Converting PCAP Web Traffic to Apache Log, (Wed, Jun 6th)

PCAP data can be really useful when you must investigate an incident but when the amount of PCAP files to analyse is counted in gigabytes, it may quickly become tricky to handle. Often, the first protocol to be analysed is HTTP because it remains a classic infection or communication vector used by malware. What if you could analyze HTTP connections likeĀ an Apache access log? This kind of log can be easily indexed/processed by many tools.

