Practical incident response and DFIR guides from the CICADA IR team.
A practical workflow for using PCAP captures to drive an incident response when endpoint telemetry isn't available — what to look for, how to extract IOCs from raw packets, and how to reconstruct an attack chain from the wire.