This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Suspected rootkit or trojan, how to be sure I capture all packets?

0

How can I be sure I capture all packets on a pc that likely has a rootkit or trojan. I know some rootkits are able to hide from what Wireshark can capture. I have an extra laptop, is it possible I run Wireshark on the laptop and somehow connect it to the pc to capture packets?

asked 16 Aug '16, 09:23

Datura007's gravatar image

Datura007
6223
accept rate: 0%


One Answer:

0

Yes, see this page for instruction on how to capture traffic of other machine than the one running Wireshark. But to be able to capture and to be able to understand the contents (or even identify the traffic for which the Trojan is responsible among all the other traffic) are different tasks.

answered 16 Aug '16, 09:35

sindy's gravatar image

sindy
6.0k4851
accept rate: 24%