Skip to content

About

Network forensics investigation of the HawkEye malware campaign using Wireshark, SMTP analysis, threat intelligence, and credential exfiltration analysis.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

10 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

HawkEye Network Forensics Investigation

Overview

This project documents the investigation of the HawkEye malware campaign using network forensic techniques. The analysis was performed on a packet capture (PCAP) file to identify malicious activity, attacker infrastructure, data exfiltration methods, and compromised credentials.

Objectives

  • Analyze network traffic using Wireshark
  • Identify malicious domains and communications
  • Investigate attacker activity
  • Recover exfiltrated information
  • Reconstruct the attack timeline

Tools Used

  • Wireshark
  • CyberChef
  • VirusTotal
  • DNS Lookup Tools

Investigation Process

  1. Packet Capture Analysis
  2. DNS Traffic Investigation
  3. HTTP Traffic Analysis
  4. SMTP Communication Analysis
  5. Threat Intelligence Validation
  6. Credential Recovery
  7. Attack Timeline Reconstruction

Key Findings

  • Identified malicious communication associated with HawkEye malware
  • Detected credential theft and exfiltration activity
  • Recovered attacker-controlled infrastructure information
  • Reconstructed the complete attack lifecycle

Report

The complete investigation report is available in:

  • HawkEye_Report.pdf

Skills Demonstrated

  • Network Forensics
  • Incident Response
  • Threat Intelligence
  • Malware Investigation
  • PCAP Analysis
  • Digital Forensics

About

Network forensics investigation of the HawkEye malware campaign using Wireshark, SMTP analysis, threat intelligence, and credential exfiltration analysis.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors