C2 servers and DNS tunneling). Below are practical Wireshark filters per layer. Each layer adds its own header on the way out and the receiver strips it.
What to look for in each layer
- L2 — MAC Address: The same IP address with two different MACs, or recurring Gratuitous ARP, indicate ARP Spoofing and Man-in-the-Middle.
- L3 — Source and Destination Addresses: One source contacting hundreds of destinations = scanning; thousands of sources to one destination = DDoS. An unusual TTL also reveals scanning tools.
- L4 — Ports and Flags: Many SYNs without ACKs = Port Scan or SYN Flood. Multiple RSTs = closed ports, meaning someone is trying.
- L7 — Payload: Long and encoded DNS queries = DNS Tunneling; strange User-Agent or large POSTs to an unknown destination = C2 or data exfiltration.