This project documents the investigation of the HawkEye malware campaign using network forensic techniques. The analysis was performed on a packet capture (PCAP) file to identify malicious activity, attacker infrastructure, data exfiltration methods, and compromised credentials.
- Analyze network traffic using Wireshark
- Identify malicious domains and communications
- Investigate attacker activity
- Recover exfiltrated information
- Reconstruct the attack timeline
- Wireshark
- CyberChef
- VirusTotal
- DNS Lookup Tools
- Packet Capture Analysis
- DNS Traffic Investigation
- HTTP Traffic Analysis
- SMTP Communication Analysis
- Threat Intelligence Validation
- Credential Recovery
- Attack Timeline Reconstruction
- Identified malicious communication associated with HawkEye malware
- Detected credential theft and exfiltration activity
- Recovered attacker-controlled infrastructure information
- Reconstructed the complete attack lifecycle
The complete investigation report is available in:
- HawkEye_Report.pdf
- Network Forensics
- Incident Response
- Threat Intelligence
- Malware Investigation
- PCAP Analysis
- Digital Forensics