[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/using-wireshark-display-filter-expressions/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/ "Learning Hub")
* [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/ "Cybersecurity Tutorials")  
  [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)

# Wireshark Tutorial: Display Filter Expressions

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 12 min read  
Related Products  
[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Brad Duncan](https://unit42.paloaltonetworks.com/author/brad-duncan/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 8, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Cybersecurity Tutorials](https://unit42.paloaltonetworks.com/category/cybersecurity-tutorials/)
  * [Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/)
  * [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/)
  * [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/?pdf=download&lg=en&_wpnonce=5f0cc26d8b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/using-wireshark-display-filter-expressions/?pdf=print&lg=en&_wpnonce=5f0cc26d8b "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Wireshark%20Tutorial:%20Display%20Filter%20Expressions&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fusing-wireshark-display-filter-expressions%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fusing-wireshark-display-filter-expressions%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fusing-wireshark-display-filter-expressions%2F&title=Wireshark%20Tutorial:%20Display%20Filter%20Expressions "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fusing-wireshark-display-filter-expressions%2F&text=Wireshark%20Tutorial:%20Display%20Filter%20Expressions "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fusing-wireshark-display-filter-expressions%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Wireshark%20Tutorial:%20Display%20Filter%20Expressions%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fusing-wireshark-display-filter-expressions%2F "Share in Mastodon")

## Executive Summary

Security professionals occasionally use Wireshark to review packet captures (pcaps) of malware-generated network traffic. To more efficiently review this type of activity, we suggest users customize their Wireshark installation.

In [our previous tutorial](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/), we customized Wireshark's column display. This tutorial introduces display filter expressions useful to review pcaps of malicious network traffic from infected Windows hosts.

This blog is the second in [a series of Wireshark tutorials](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/) that provide customization options helpful for investigating malicious network traffic. It was first published in January 2019 and has been updated for 2023.

The pcaps in this tutorial contain traffic generated by Windows-based malware. Palo Alto Networks customers receive protection from these threats through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions) that include [WildFire](https://www.paloaltonetworks.com/network-security/wildfire) and [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention).

| **Related Unit 42 Topics** | [**pcap**](https://unit42.paloaltonetworks.com/tag/pcap/)**,** [**Wireshark**](https://unit42.paloaltonetworks.com/tag/wireshark/)**,** [**Wireshark Tutorial**](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/) |
|----------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## Requirements and Supporting Material

This tutorial requires readers to have reviewed and understand [our previous Wireshark tutorial](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/). Requirements also include using a recent version of Wireshark, at least version 3.6.2 or later. This tutorial uses Wireshark version 4.0.7 with a customized column display from the previous tutorial. As always, we recommend using the most recent version of Wireshark available for your environment.

Our requirements also include a basic knowledge of network traffic. Part of this knowledge is understanding the [three-way handshake](https://www.akamai.com/blog/security/tcp-three-way-handshake) used for TCP connections. Furthermore, some of the pcaps for this tutorial contain malicious content from Windows-based infections, so we recommend using Wireshark in a non-Windows environment like BSD, Linux or macOS.

The five pcap files used in this tutorial are contained in a password-protected ZIP archive hosted at our [GitHub repository](https://github.com/PaloAltoNetworks/Unit42-Wireshark-tutorials/blob/main/Wireshark-tutorial-filter-expressions-5-pcaps.zip). Download the ZIP file named Wireshark-tutorial-filter-expressions-5-pcaps.zip. Use *infected* as the password to extract the pcap files, as shown below in Figure 1.
![Image 1 is a screenshot of the Palo Alto Networks Unit 42 Wireshark tutorials GitHub. A black arrow indicates to hit the download button on the page. A second black arrow points to the “password required” popup after selecting the zip file in the downloads folder. The password is entered. A final black arrow points to the contents of the zip file.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-1.jpeg) Figure 1. Acquiring pcap files for this tutorial.

The five extracted pcap files for this tutorial are:

* Wireshark-tutorial-filter-expressions-1-of-5.pcap
* Wireshark-tutorial-filter-expressions-2-of-5.pcap
* Wireshark-tutorial-filter-expressions-3-of-5.pcap
* Wireshark-tutorial-filter-expressions-4-of-5.pcap
* Wireshark-tutorial-filter-expressions-5-of-5.pcap

Before continuing, we should ensure we are using a personal Wireshark profile, not the default.

