ZERO-CLOUD // 100% LOCAL AIR-GAPPED IN-BROWSER DISSECTOR
PCAP & Frame Forensics Inspector
EVIDENCE PRESET:
THREAT ACTOR:APT29 (Cozy Bear) / UNC4192|TECHNIQUE:T1071.004 - DNS Application Layer Protocol
ACTIVE FILE:
incident_evidence.pcapA compromised engineering workstation (10.0.1.45) queries high-entropy base64 subdomains against an internal DNS resolver (10.0.1.2) to exfiltrate system reconnaissance and receive secondary stager stages without direct outbound TCP/HTTPS.
INVESTIGATION OBJECTIVES:
- What is the average subdomain entropy and length?
- Which rogue apex domain is authoritative for the queries?
- Can you decode the stage fragment hidden within the TXT records?
KEY CORRELATED IOCS:
10.0.1.45 (Compromised Host)198.51.100.88 (External C2 DNS)c2-cdn-edge.cloud
FRAMES: 0 / 0|TOTAL BYTES: 0.0 KB|SPAN: 0.000s
No.
Time (s)
Source
Destination
Protocol
Length
Info
No packets match current filter or capture is empty.
Select a frame from the packet table to inspect protocol layers.
Select a frame to load raw byte stream.