Skip to main content
AD Academy
SOC Analyst — Read traffic, logs, and attacks
Intermediate14 minLast updated: Topic 1 of 3

Network Packet Anatomy — Where to look for an attacker

Ethernet / IP / TCP / Payload by OSI layers, and what to check in each layer in Wireshark.

Not read

What you will learn here

  • What to look for in each layer
  • Ready-made Wireshark filters
  • Ethernet / IP / TCP / Payload by OSI layers, and what to check in each layer in Wireshark.

Analogy: A network packet is an envelope within an envelope. The postman (L2) only looks at the physical address, the branch (L3) at the city, the office (L4) at the room number, and only at the end someone opens the letter itself (L7). A good analyst knows in which envelope the problem is hidden.

The frame has four layers: L2 Ethernet with MAC addresses (where ARP spoofing appears), L3 IP with source and destination addresses (scanning and DDoS), L4 TCP/UDP with ports and flags (SYN flood and port scan — SYN without ACK), and L7 payload with HTTP, DNS and SMB (C2 servers and DNS tunneling). Below are practical Wireshark filters per layer. Each layer adds its own header on the way out and the receiver strips it.

What to look for in each layer

  • L2 — MAC Address: The same IP address with two different MACs, or recurring Gratuitous ARP, indicate ARP Spoofing and Man-in-the-Middle.
  • L3 — Source and Destination Addresses: One source contacting hundreds of destinations = scanning; thousands of sources to one destination = DDoS. An unusual TTL also reveals scanning tools.
  • L4 — Ports and Flags: Many SYNs without ACKs = Port Scan or SYN Flood. Multiple RSTs = closed ports, meaning someone is trying.
  • L7 — Payload: Long and encoded DNS queries = DNS Tunneling; strange User-Agent or large POSTs to an unknown destination = C2 or data exfiltration.

Ready-made Wireshark filters

# Port Scan: SYN without ACK
tcp.flags.syn == 1 && tcp.flags.ack == 0

# All traffic to/from a specific computer
ip.addr == 10.0.0.55

# Suspected ARP Spoofing
arp.duplicate-address-detected || arp.opcode == 2

# Suspicious DNS (long names / TXT)
dns.qry.name.len > 40 || dns.qry.type == 16

# Data Exfiltration via HTTP
http.request.method == "POST" && http.content_length > 100000

# SMB between workstations (Lateral Movement)
tcp.port == 445 && ip.src != 10.0.0.10
bash
Architecture and Theory — Under the Hood

Every network packet contains layers of Encapsulation. The analyst disassembles them just like a box: Ethernet → IP → TCP/UDP → Payload (HTTP, SMB, DNS). Each layer tells a different story about the attack.

  • Ethernet: who sent to whom at the hardware level — reveals MITM and ARP Spoofing.
  • IP: source/destination addresses, TTL — unusual TTL reveals Traceroute/scanning.
  • TCP: Flags (SYN/ACK/FIN/RST), Sequence — SYN without ACK at scale = Port Scan.
  • Payload: Encrypted or Cleartext Data — C2 characters, DNS Tunneling queries, unusual SMB requests are hidden here.
Practical Configuration (PowerShell / GUI)
# Useful Filters in Wireshark
tcp.flags.syn == 1 && tcp.flags.ack == 0        # SYN without ACK - Scan
tcp.analysis.retransmission                     # Packet Loss
dns.qry.name contains ".xyz"                    # Suspicious Domains
smb2.cmd == 3                                   # SMB Session Setup
kerberos.CNameString contains "$"               # Computer accounts requesting tickets

# tshark - Command Line
tshark -r capture.pcap -Y 'dns' -T fields -e dns.qry.name | sort -u
bash
Real-world Scenarios in the Organization
  • C2 Beaconing — connecting at regular intervals (every 60 seconds) to the same external IP.
  • DNS Tunneling — long and random queries for TXT/NULL records.
  • — multiple TGS-REQ for service accounts from the same source.
  • Lateral Movement — SMB (445) between user workstations, not just to servers.
Diagnosis and Troubleshooting
  • No traffic in Capture → SPAN/Mirror Port not configured on the Switch.
  • Huge PCAP → cut with editcap by time or editcap -c by packet count.
  • Encrypted traffic (TLS) → look for external signs: JA3, SNI, packet size, rate.
Glossary and Quick Command Line
  • Wireshark + tshark = the basics.
  • Zeek/Suricata = analysis at scale.
  • JA3 = TLS Client fingerprint.
  • PCAP → Zeek logs → Elastic/Splunk.

Check yourself

In which layer is a SYN Flood identified?

Long and encoded DNS queries for one domain hint at…

Was this page helpful?