## Profile Check

During this tutorial, we save Wireshark filter expressions as filter buttons. Like the column changes from [our previous tutorial](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/), filter buttons will also be saved to your current Wireshark profile. The name of the personal profile from our previous tutorial is "Customized."

To ensure you are using a personal profile, check the right side of the status bar, which shows the name of your current profile. You can also select "Configuration Profiles..." under the Edit menu to verify. Both options are shown below in Figure 2, revealing the customized profile name from our previous tutorial.
![Image 2 is a Wireshark screenshot. Configuration profiles has been selected in the edit menu from the main menu. A popup window of the configuration profiles is inset in the screenshot. A red arrow indicates the customized profile is selected. A second red arrow indicates the bottom of the pane that shows the profile is customized.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-2.jpeg) Figure 2. Checking your current configuration profile in Wireshark.

After confirming use of a personal profile, we can examine the Wireshark display filter.

## The Wireshark Display Filter

In Wireshark's default configuration, the display filter is a bar located immediately above the column display. This is where we type expressions to filter our view of Ethernet frames, IP packets or TCP segments from a pcap. When typing in the display filter bar, Wireshark offers a list of suggestions based on the typed text, as shown below in Figure 3.
![Image 3 is a Wireshark screenshot displaying many filters. These are suggested based on what is typed into the filter menu.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-3.jpeg) Figure 3. Wireshark's display filter offers suggestions based on what you type.

As long as the display filter bar remains red, the expression will not be accepted. Note the filter bar's red color in Figure 3.

Open our first pcap named Wireshark-tutorial-filter-expressions-1-of-5.pcap in Wireshark. Type http.request in the display filter and hit Enter. If the filter bar is green, the expression has been accepted, and it should work properly, as shown below in Figure 4.
![Image 4 is a Wireshark screenshot. The filter displayed is http.request.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-4.jpeg) Figure 4. Wireshark's display filter accepts an expression, and it works as intended.

If the filter bar turns yellow, the expression is accepted, but it may not work as intended. Yellow filter bar results are more common in earlier versions of Wireshark. For example, Figure 5 shows the filter expression dns \&\& ip.addr || http.request using Wireshark version 3.6.2. This produces a yellow result in the filter bar, with a suggested solution at the bottom in the status bar.
![Image 5 is a Wireshark screenshot. A red rectangle and a red arrow indicate it's a bad filter expression. Suggest parentheses around ‘\&\&’ within ‘||’. The inputted filter is yellow instead of green.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-5.jpeg) Figure 5. Bad filter expression for our first pcap in Wireshark version 3.6.2.

The results in Figure 5 reveal no HTTP request lines among the results in our column display. But using the same filter on the same pcap with Wireshark version 4.0.7 provides a green result and displays HTTP request lines, as shown below in Figure 6.
![Image 6 is a Wireshark screenshot. The corrected filter is green. There is no suggestion to correct the filter language.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-6.jpeg) Figure 6. The same filter expression for our first pcap is green in Wireshark version 4.0.7.

This illustrates one of the differences between Wireshark's version 3 series and version 4. As stated earlier, we recommend using the latest version of Wireshark available for your system.

Wireshark's display filter uses [Boolean expressions](https://en.wikipedia.org/wiki/Boolean_expression), so we can specify values and chain them together. Below, Table 1 lists common Boolean operators used in Wireshark filter expressions.

|----------------------|----------------|--------------------------|
| **Boolean Operator** | **Expression** | **Alternate Expression** |
| Equals               | ==             | eq                       |
| Not                  | !              | not                      |
| And                  | \&\&           | and                      |
| Or                   | ||           | or                       |

*Table 1. Boolean functions used in Wireshark display filter expressions.*

Random examples of Wireshark display filter expressions include:

* ip.addr eq 10.8.15\[.\]1 and dns.qry.name.len \> 36
* http.request \&\& ip.addr == 10.8.15\[.\]101
* http.request || http.response
* dns.qry.name contains microsoft or icmp

## Filtering for **Web Traffic**

Our [previous Wireshark tutorial](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/) used the following filter for web traffic:

http.request or tls.handshake.type eq 1

The expression http.request reveals URLs for HTTP requests, and tls.handshake.type eq 1 shows domain names used in HTTPS or SSL/TLS traffic.

