Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A security analyst is performing a network forensic investigation. The analyst needs to reconstruct a series of HTTP requests and responses from a PCAP file to understand user activity and potential data exfiltration. Which command-line tool is specifically designed for extracting and reassembling TCP/IP streams, including HTTP conversations, from a PCAP?
- AWireshark (CLI)
- Btshark
- Ctcpdump
- Dnetstat
Show answer & explanationAnswer & explanation
Correct answer: B. tshark
Tshark is the command-line version of Wireshark and is specifically designed for analyzing and extracting data from packet capture files, including the ability to reconstruct TCP/IP streams and display application-layer protocols like HTTP.
Why the other options are wrong
- A. Wireshark (GUI) is excellent for this, but the question specifies a 'command-line tool'.
- C. Tcpdump is primarily for capturing and displaying raw packet data, not for reassembling application-layer streams.
- D. Netstat displays network connections, routing tables, and interface statistics on a live system, not for analyzing PCAP files.
Tshark
The command-line network protocol analyzer that is part of the Wireshark suite, used for capturing, displaying, and analyzing packet data from live networks or saved PCAP files.
- Command-line version of Wireshark
- Supports stream reassembly
- Powerful filtering and export capabilities
Memory trick: PCAP Analysis: Tshark for CLI, Wireshark for GUI.