traffic-analysis-pcap
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides extensive command-line templates for forensic tools including
tshark,pcapfix,editcap,mergecap,binwalk,foremost, andhashcat. These are standard utilities used for network traffic analysis and file reconstruction. - [EXTERNAL_DOWNLOADS]: The documentation includes instructions for installing the
networkminerforensic tool using the system's package manager (apt). - [DATA_EXFILTRATION]: The playbook contains heuristics and specific filters for detecting data exfiltration and covert channels within network captures, such as identifying unusual ICMP payload sizes and DNS tunneling patterns.
- [CREDENTIALS_UNSAFE]: The skill describes methodologies for identifying and extracting plaintext credentials from unencrypted protocols (FTP, HTTP Basic Auth, SMTP) as part of a legitimate forensic investigation process.
Audit Metadata