For web traffic generated by Windows hosts, results from this filter include HTTP requests over UDP port 1900. This HTTP traffic is [Simple Service Discovery Protocol (SSDP)](https://en.wikipedia.org/wiki/Simple_Service_Discovery_Protocol). SSDP is used to discover plug-and-play devices and is not associated with normal web traffic. We can exclude SSDP traffic in our results by modifying our filter expression to:

(http.request or tls.handshake.type eq 1) and !(ssdp)

While parentheses in the above filter expression are not required in Wireshark version 4, we suggest including them to ensure filter expression compatibility with older versions of Wireshark. Use this filter on our first pcap, Wireshark-tutorial-filter-expressions-1-of-5.pcap and the results should appear similar to Figure 7.
![Image 7 is a screenshot of a basic web filter used in Wireshark to examine traffic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-7.jpeg) Figure 7. Using the basic web filter in our first pcap.

Reviewing the traffic shown in Figure 7 reveals several lines of unencrypted HTTP POST requests associated with [Loki Bot malware](https://malpedia.caad.fkie.fraunhofer.de/details/win.lokipws) to the URL hxxp://194.55.224\[.\]9/liuz/five/fre.php, which was [reported to Threatfox](https://threatfox.abuse.ch/ioc/1149105/) in August 2023.

To examine the traffic, click on any of the lines for traffic to 194.55.224\[.\]9 to select the frame, then right-click to bring up a menu. From the menu, select "Follow" then "TCP Stream" or "HTTP Stream," as shown below in Figure 8.
![Image 8 is a Wireshark screenshot demonstrating how to follow a TCP stream. A black arrow indicates to click on a row within the traffic. The popup menu has “Follow” selected, and from a submenu, “TCP Stream” is selected.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-8.jpeg) Figure 8. Following a TCP stream in Wireshark.

This will bring up a new window, and we can review an ASCII representation of the content of this unencrypted HTTP traffic. Review this on your own to become familiar with Loki Bot command and control (C2) traffic.

Open our second pcap Wireshark-tutorial-filter-expressions-2-of-5.pcap in Wireshark. This is traffic from a [standard variant IcedID (Bokbot)](https://www.proofpoint.com/us/blog/threat-insight/fork-ice-new-era-icedid) infection. It contains HTTP traffic to vrondafarih\[.\]com and HTTPS traffic to both magiketchinn\[.\]com and magizanqomo\[.\]com. All three were [identified as IcedID-related domains in July 2023](https://threatfox.abuse.ch/browse.php?search=malware%3Aicedid).

Figure 9 shows these IcedID-associated domains in our second pcap using the basic web filter in Wireshark.
![Image 9 is a Wireshark screenshot. Red arrows pointing to the rows of traffic indicate the domains associated with an IcedID infection.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-9.jpeg) Image 9 is a Wireshark screenshot. Red arrows pointing to the rows of traffic indicate the domains associated with an IcedID infection.

## Creating Filter Buttons

Complex filter expressions are very tedious to type in Wireshark's filter bar every time you need them. Fortunately, we can save any of our typed expressions as filter buttons.

On the right side of the Wireshark filter bar is a plus sign to add a filter button. Ensure we are still using the basic web filter shown in Figures 7, 8 and 9. After ensuring this filter has been implemented, click on the plus sign as shown below in Figure 10.
![Image 10 is a Wireshark screenshot. A red rectangle indicates how to add a filter button after clicking the +. The options are Filter Button Preferences, Label, Filter, and Comment. Then the user can Cancel or hit OK.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-10.jpeg) Figure 10. Clicking the plus sign to add a filter button.

Clicking the plus sign generates a temporary panel immediately under the filter bar, as noted above in Figure 10. This panel has three fields: Label, Filter and Comment. The Filter field should contain the expression already implemented in the filter bar. Since this is our basic web filter, type basic in the Label field and click the OK button as shown below in Figure 11.
![Image 11 is a Wireshark screenshot where a basic filter is being created. A black arrow indicates the label is “basic.” A second black arrow indicates to hit the OK button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-11.jpeg) Figure 11. Creating our basic web filter button.

This should create a button to the right of Wireshark's filter bar labeled "basic" as shown below in Figure 12. Wireshark filter buttons have no borders and look like labels, but they function as buttons. Anytime you need this basic web filter, just left-click on it.
![Image 12 is a zoomed-in Wireshark screenshot. A black arrow points to the basic filter button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-12.jpeg) Figure 12. The button for our basic web filter.

