Brilliant. You should create a course for people to do some basic verification on their systems for malware, viruses, etc
@ChrisGreer2 жыл бұрын
Hey it is definitely something I am considering. Let me know if you'd like to see that Packet Heads! 🙂
@jaredteaches8942 жыл бұрын
@@ChrisGreer I’d love to. I bought Pluralsight just for your courses!
@viktor.madarasz2 жыл бұрын
+1
@matimematime28672 жыл бұрын
+2
@CyberNancy2 жыл бұрын
@@ChrisGreer Nice idea - it would be educational to see the impact this has on a Windows system. You could use Volatility for process listing and network connection artifacts. You could also do some registry or file system analysis as well.
@zapajd26 күн бұрын
I've been feeling lost getting the right roadmap on becoming a SOC Analyst, and man you gave me direction! I'm super excited! Thank you Chris, God bless you and keep up the great work! 🙏🏼🙏🏼
@CyberNancy2 жыл бұрын
If you're interested in learning about SOC work, this is a fast and great intro into some of the often encountered technology and trends.
@mytechnotalent2 жыл бұрын
Nice job Chris. This really shows the detail of how Malware traverses a network. Love the practical breakdown.
@ChrisGreer2 жыл бұрын
Thanks Kevin! I agree, this was a fun one to work through.
@robtot19342 жыл бұрын
There are too many words to describe the material you have offered here. Impressive, is one..... your talent to present material, it just makes you the right person for the job... Congratulation
@matimematime28672 жыл бұрын
Brilliant C.G. Please do more of these. Helps to understand the capabilites of wireshark
@ChrisGreer2 жыл бұрын
More on the way!
@Brutatech Жыл бұрын
Must say that i am pleasantly shocked from your videos and the way you present the analysis- i am working with captures almost 21 years and i still learning something from each of your videos- you are amazing !!!
@michalczapnik19882 жыл бұрын
I just wanted to take a glance at the video as i really appreciate your work and got totally sucked in! Great content and presentation. Simple, clear and effective. Would love to see more.
@ChrisGreer2 жыл бұрын
Thanks for the feedback Michal! I'll get on it.
@skizz_2 жыл бұрын
That was amazing, would love to see deeper dives on malware analysis . JA3 was mindblowing. Keep them coming! All the best.
@itguy12 жыл бұрын
Recently discovered your channel and I must admit that everything you cover is pure gold - Thank you so much for sharing your knowledge Chris!
@ChrisGreer2 жыл бұрын
Thank you! Thanks for stopping by the channel.
@chekov66682 жыл бұрын
Thank you Chris for another brilliant session! Very interesting tip with the ja3 hash and I guess that's the voodoo the new next gen firewall use to identify application level traffic?! I am looking forward to your next videos :-)
@ChrisGreer2 жыл бұрын
Agreed. I'm totally nerding out on JA3 stuff right now. Super cool.
@maumotec23452 жыл бұрын
This is not just a high technical valuable content but enjoyable 👏🏻 someone give a award to this man 🙌🏻 as always, amazing content.
@ChrisGreer2 жыл бұрын
Much appreciated!
@nd.b772 жыл бұрын
Hi Chris. I just want to say that I LIKE THIS KIND OF CONTENT A LOT!👍
@ChrisGreer2 жыл бұрын
Thank you for the feedback!
@vijay85cisco2 жыл бұрын
why iam thankful to chris. because his video and sharing his knowledge saved me in my career many times.. when my application team easily pointing anything to my network team.
@ChrisGreer2 жыл бұрын
Thank you for the comment!
@muhammadawais59742 жыл бұрын
Thanks Chris. I appreciate this effort and would love to see more of 'em in this domain.
@SoulJah8762 жыл бұрын
Very cool video - looking forward to the rest.
@lorieforchia38962 жыл бұрын
Thank you or making this video. I'm getting a degree in Cyber Security and I'm recommending this to everyone!
