- DHCP traffic
- NetBIOS (NBNS) traffic
- Kerberos traffic
DHCP
| Packet / Data | Filter |
|---|---|
| DHCP Request contain the hostname information | dhcp.option.dhcp 3 |
| DHCP Request Options: 12: Hostname. 50: Requested IP address. 51: Requested IP lease time. 61: Client's MAC address | dhcp.option.hostname contains "keyword" dhcp.option.equested_ip_addres x.x.x.x |
| DHCP ACK accepted requests | dhcp.option.dhcp 5 |
| DHCP ACK Options 15: Domain name 51: Assigned IP lease time | dhcp.option.domain_name contains "keyword" |
| DHCP NAK denied requests | dhcp.option.dhcp 6 |
| DHCP NAK Options 56: Message (rejection reason) | N/A |
only "Option 53" ( request type) has predefined static values.
dhcp.option.dhcp checks option
You should filter the packet type first, and then you can filter the rest of the options by "applying as column" or use the advanced filters like "contains" and "matches".
NetBIOS (NBNS) Analysis
Global filter: nbns
"NBNS" options for grabbing the low-hanging fruits:
- Queries: Query details, could contain:
- name, Time to live (TTL) and IP address details
nbns.name contains "keyword"
Kerberos Analysis
Kerberos is the default authentication service for Microsoft Windows domains. It is responsible for authenticating service requests between two or more computers over the untrusted network. The ultimate aim is to prove identity securely.
Kerberos investigation in a nutshell:
| Notes | Wireshark Filter |
| Global search. | - kerberos |
| User account search: - CNameString: username. Note: Some packets could provide hostname information in this field. To avoid this confusion, filter the $ value. The values ending with $ are hostnames, and the ones without it are user names. | - kerberos.CNameString contains "keyword" kerberos.CNameString and !(kerberos.CNameString contains "$" ) |
| "Kerberos" options for grabbing the low-hanging fruits: - pvno: Protocol version. - realm: Domain name for the generated ticket. - sname: Service and domain name for the generated ticket. - addresses: Client IP address and NetBIOS name. Note: the "addresses" information is only available in request packets. | kerberos.pvno 5 kerberos.realm contains ".org" kerberos.SNameString "krbtg" |