For this tutorial, we should create the following filter buttons listed below in Table 2.

|------------------|-------------------------------------------------------------------------------------------------------------------|
| **Button Label** | **Filter Expression**                                                                                             |
| basic            | basic (http.request or tls.handshake.type eq 1) and !(ssdp)                                                       |
| basic+           | basic (http.request or tls.handshake.type eq 1 or (tcp.flags.syn eq 1 and tcp.flags.ack eq 0)) and !(ssdp)        |
| basic+dns        | basic (http.request or tls.handshake.type eq 1 or (tcp.flags.syn eq 1 and tcp.flags.ack eq 0) or dns) and !(ssdp) |

*Table 2. Filter buttons to more fully investigate malicious web traffic.*

When examining suspicious traffic in Wireshark, we should use a progressive method. Start simple with our basic web filter, then check for other non-web traffic using the "basic+" filter.

In Table 2, the "basic+" filter expression displays the same information as our "basic" filter, but it includes TCP segments with the SYN flag and not the ACK flag by adding or (tcp.flags.syn eq 1 and tcp.flags.ack eq 0). This displays TCP SYN segments that reveal the start of a TCP stream. With this filter, we can find non-web traffic in a pcap.

The "basic+" filter also reveals any TCP connection attempts that failed. Depending on the IP address, repeated and failed TCP connection attempts could indicate a C2 server that was off-line when the pcap was recorded.

After checking the "basic+" filter, we should review the "basic+dns" filter to check for any notable DNS activity.

In Table 2, the "basic+dns" filter expression shows the same data as our "basic+" filter, but it includes or dns. This filter reveals any DNS queries in the pcap. It is very helpful for determining domain names associated with non-web traffic.

Furthermore, if a malware sample's C2 server is offline when the pcap was recorded, this filter could reveal one or more C2 domains associated with any failed connection attempts. Finally, this filter might reveal examples of [DNS tunneling](https://www.paloaltonetworks.com/cyberpedia/what-is-dns-tunneling).

Add the "basic+" and "basic+dns" filters as shown below in Figure 13 and Figure 14. After adding the filter buttons, we should see all three to the right of Wireshark's filter bar as shown below in Figure 15.
![Image 13 is a Wireshark screenshot. Black arrows indicate create a “basic-plus” filter. The options are Filter Button Preferences, Label, Filter, and Comment. Then the user can Cancel or hit OK. The label entered is “basic+.”](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-13.jpeg) Figure 13. Creating the "basic+" filter button. ![Image 14 is a Wireshark screenshot. Black arrows indicate create a “basic-plus-dns” filter. The options are Filter Button Preferences, Label, Filter, and Comment. Then the user can Cancel or hit OK. The label entered is “basic+dns.” Entered into the filter is gs.ack eq 0) or dns) and !(ssdp).](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-14.jpeg) Figure 14. Creating the "basic+dns" filter button. ![Image 15 is a zoomed-in Wireshark screenshot. The new filter buttons are displayed in a row: basic, basic+ and basic+dns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-15.jpeg) Figure 15. Our newly created filter buttons beside the Wireshark filter bar.

With our three newly created filter buttons in place, we can explore other types of malicious traffic.

## Filtering for Non-Web Traffic

Open our third pcap Wireshark-tutorial-filter-expressions-3-of-5.pcap in Wireshark. This pcap contains post-infection traffic generated by a Remote Access Tool (RAT) malware called [Ave Maria RAT (also known as Warzone RAT)](https://malpedia.caad.fkie.fraunhofer.de/details/win.ave_maria).

Using our basic web filter, nothing obvious stands out in the traffic. However, by using our "basic+dns" web filter and scrolling through the results, we can see things more clearly. We can find a DNS query for adaisreal.ddns\[.\]net that resolves to 87.121.221\[.\]212, then a TCP segment to that IP address with the SYN flag over TCP port 7888, as shown below in Figure 16.
![Image 16 is a Wireshark screenshot. The filter used is the basic+dns filter. a black rectangle indicates the standard query used and the standard query response. The standard query is 0xdab7 A adaisreal dot ddns dot net. The standard query response is 0xdab7 A adaisreal dot ddns dot net A 87 dot 121 dot 221 dot 212. The SYN flag is also indicated.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-16.jpeg) Figure 16. Ave Maria RAT C2 traffic found in our third pcap.