@mutzati Жыл бұрын
Mate, you are the pope of the Wireshark 🙏 it’s the greatest video I’ve ever seen about a Malware network activity. Thanks and we need more and more videos! 🤜💥🤛🙌🦈
@ChrisGreer Жыл бұрын
on it!
@JFrow832 жыл бұрын
That was great, could definitely sit through more videos like this.
@ChrisGreer2 жыл бұрын
More to come!
@zdzisawdyrma33192 жыл бұрын
This is very good stuff! It's a shame there wasn't material like this 10+ years ago.
@alaudet2 жыл бұрын
That's a great site for practicing with infected pcaps. Been downloading and analyzing them to cut my teeth a bit. Looking forward to future videos of files I have analyzed to see how I compare to your methodology. Excellent content as usual.
@shruthesh2 жыл бұрын
This was insightful! Please create more videos like this.
@SinisterSpatula2 жыл бұрын
Discovered you from the david bombal video and man, I'm excited to learn from your videos, this one was great! So cool to see malware attacks from a packet level perspective. If they had taken extra steps to use SSL and a normal user-agent string, aside from the foreign IP it might be a bit harder to spot.
@ChrisGreer2 жыл бұрын
Thanks for the comment! Welcome to the channel. Suggestions always welcome. 👍
@Phanda3193 күн бұрын
Extremely informative for the CTF I'm doing right now! Thank you!
@xaviervillalobos39589 ай бұрын
This was great! I'm also taking your wireshark master class on Udemy and it's awesome! Great content. Thanks!
@Astro-Stock2 жыл бұрын
Chris, great content as always! Thank you for these short little "deep dives".
@siabelle Жыл бұрын
Hello Chris, Love the way you are able to balance on more levels of difficulty and still keep in short, interesting and applicable: you go deep in the packets but seem to avoid long tails where one shoe might fit but than the pathway to the second one zzzzz … btw I learned a lot, enough to be able to identify my ex-boss -as the sneaky-creep-hacker who harassed me more than a year- I would never ever have know whiteout your video’s- thank you Mr C. next week -
@nourmaslouhi31832 жыл бұрын
Genious. Like these type of videos will be very helpful identifying which type of malware by just using pcap file. Please post more videos.
@ChrisGreer2 жыл бұрын
Thank you!
@Das_lst_Gut_Ja11 ай бұрын
You did an amazing job analyzing this infected PCAP file
@kevingendron55862 жыл бұрын
More content like this, please! This is amazing and scary. Thanks very much for sharing this.
@ChrisGreer2 жыл бұрын
Thanks Kevin!
@shivadhanrityalaya93282 жыл бұрын
Every video of Chris is an eye opener in packet analysis. To the point.. Thank you very much Chris..
@ChrisGreer2 жыл бұрын
My pleasure! Thank you for the comment!
@ruttalaabhinav81052 жыл бұрын
Looking forward for more malware analysis with wireshark
@yhytuncer Жыл бұрын
Awesome Video ! You should do more this kind of malware analysis videos with wireshark cause it’s a great skill for defenders
@otienofredrick99722 жыл бұрын
Thank you very much, Mr Chris. Please make a series of such videos for malware analysis using Wireshark.
@ChrisGreer2 жыл бұрын
I need to add more on this topic, I know!
@otienofredrick99722 жыл бұрын
@@ChrisGreer Thank you sir, I will really appreciate it! You just don't know how much you have helped me with your videos...You're impacting the world! Thank you once more Mr Chris. God bless.
@SeroeKrevedko12 жыл бұрын
Great content Mr Greer, thank you. Why attackers use plaintext for transmitting sensitive information?
@EricBrokeIt2 жыл бұрын
Definitely love this kind of video Chris. Great content.
@ChrisGreer2 жыл бұрын
Thanks Eric!
@mrj4264 Жыл бұрын
Loved the video, just wished you went more into details such as how to remove the malware (such as what ips to blacklist).
