This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

PCAP file extracting

0

Hello ,

i am new with wireshark, we think that an employee is hacking/transferring files from another PC. i have the traffic captured for the 2 PCs but i don't know where to look or how can i find the data transferred.

he used VNC to view/copy data. i can see the VNC protocol but cant find anything else. is there a way to find the transferred files name/folder ?

thanks .

asked 08 Jan '17, 23:14

mohamed%20ismaiel's gravatar image

mohamed ismaiel
6112
accept rate: 0%