PHASE: File Extraction33% COMPLETION
MODULE 16
Network Forensics
Reconstructing files and user activity from PCAP data.
File Extraction
< div class="space-y-4" >
Wireshark isn't just for looking at headers. You can pull files out of the air.
< div class="bg-blue-900/20 p-4 rounded border border-blue-500/30" >
File -> Export Objects -> HTTP
< br >
This will reconstruct any images, PDFs, or executables transferred over unencrypted HTTP.
Great for proving malware delivery.