1 Where network evidence lives
Disk forensics starts with one device. Network forensics starts with a question, and the evidence is spread over many systems. Each saw the same event from a different place and kept a different part of it:
| Source | Tells you | Cannot tell you |
|---|---|---|
| Packet capture (SPAN port, TAP, sensor) | Exact bytes, protocol details, timing, unencrypted content | Anything outside the capture point or time; content inside TLS |
NetFlow / IPFIX / Zeek conn.log | 5-tuple, start, duration, bytes and packets per connection | What was transferred; user names |
| Web proxy | User (if authenticated), URL or host, bytes, user agent | Traffic that bypasses the proxy |
| DNS resolver | Which client asked for which name | Whether a connection followed; names resolved elsewhere |
| DHCP, Wi-Fi controller, asset inventory | Which device had which IP address, where it was attached | Who was holding the device |
| Authentication (Windows, VPN, RADIUS) | Which account logged on where, how, from which address | Who typed the password |
| Badge / physical access | Which card opened which door | Who carried the card |
| Mail server and headers | Sender, recipients, path, times, authentication results | Content once deleted, unless kept |
2 The pages
The byte-level pages have the same interactive hex views as the file-system pages: click a field to see its bytes, click a byte to find its field.
3 Ground rules
- Collect fast. Proxy, DNS and flow logs are often kept for days or weeks only. Secure them before you analyse anything.
- Hash every export when you collect it, and record the system, the time range and who exported it.
- Measure every clock. Note each source's time zone convention and its offset from a reference clock before you compare times across sources.
- Keep the original formats. Convert for analysis, but keep the raw export; your conversions may be wrong.
- Minimise. Logs are full of personal data about uninvolved people. Look only at what the question needs.
4 Warm-up
Two quick checks before you start.
A port number is stored as two bytes in network byte order. On the wire they read 01 BB. Which port is it?
Network byte order is big-endian: the first byte is the high byte.
0x01BB = 1 × 256 + 187 = 443 (HTTPS). Read little-endian, the same bytes would be
0xBB01 = 47,873, which is why the byte order matters.
An alert names the internal address 10.1.2.3. Which source tells you which device had that address at the time?
Look at the row "Tells you" in the table above.
The DHCP log: it records which MAC address and host name leased which IP address, and when. The DNS log shows what that address asked for, and flows show whom it talked to, but neither ties the address to a device. Static addresses are not in DHCP logs; then you need the asset inventory.