@jarbystark2 жыл бұрын
Great video as always. spent 4 hours looking for malware in my network and cant stop ;))
@ChrisGreer2 жыл бұрын
Nice! Keep going!
@pedrobarthacking Жыл бұрын
A good user friendly malware analysis! Congrats! 🏴☠️
@auslander1026 Жыл бұрын
Ja3er is down now - see github discussion. Otherwise, professional video - straight to the point
@ChrisGreer Жыл бұрын
Thank you I gotta fix that.
@melonscratcher2 жыл бұрын
Keep making the real world examples, love videos like this.
@SOC_Pavi2 жыл бұрын
Thanks, Chris for the great session. Could you help us to identify the source of infection.
@ChrisGreer2 жыл бұрын
This was probably a successful phishing attack. Watch out for those links and email attachments!
@vyasG2 жыл бұрын
Thank you Chris for this exciting video. Loved the content. Will you be adding more videos to the "Masterclass" playlist?
@ChrisGreer2 жыл бұрын
Hey Vyas! Probably not - now that the Udemy course is out there - bit.ly/udemywireshark
@majiddehbi91862 жыл бұрын
Woow Chris u are so generous with knowledge u share this the way that gentil People act thx a million a god bless u
@ChrisGreer2 жыл бұрын
Glad you liked it! Thank you for the comment!
@majiddehbi91862 жыл бұрын
@@ChrisGreer Just to add something in medcin the radiologist is the Guy who see the inside thé organs. And it s the same for u see inside thé packets (data) u heal thé network :)
@ChrisGreer2 жыл бұрын
@@majiddehbi9186 Very true! Thanks for the interesting comment.
@sugaobilboa2 жыл бұрын
I really enjoyed your video! Thank you very much for posting such incredibly interesting stuff! We want more!!! 😀
@ChrisGreer2 жыл бұрын
Well more you will get! Thanks for the comment.
@PalazonPhotograpy2 жыл бұрын
Hi, your lessons are really great ! thanks and please keep doing it. I have a question for You...what will your first reaction if when doing a capture of a pc you see no tcp packets ? beacause i got the pb in my network... for one pc i only see NBNS, MDNS, LLMNR but no TCP... i'm a bit confuse...
@cryptoknight59272 жыл бұрын
Pretty good infos. Thank you chris, i hope to know more about you actual career and how can i get useful from this great informations
@vicky5573 Жыл бұрын
Thank you. Yes, I like this type of training using Wireshark
@skynet.yousha2 жыл бұрын
Amazing lectures, this will help me in my Network forensics analysis cases. Really you make my life much easier.
@ChrisGreer2 жыл бұрын
Glad to hear that!
@benoitburdet78692 жыл бұрын
Yes I liked it !! Your videos are really intesresting. Thank you
@ChrisGreer2 жыл бұрын
Glad you like them!
@CosmeFulanito0082 жыл бұрын
Thanks Chris for all the information you bring to us, its incredible how much we can do with wireshark! A lot of things that some people maybe didn't know. Please don't stop doing this type of content, i'll be waitint for your next videos. Greetings.
@in_TH3_Moment9 ай бұрын
Just discovered you, thanks for a great guide. i hope you make more security analyst related videos.
@twinbullets18682 жыл бұрын
Excellent Video. Please create a video on setting up the GEOIP option within wireshark.
@ChrisGreer2 жыл бұрын
Got you covered! - kzbin.info/www/bejne/f525oaOiqryHftk
@twinbullets18682 жыл бұрын
@@ChrisGreer Amazing.. Thank you so much.
@bricejackson157610 ай бұрын
Thanks Chris, really enjoyed this video! Very informative and to the point!
@wie1452 жыл бұрын
Valuable tips from you. Thanks a lot. Look forward to seeing more videos
@ChrisGreer2 жыл бұрын
More to come!
@joerockhead72462 жыл бұрын
That was so cool. Would love to see more. Thank you.
@ChrisGreer2 жыл бұрын
You got it! Thanks Joe.
