QuestionQ10
Forensics Techniques
Refer to the exhibit. A network engineer is reviewing a Wireshark capture to identify the HTTP request that triggered download of the initial Ursnif banking Trojan binary. Which filter did the engineer use to sort the Wireshark traffic logs?
- A http.request.un matches
- B tls.handshake.type ==1
- C tcp.port eq 25
- D tcp.window_size ==0
Community Discussion