competition-pcap-protocol
zhaoxuya520/reverse-skill
This specialized skill automates advanced forensic network analysis on captured packet data (PCAP). It is designed for reconstructing complex network sessions (TCP/UDP), decoding obscure or custom protocols (e.g., C2, custom binary), and correlating packet sequences with host or malware behavior. Use when evidence is embedded in protocol framing, timing, or session state, requiring reassembly beyond simple packet inspection.