@RR-vy7jd2 жыл бұрын
Love it. More malware analysis will be great. Great content thx
@ChrisGreer2 жыл бұрын
More to come! Thank you.
@Closer80IT2 жыл бұрын
Very clear and interesting!
@ChrisGreer2 жыл бұрын
Thanks for the comment Fab!
@duscraftphoto2 жыл бұрын
This was great! About to check out the GeoIP video!
@ChrisGreer2 жыл бұрын
Awesome! Let me know if you like that one. Watch out for my cat to make an appearance on that one too. :-)
@duscraftphoto2 жыл бұрын
@@ChrisGreer ha ha! I saw that and it reminded me of a buddy of mine when I worked at Apple who had two cats that were in all of his video calls. Great content, on your channel, Chris. I never cared to really mess with Wireshark until I found your channel and now I'm wanting to learn all I can about packet analysis! Thank you for making amazing content and keep it up!
@ChrisGreer2 жыл бұрын
@@duscraftphoto Haha - awesome. Hey be sure to check out my new Udemy class when you get a chance - bit.ly/udemywireshark - it's full of this kind of stuff!
@DEDEPLDEDE Жыл бұрын
Nice video Chris. Where to find the updated database of JA3 hashes ?
@x0rZ15t2 жыл бұрын
Love those malware analysis videos!!!
@ChrisGreer2 жыл бұрын
Glad you like them!
@isabelledelmas53322 жыл бұрын
Excellent content, very informative. Please, create more of those!
@ChrisGreer2 жыл бұрын
Thanks, will do!
@xDx44442 жыл бұрын
I'd love to see more videos like this one. I'd also pay for Identify Cyber Attacks with Wireshark course if it were available on Udemy :(
@ChrisGreer2 жыл бұрын
Great suggestion.
@alaahaider2 жыл бұрын
Man… that was excellent video. You are a super star 🌟
@ChrisGreer2 жыл бұрын
Thanks for watching!
@jrelic Жыл бұрын
Hey Chris, nice video. I've been practicing Pentesting on my VM's on VMWare. Any videos available for that type of scenario--seeing a hack in real time through Wireshark? Or at least, detecting one after the fact through Wireshark?
@tranxn79712 жыл бұрын
That was very good thanks, this new malware analysis is really interesting.
@ChrisGreer2 жыл бұрын
Glad you liked it!
@vinyldown8490 Жыл бұрын
what a dope video dude! thank you so much! I learned so many things from this!
@ibejoe77195 ай бұрын
Good stuff! definitely make more and if possible in your own website and charge a small fees for a certificate of completion 😅
@philosphize10 ай бұрын
Awesome video, please make more content on malware analysis
@ChrisGreer10 ай бұрын
Thanks, will do!
@bakri99 Жыл бұрын
Awesome! Love this kind of videos, we need more like this 👌👌
@mrbrown64212 жыл бұрын
I love this stuff! 45 years ago I would hand disassemble Z80 code to figure out what it did, and then modify it as needed. I spent many hours digging into binary and hex files until I found this thing called a disassembler that converted it to 'readable' mnemonics along with an assembler that would do the opposite. (No internet back then) It was a wonderful place for a curious 18 year old and I loved it and it launched my career into other microprocessors and debugging methods. You, sir, are doing the same thing with that enthusiasm, but I do not know the 'language'! A neighbor flies his drone over my property all the time, and I just wanted to capture his GPS data to prove to the law both his altitude and position over my property. I would be forever thankful if someone could point me in that direction for this data collection effort. I do not know what types of drones he flies, but they are all VERY annoying and it is clearly an intimidation effort considering his darting around while we are outside (9 acres). Many thanks. Mr. Brown North Central Florida.
@madayag4082 жыл бұрын
I love your videos. I'm learning a lot. Thank you.
@ChrisGreer2 жыл бұрын
Great! I am having a bunch of fun making them.
@madayag4082 жыл бұрын
@@ChrisGreer keep it up! We love more!
