Defensive labs About 1 min read
Offline packet and trace reading
Read an offline trace with a specific question in mind. Record the observed bytes, supported conclusions and information missing from the capture.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Offline research and planning only; product or deployment acceptance belongs to separately governed environment validation.
On this page
Overview#
Lab class: Offline fixture
Purpose#
Build a layered interpretation without assuming a dissector's label proves semantics, security or conformance.
Procedure#
- Use a synthetic fixture or a sanitised capture with documented ownership, authority, provenance, and digest.
- Record capture source, topology, timestamp/timezone, interface, filter, truncation and packet loss limitations.
- Identify physical/link, network, transport, security/session, application and domain layers.
- Reconstruct endpoints, connection direction, DNS/discovery, multicast groups and negotiated ports.
- Identify plaintext versus protected portions; don't import real private keys into general analysis tooling.
- Follow one transaction/event/stream using sequence, transaction, session and correlation identifiers.
- Mark retransmission, duplicate, gap, out of order, reset, timeout and reconnect evidence.
- Compare observed fields with the exact standard/profile/vendor revision.
- Redact addresses, credentials, media, card values, identities and facility details before sharing notes.
Questions#
- Which endpoint initiated the connection and who authenticated whom?
- Are discovery and operational traffic scoped to intended zones?
- Does encryption cover only credentials, the whole control session, media, or nothing?
- Which delivery acknowledgement exists, and what does it actually prove?
- Are timestamps source, transport or capture timestamps?
- Could the trace be incomplete because of switching, offload, multicast or asymmetric routing?
Evidence checklist#
- Fixture provenance, authority, digest, sensitivity, capture point, and topology recorded
- Capture time basis, filter, snap length, offload, asymmetry, loss, and truncation limitations documented
- Link, network, transport, security/session, application, and domain layers separated
- One transaction, event, or stream followed through identifiers and timing
- Retransmission, duplication, gaps, reordering, resets, timeout, and reconnect evidence distinguished
- Protection, authentication, acknowledgement, and conformance claims bounded to observed evidence
- Addresses, identities, credentials, media, and facility details sanitised before sharing