Learn · Network forensics

The network remembers, in pieces

No single system saw everything. A switch port saw packets, a router counted flows, the proxy wrote down URLs, the door controller logged a badge, the mail server kept headers. Network forensics means collecting these pieces, putting them on one clock, and joining them into one story.

1 Where network evidence lives

Disk forensics starts with one device. Network forensics starts with a question, and the evidence is spread over many systems. Each saw the same event from a different place and kept a different part of it:

Full packets (pcap)every byte, but only where a sensor listens, and only for hours or days
Flowswho talked to whom, when, how much; no content; weeks to months
Application logsproxy, DNS, VPN, mail, logons: what the service understood
Physical & identitybadges, Wi-Fi, DHCP, asset lists: who and which device
SourceTells youCannot tell you
Packet capture (SPAN port, TAP, sensor)Exact bytes, protocol details, timing, unencrypted contentAnything outside the capture point or time; content inside TLS
NetFlow / IPFIX / Zeek conn.log5-tuple, start, duration, bytes and packets per connectionWhat was transferred; user names
Web proxyUser (if authenticated), URL or host, bytes, user agentTraffic that bypasses the proxy
DNS resolverWhich client asked for which nameWhether a connection followed; names resolved elsewhere
DHCP, Wi-Fi controller, asset inventoryWhich device had which IP address, where it was attachedWho was holding the device
Authentication (Windows, VPN, RADIUS)Which account logged on where, how, from which addressWho typed the password
Badge / physical accessWhich card opened which doorWho carried the card
Mail server and headersSender, recipients, path, times, authentication resultsContent once deleted, unless kept
The central skill: an IP address is not a person. You get from a packet to a person through a chain: IP → device (DHCP) → account (logon) → human (badge, Wi-Fi, CCTV, interview). Every link is a separate piece of evidence and can break.

2 The pages

The byte-level pages have the same interactive hex views as the file-system pages: click a field to see its bytes, click a byte to find its field.

3 Ground rules

Before you start: the File Systems in Hex pages explain hex and offsets. Network protocols store numbers big-endian ("network byte order"), unlike the little-endian file systems you have seen.

4 Warm-up

Two quick checks before you start.

A port number is stored as two bytes in network byte order. On the wire they read 01 BB. Which port is it?

Network byte order is big-endian: the first byte is the high byte.

0x01BB = 1 × 256 + 187 = 443 (HTTPS). Read little-endian, the same bytes would be 0xBB01 = 47,873, which is why the byte order matters.

An alert names the internal address 10.1.2.3. Which source tells you which device had that address at the time?

Look at the row "Tells you" in the table above.

The DHCP log: it records which MAC address and host name leased which IP address, and when. The DNS log shows what that address asked for, and flows show whom it talked to, but neither ties the address to a device. Static addresses are not in DHCP logs; then you need the asset inventory.