@jamesadeke98732 жыл бұрын
Good morning Chris. Please can you make a video on how to preprocess network packets (PCAP)? For example to extract payload information and convert them into image to be use for CNN as its done in this paper "Malware traffic classification using convolutional neural network for representation learning"
@bbowling619 Жыл бұрын
Loving it ! Keep em coming good sir !
@volodymyrverdysh5790 Жыл бұрын
Thanks for the video! I have a question. You said that using HTTP (not HTTPS) is a mark you should pay attention at. Also, using HTTP makes all the traffic visible and available for analizyng by security specialists, some security tools and application. If the attacker didn't use HTTP but HTTPS, it wouldn't catch your eye just as you wouldn't be able to look into the traffic, because the traffic would be encrypted. The question is: what is the reason why an attacker prefers using HTTP against HTTPS?
@zdrasbuytye2 жыл бұрын
I love this guy. Thank for your time
@preadatordetector2 жыл бұрын
Man I gotta go see this site. Seems fun.
@ChrisGreer2 жыл бұрын
It is!
@Pianeta0scuro2 жыл бұрын
You are a F***ing Genius! Great Video, Great Explanation. Please more video like this. But here we have a filtered pcapng file,.The investigations star from an IDS alarm or periodic human monitoring. Real life cases are very difficult to detect without apply best practice.
@ChrisGreer2 жыл бұрын
True - it isn’t easy to find this stuff on the wire. That is why we have to have a good idea of the types of traffic to focus on. I will keep up this kind of content!
@miracdasmine2 жыл бұрын
Hi Chris, great video. Pls how do I get that JA3 stuffs in my wireshark. It's not in my packet I downloaded from the same link
@Lampshadx2 жыл бұрын
Is this the kind of stuff we can expect for the class you’re giving at Sharkfest this year
@ChrisGreer2 жыл бұрын
Yes - this is spot on with the kind of stuff I will be teaching at Sharkfest. However we won't just focus on malware - but scan traffic, exfil traffic, and c2 traffic too.
@Lampshadx2 жыл бұрын
@@ChrisGreer Great to hear. See you there!
@thiagocaval87992 жыл бұрын
Great work Chris, thanks.
@Love-yv1fc Жыл бұрын
Excellent work sir❤keep it up😊
@dezejongeman2 жыл бұрын
awesome; more of this please!
@kngced7 ай бұрын
Hey Chris, is the pcap file still available? I'm trying to follow along using the link but when I click the link it is saying "The requested URL was not found on this server."
@ltfdagci6664 ай бұрын
Thank you for this informative video. ❤
@AnkitaShenoy-i6i8 ай бұрын
such a wonderful explanation.......
@viktor.madarasz2 жыл бұрын
Need more of this
@EngrDJDebug2 жыл бұрын
do more of this kind of video chris
@ChrisGreer2 жыл бұрын
Ok for sure!
@EngrDJDebug2 жыл бұрын
@@ChrisGreer thanks Chris
@zzzfff58542 жыл бұрын
more malware analyze video please,thank you
@utkarshmishra1928 Жыл бұрын
Brilliant video Chris!!!!
@IamKhoramdin Жыл бұрын
Amazing, i really enjoy and learned alot
@minhajrahman6259 Жыл бұрын
Is there an alternative to ja3er? Seems to be down
@anders66712 жыл бұрын
This is awesome! More of this!
@ChrisGreer2 жыл бұрын
Ok will do!
@patrickspaceman305 Жыл бұрын
Glorious work, thank you.
@onrcrn2 жыл бұрын
Great!! Thank you Chris
@albertescaraugustin3981 Жыл бұрын
Yes I love it , make more of this
@danmcd4902 жыл бұрын
Love this walkthroughs
@SnortDefence Жыл бұрын
@Chris Hey Hi, I thought you will start this series and many more such malware analysis vlog will come but not seen any new after this
@ChrisGreer Жыл бұрын
Hey Praveen, you are right. I have been busy but I need to get more of these out. Thank you for the prod!!