PHASE: File Extraction33% COMPLETION
Abort Mission
MODULE 16

Network Forensics

Reconstructing files and user activity from PCAP data.

File Extraction

< div class="space-y-4" >

Wireshark isn't just for looking at headers. You can pull files out of the air.

< div class="bg-blue-900/20 p-4 rounded border border-blue-500/30" >

File -> Export Objects -> HTTP < br >
This will reconstruct any images, PDFs, or executables transferred over unencrypted HTTP. Great for proving malware delivery.