- Posted on
- Featured Image
Turn multi‑GB pcaps from overwhelm to insight by pairing Wireshark/TShark with a lightweight Isolation Forest in Bash: export packet fields to CSV, aggregate 5‑tuple flows, score anomalies (pps/bps/bytes/duration), then pivot back with precise filters in Wireshark. The guide includes apt/dnf/zypper installs, a Python venv, ready-to-run scripts, real-world pivots, and tuning tips to automate fast triage.