This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Network Traffic classification

0

Is there any tool or method to separate normal traffic and malicious traffic from pcap? For example : if malicious traffic detected with snort i need to store those packets .only if malicious traffic . if ($pcap==snort.signature(i mean it's malicious) then store this packet.sorry for my bad english. .Thanks for respond.

asked 30 Nov '14, 11:16

Chinguun's gravatar image

Chinguun
11112
accept rate: 0%


One Answer:

1

If you're trying to confirm if there's a way to use Snort filters in Wireshark when reading a packet capture file, sorting by one Snort rule or another, I haven't used it myself but there is a plugin to allow for this within Wireshark: http://www.honeynet.org/node/790

answered 01 Dec '14, 16:03

Quadratic's gravatar image

Quadratic
1.9k6928
accept rate: 13%

thanks for respond.But git link doesnt work .how solve this ?

(02 Dec '14, 00:45) Chinguun