This project demonstrates network traffic analysis using Wireshark to investigate communication patterns, protocol usage, DNS activity, encrypted communications, and TCP connection establishment. The objective was to develop foundational security monitoring skills that are applicable to Security Operations Center (SOC) environments and cloud security operations.
- Wireshark
- Windows
- Kali Linux
- VirtualBox
- Captured 33,542 packets during a 10-minute 47-second session.
- TCP was the most frequently observed protocol.
- Identified 11,818 encrypted packets using TLS and QUIC.
- Observed DNS queries for domains including google.com and alphabot.app.
- Verified successful TCP three-way handshakes.
- Identified VLAN-tagged traffic generated by VirtualBox virtual networking.
For a detailed breakdown of the methodology, protocol analysis, DNS investigation, TLS inspection, TCP handshake verification, and security observations, see the full report:
➡️ Network Traffic Analysis Report
The concepts demonstrated in this project align with cloud security monitoring practices, including traffic visibility, DNS monitoring, encrypted communication analysis, and network investigation techniques used within cloud environments.
Orebiyi Victor
Cybersecurity Student | Cloud Security Enthusiast