Firefox ๋ธŒ๋ผ์šฐ์ € ๋ถ€๊ฐ€ ๊ธฐ๋Šฅ
  • ํ™•์žฅ ๊ธฐ๋Šฅ
  • ํ…Œ๋งˆ
    • Firefox์šฉ
    • ์‚ฌ์ „ ๋ฐ ์–ธ์–ด ํŒฉ
    • ๋‹ค๋ฅธ ๋ธŒ๋ผ์šฐ์ € ์‚ฌ์ดํŠธ
    • Android ๋ถ€๊ฐ€ ๊ธฐ๋Šฅ
๋กœ๊ทธ์ธ
Wireshark Network Threat Forensics ๋ฏธ๋ฆฌ๋ณด๊ธฐ

Wireshark Network Threat Forensics ์ œ์ž‘์ž: Libor Benes (Dr. B)

3,100 Wireshark display filters for threat hunting, malware C2/beaconing detection, intrusion analysis, exfiltration, lateral movement, credential abuse, and network forensics. โ€ข Real-time search. โ€ข Fully offline. No Data Collection.

0 (๋ฆฌ๋ทฐ 0๊ฐœ)0 (๋ฆฌ๋ทฐ 0๊ฐœ)
Firefox๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ํ™•์žฅ ๊ธฐ๋Šฅ์„ ๋ฐ›์œผ์„ธ์š”
ํŒŒ์ผ ๋‹ค์šด๋กœ๋“œ

ํ™•์žฅ ๋ฉ”ํƒ€ ๋ฐ์ดํ„ฐ

์ •๋ณด
Wireshark Network Threat Forensics is a security-first, offline Firefox sidebar extension that delivers instant, searchable access to 3,100 carefully curated Wireshark display filters โ€” a unique (albeit logically non-exhaustive) collection focused on real-world network threat detection and digital forensics.

With the signature, hallmark architecture prioritizing the security-first approach, all processing and data are client-side โ€” no telemetry, no network requests, no data collection.

During incident response, malware analysis, threat hunting, red-team/blue-team exercises, and forensic investigations, security professionals need rapid access to proven display filters capable of identifying command-and-control (C2) beaconing, data exfiltration, lateral movement, credential harvesting, ransomware precursors, port scans, MITM attempts, protocol abuse, and many other malicious behaviors.

This extension provides exactly that โ€” a comprehensive, categorized reference of the most effective and up-to-date display filters, drawn from official Wireshark documentation, public cheat sheets, SANS posters, malware traffic analysis reports (Unit 42, Mandiant, Black Hills, etc.), and current 2025โ€“2026 threat intelligence observations.

Purpose:
Rapid, searchable reference for Wireshark display filters โ€” ideal for real-time packet analysis, threat hunting, incident response, malware traffic analysis, red-team/blue-team exercises, and forensic investigations.

About Wireshark:
Wireshark, originally authored as Ethereal in 1998 by Gerald Combs (a computer science graduate of the University of Missouriโ€“Kansas City), is the world's leading open-source network protocol analyzer. It supports two distinct types of filters:
โ€ข Capture filters โ€” applied during live capture using BPF syntax (e.g. tcp port 80), used to reduce the volume of recorded traffic.
โ€ข Display filters โ€” applied after capture to filter, highlight, and analyze already-recorded packets using Wireshark's own powerful expression language (e.g. http.request.method == "POST" && http.request.uri contains "login").

This extension contains exclusively display filters โ€” the far more expressive, flexible, and forensics-oriented type used for deep inspection of PCAP files or live sessions. It does not include capture filters, which are simpler and far less numerous.

Target Audience:
โ€ข Network Security Analysts & Threat Hunters.
โ€ข Incident Responders & DFIR Practitioners.
โ€ข Malware Reverse Engineers.
โ€ข Red Team / Penetration Testers.
โ€ข Blue Team / SOC Analysts.
โ€ข Forensic Investigators.
โ€ข Bug Bounty Hunters.
โ€ข Students & Educators in network security.

Key Categories Include:
โ€ข Frame & General
โ€ข Ethernet / Link Layer
โ€ข IP / ICMP / ICMPv6
โ€ข TCP Basics & Flags
โ€ข TCP Analysis & Errors
โ€ข UDP
โ€ข DNS (tunneling, DGA, exfil)
โ€ข HTTP / HTTPS / TLS (client hints, weak ciphers, downgrade)
โ€ข Suspicious / Security / Anomalies (scans, MITM, DoS)
โ€ข Malware / C2 / Beaconing Indicators
โ€ข Wireless / Wi-Fi / 802.11 (deauth, PMKID, evil twin)
โ€ข SMB / Windows Protocols (NTLM, PsExec, WMI)
โ€ข Email / SMTP / IMAP / POP (phishing, credential leaks)
โ€ข VoIP / RTP / SIP (toll fraud, call spam)
โ€ข Miscellaneous / Expert / Custom (rare patterns, high-entropy, shellcode).

Features:
โ€ข Real-time dynamic smart search across category, title, filter expression, and description.
โ€ข Click-to-copy display filter string with "Copied!" visual feedback.
โ€ข Syntax-highlighted filters (monospace) + highlighted search terms (<mark>).
โ€ข Terminal-inspired design.
โ€ข Fully offline โ€” no network requests, no data collection.
โ€ข Compact with instant performance even on 3,100 entries.

