12 Days of Defense - Day 9: How to Analyze HTTP Traffic in Wireshark
In this episode I cover one of the most common and fundamental protocols for analysts to understand - HTTP. This protocol is used for everything from early stage delivery and exploitation to command and control and even exfiltration. Every blue team member must know the key fields included in HTTP, how to identify suspicious HTTP content, and how to extract files. This video shows how to read HTTP in Wireshark, examine fields for suspicious content and extract files from a HTTP PCAP. While in this video we focus on HTTP/1, don't miss the following video in this series for an important follow-on discussing the newer and much more complex HTTP/2 and HTTP/3 protocols! === My SANS Courses: SEC450 - Blue Team Fundamentals: https://sans.org/sec450 MGT551 - Building and Leading Security Operations Centers: https://sans.org/mgt551 PDF Guide to Security Operations: https://www.sans.org/security-resourc... Blueprint Podcast: https://sans.org/blueprint-podcast Twitter: / sechubb

12 Days of Defense - Day 10: How to Analyze HTTP/2 Traffic in Wireshark

12 Days of Defense - Day 4: How to Analyze Email Headers and How Spoofed Email Works

Wireshark: What They Don't Teach You

Analyzing HTTP Traffic in Wireshark

Wireshark Basics for IoT Hacking

the true reason C++ always wins

12 Days of Defense - Day 11: Prioritizing Detection with MITRE ATT&CK Navigator

Mastering Wireshark: The Complete Tutorial!

12 Days of Defense - Day 8: How Encrypted SNI works (and How It Will Blind Your Security Team)

A visual guide to Bayesian thinking

Wireshark - Malware traffic Analysis

Why Fighter Jets Ban 90% of C++ Features

12 Days of Defense - Day 1: PDF and Office Doc Malware IOC Extraction

12 Days of Defense - Day 6: How DNS over HTTPS (DoH) Works / DNS Privacy

slink: WAF: Wrong Approach Firewall

Will QUIC Kill TCP? // Wireshark Talk

MALWARE Analysis with Wireshark // TRICKBOT Infection

How Your Phone is Tracked in 2026 – And How to Stop It

Top 5 Wireshark tricks to troubleshoot SLOW networks

