data:image/s3,"s3://crabby-images/5f870/5f8702f450a26ed8492339081a0b3becdbe25294" alt=""
Extract files from a TCP stream when given a PCAP file and Wireshark
Implementing Cisco Cybersecurity Operations (210-255)
For this example, I made a sample pcapng file using Wireshark. I did a wget of a graphics file from my website.
data:image/s3,"s3://crabby-images/d4cc1/d4cc19f314c842225ab7b770ceee73ef07f6b65d" alt=""
- Go to File>Export Objects>HTTP (works the same with the other protocols listed)
data:image/s3,"s3://crabby-images/2c090/2c090a8afcb7233886cb155b51b8c1345ce2fec9" alt=""
2. Choose the file you want to save and click save.
data:image/s3,"s3://crabby-images/d84f2/d84f29dc9ffd88b52d742069f0c702a68cd20144" alt=""
For this example, only one file object existed in the captured traffic. Also, keep in mind that this will not work with SSL/TLS encrypted traffic unless several things are in place. It is also important to note when dealing with potential malicious traffic that the files saved will not be defanged.