performing-network-traffic-analysis-with-tshark
mukul975/Anthropic-Cybersecurity-Skills
Automates deep packet inspection using tshark and pyshark on PCAP files. This tool is designed for cybersecurity professionals to perform structured network forensics, compute protocol distribution, detect suspicious activity (like port scans, beaconing, and data exfiltration), extract critical IOCs (IPs, domains, URLs), and identify advanced threats such as DNS tunneling patterns. Ideal for incident response and security auditing.