• We just launched and are currently in beta. Join us as we build and grow the community.

PA Toolkit – A collection of security-focused traffic analysis plugins

easternfn

CTR Specialist
E Rep
0
0
0
Rep
0
E Vouches
0
0
0
Vouches
0
Posts
160
Likes
146
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 400 XP
patoolkit_3-png.143018

The PA Toolkit is a collection of traffic https://linkmonetizado.com/full?api...QuY29tL3NlYXJjaC9sYWJlbC9BbmFseXNpcw==&type=2 plugins to extend the functionality of Wireshark from a microanalysis tool and a dissection protocol to the macro analyzer and threat hunter. The PA Toolkit contains plugins (dissectors and taps) covering various scenarios for various protocols, including:
  • WiFi (WiFi network summary, detection beacon, deauth floods, etc.)
  • HTTP (listing all websites visited, files downloaded)
  • HTTPS (List all websites open on HTTPS)
  • ARP (MAC-IP table, Detect MAC spoofing and ARP poisoning)
  • DNS (Listing DNS servers used and DNS resolution, Detecting DNS Tunnels)

The project is under active development and more plugins will be added in near future.
This material was created while working on “Traffic Analysis: TSHARK Unleashed” course. Those interested can check the course here: https://linkmonetizado.com/full?api...VzdGVyYWNhZGVteS5jb20vY291cnNlP2lkPTQy&type=2
Installation
Steps:
  • Copy the “plugins” directory to Wireshark plugins directory.
  • Start wireshark.

One can get the location of wireshark plugins directory by checking Help > About Wireshark > Folders

patoolkit_2-png.143019

Tool featured at

Author

Under the guidance of Mr. Vivek Ramachandran, CEO of Pentester Academy
Documentation
For more details, see the PDF file “PA-Toolkit.pdf”. This file contains the slide deck used for presentations.
PA Toolkit screenshots
after installation

patoolkit_3-png.143020

List of websites visited via HTTP

patoolkit_4-png.143021

Search functionality

patoolkit_5-png.143022

Domain to IP mappings

patoolkit_6-png.143023



Link:






patoolkit_3-png.143017
 

435,057

313,705

313,714

Top