Security & Privacy:
โ€ข Only one permission: clipboardWrite (required for copy-to-clipboard).
โ€ข Zero data collection โ€” explicitly declared in manifest.json.
โ€ข No external requests, no analytics, no telemetry.
โ€ข No third-party libraries โ€” 100% first-party code.
โ€ข Manifest v2 compliant with Mozilla review standards.

Technical Specifications:
โ€ข Compatibility: Firefox 109.0+ (64-bit desktop).
โ€ข Size: ~532 KB total (minimal memory footprint).
โ€ข Performance: Instant filtering on 3,100 entries.
โ€ข Tested on: Firefox 147.0.3 (February 2026).

Wireshark Network Threat Forensics brings a unique, powerful, comprehensive, security-first collection of display filters directly into your Firefox sidebar โ€” ready for immediate use in threat hunting and forensic workflows, with complete offline privacy protection.

Happy network threat hunting โ€” stay safe, stay offline.
0๋ช…์ด 0์ ์œผ๋กœ ํ‰๊ฐ€ํ•จ
๋กœ๊ทธ์ธํ•˜์—ฌ ์ด ํ™•์žฅ ๊ธฐ๋Šฅ์˜ ํ‰์ ์„ ๋‚จ๊ฒจ์ฃผ์„ธ์š”
์•„์ง ํ‰์ ์ด ์—†์Šต๋‹ˆ๋‹ค

๋ณ„์  ์ €์žฅ๋จ

5
0
4
0
3
0
2
0
1
0
์•„์ง ๋ฆฌ๋ทฐ ์—†์Œ
๊ถŒํ•œ ๋ฐ ๋ฐ์ดํ„ฐ

ํ•„์ˆ˜ ๊ถŒํ•œ:

  • ํด๋ฆฝ๋ณด๋“œ์— ๋ฐ์ดํ„ฐ ๋„ฃ๊ธฐ

๋ฐ์ดํ„ฐ ์ˆ˜์ง‘:

  • ๊ฐœ๋ฐœ์ž๊ฐ€ ์ด ํ™•์žฅ ๊ธฐ๋Šฅ์€ ๋ฐ์ดํ„ฐ ์ˆ˜์ง‘์ด ํ•„์š”ํ•˜์ง€ ์•Š๋‹ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค.
๋” ์•Œ์•„๋ณด๊ธฐ
์ถ”๊ฐ€ ์ •๋ณด
๋ถ€๊ฐ€ ๊ธฐ๋Šฅ ๋งํฌ
  • ์ง€์› ์‚ฌ์ดํŠธ
  • ์ง€์› ์ด๋ฉ”์ผ
๋ฒ„์ „
1.0
ํฌ๊ธฐ
150.99 KB
๋งˆ์ง€๋ง‰ ์—…๋ฐ์ดํŠธ
16์ผ ์ „ (2026๋…„ 2์›” 15์ผ)
๊ด€๋ จ ์นดํ…Œ๊ณ ๋ฆฌ
  • ์›น ๊ฐœ๋ฐœ ๋„๊ตฌ
  • ๊ฐœ์ธ ์ •๋ณด ๋ณดํ˜ธ ๋ฐ ๋ณด์•ˆ
  • ๊ฒ€์ƒ‰ ๋„๊ตฌ
๋ผ์ด์„ ์Šค
Mozilla Public License 2.0
๋ฒ„์ „ ๋ชฉ๋ก
  • ๋ชจ๋“  ๋ฒ„์ „ ๋ณด๊ธฐ
๋ชจ์Œ์ง‘์— ์ถ”๊ฐ€
์ด ๋ถ€๊ฐ€ ๊ธฐ๋Šฅ ์‹ ๊ณ 
Mozilla ํ™ˆํŽ˜์ด์ง€๋กœ ์ด๋™

๋ถ€๊ฐ€ ๊ธฐ๋Šฅ

  • ์†Œ๊ฐœ
  • Firefox ๋ถ€๊ฐ€ ๊ธฐ๋Šฅ ๋ธ”๋กœ๊ทธ
  • ํ™•์žฅ ๊ธฐ๋Šฅ ์›Œํฌ์ƒต
  • ๊ฐœ๋ฐœ์ž ํ—ˆ๋ธŒ
  • ๊ฐœ๋ฐœ์ž ์ •์ฑ…
  • ์ปค๋ฎค๋‹ˆํ‹ฐ ๋ธ”๋กœ๊ทธ
  • ํฌ๋Ÿผ
  • ๋ฒ„๊ทธ ์‹ ๊ณ 
  • ๋ฆฌ๋ทฐ ์ง€์นจ

๋ธŒ๋ผ์šฐ์ €

  • Desktop
  • Mobile
  • Enterprise

์ œํ’ˆ

  • Browsers
  • VPN
  • Relay
  • Monitor
  • Pocket
  • Bluesky (@firefox.com)
  • Instagram (Firefox)
  • YouTube (firefoxchannel)
  • ๊ฐœ์ธ ์ •๋ณด
  • ์ฟ ํ‚ค
  • ๋ฒ•๋ฅ 

ํŠน๋ณ„ํ•œ ๊ณ ์ง€๊ฐ€ ์—†๋Š” ํ•œ, ๋ณธ ์‚ฌ์ดํŠธ์˜ ์ฝ˜ํ…์ธ ๋Š” Commons Attribution Share-Alike License v3.0 ๋˜๋Š” ๊ทธ ์ดํ›„ ๋ฒ„์ „์— ๋”ฐ๋ผ ์‚ฌ์šฉ์ด ํ—ˆ๊ฐ€๋ฉ๋‹ˆ๋‹ค.