1 min read 351 words Updated Sep 12, 2026 Created Sep 12, 2026
  • DHCP traffic
  • NetBIOS (NBNS) traffic 
  • Kerberos traffic

DHCP

Packet / DataFilter
DHCP Request
contain the hostname information
dhcp.option.dhcp 3
DHCP Request Options:
12: Hostname.

50: Requested IP address.

51: Requested IP lease time.

61: Client's MAC address

dhcp.option.hostname contains "keyword"

dhcp.option.equested_ip_addres x.x.x.x
DHCP ACK
accepted requests
dhcp.option.dhcp 5
DHCP ACK Options
15: Domain name
51: Assigned IP lease time

dhcp.option.domain_name contains "keyword"
DHCP NAK
denied requests
dhcp.option.dhcp 6
DHCP NAK Options
56: Message (rejection reason)
N/A

only "Option 53" ( request type) has predefined static values.

dhcp.option.dhcp checks option

You should filter the packet type first, and then you can filter the rest of the options by "applying as column" or use the advanced filters like "contains" and "matches".

NetBIOS (NBNS) Analysis

Global filter: nbns

"NBNS" options for grabbing the low-hanging fruits:

  • Queries: Query details, could contain:
    • name, Time to live (TTL) and IP address details
    • nbns.name contains "keyword"

Kerberos Analysis

Kerberos is the default authentication service for Microsoft Windows domains. It is responsible for authenticating service requests between two or more computers over the untrusted network. The ultimate aim is to prove identity securely.

Kerberos investigation in a nutshell:

NotesWireshark Filter
Global search.- kerberos
User account search:

- CNameString: username.

Note: Some packets could provide hostname information in this field. To avoid this confusion, filter the $ value. The values ending with $ are hostnames, and the ones without it are user names.

- kerberos.CNameString contains "keyword"

kerberos.CNameString and !(kerberos.CNameString contains "$" )
"Kerberos" options for grabbing the low-hanging fruits:

- pvno: Protocol version.
- realm: Domain name for the generated ticket.
- sname: Service and domain name for the generated ticket.

- addresses: Client IP address and NetBIOS name.

Note: the "addresses" information is only available in request packets.

kerberos.pvno 5

kerberos.realm contains ".org"

kerberos.SNameString
"krbtg"