This is just one example, but different RATs and other types of malware also generate similar types of non-web traffic. Our "basic+dns" filter provides a way to search for malicious non-web activity.

## Filtering for FTP Traffic

Some infection traffic uses common protocols that Wireshark can easily decode. Our fourth pcap Wireshark-tutorial-filter-expressions-4-of-5.pcap contains post-infection activity caused by a [malware executable that generates FTP traffic](https://bazaar.abuse.ch/sample/adfa401cdfaac06df0e529bc9d54b74cea9a28d4266a49edafa5b8e04e3b3594/). Our "basic+dns" filter reveals traffic over TCP port 21 and another TCP port after a DNS query to valvulasthermovalve\[.\]cl as shown below in Figure 17.
![Image 17 is a Wireshark screenshot. The filter used is the basic+dns filter. a black rectangle indicates the standard query used and the standard query response. The standard query is 0x583f A valvulasthermovalve dot cl. The standard query response is 0x583f A valvulasthermovalve dot cl A 190 dot 107 dot 177 dot 239. The SYN flag is also indicated.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-17.jpeg) Figure 17. Finding FTP traffic from our fourth pcap.

In Figure 17, we can also see HTTPS traffic to api.ipify\[.\]org immediately before the FTP activity. While this domain is not inherently malicious, malware often uses the service to check the IP address of an infected host.

Our "basic+dns" filter can help find unencrypted FTP traffic, but other filter expressions would better fit an FTP search. Two basic Wireshark filters for unencrypted FTP traffic are shown below in Table 3.

|-----------------------|-------------------------------------------------------|
| **Filter Expression** | **Description**                                       |
| ftp                   | FTP activity in the control channel (TCP port 21)     |
| ftp-data              | FTP activity in the data channel (ephemeral TCP port) |

*Table 3. Basic FTP searches for Wireshark.*

A general-purpose filter expression to review unencrypted FTP activity is:

ftp.request.command or (ftp-data and tcp.seq eq 1)

Type the above expression into Wireshark's display filter bar and hit enter. The results should look similar to the screenshot in Figure 18.
![Image 18 is a Wireshark screenshot. The filter used, ftp.request.command or (ftp-data and tcp.seq eq 1), allows the end user to see the flow of FTP activity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-18.jpeg) Figure 18. Filtering to see the flow of FTP activity in Wireshark.

Figure 18 shows the username and password for this compromised FTP site, then a STOR command to send an HTML file to the FTP server. This represents stolen data being exfiltrated from the infected Windows host. We can follow the TCP streams to review the FTP commands and examine the stolen data. If needed, you can save this filter expression as a filter button for future use.

## Filtering for Email (Spambot) Traffic

In addition to FTP, malware can use other common protocols for malicious traffic. Spambot malware can turn an infected host into a spambot designed to constantly send email messages. This is characterized by a large amount of DNS requests to various mail servers followed by SMTP traffic on TCP ports 25, 465, 587 and other ports less-commonly associated with SMTP traffic.

Our fifth pcap, Wireshark-tutorial-filter-expressions-5-of-5.pcap, contains post-infection spambot traffic. Open that pcap and type the following expression into Wireshark's filter bar:

smtp or dns

The results should look similar to Figure 19.
![Image 19 is a Wireshark screenshot. Using the filter smtp or dns, the end user can review spambot activity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-19.jpeg) Figure 19. Quick review of spambot activity in our fifth pcap.

If you scroll through the results, you should find several DNS queries for various mail server domains and different SMTP statements on the far right under the "Info" column.

Now type the following filter into the filter bar:

smtp.req.command

The results shown below in Figure 20 reveal the infected host contacted several different IP addresses for mail servers in a relatively short amount of time. Note how most of these SMTP requests state STARTTLS, which establishes an encrypted tunnel after the initial SMTP connection. Most email traffic is encrypted, and most spambot activity is also encrypted.
![Image 20 is a Wireshark screenshot of the traffic displayed when the filter smtp.req.command is used.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-20.jpeg) Figure 20. Filtering on smtp.req.command in our fifth pcap.

However, spambot traffic might have unencrypted email messages we can review. To find these messages, type the following expression in Wireshark's filter bar:

smtp.data.fragment

This should reveal seven results in the column display as shown below in Figure 21. We can follow the TCP stream for any of these to further investigate these messages.
![Image 21 is a Wireshark screenshot of the traffic displayed when the filter smtp.req.command is used.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/09/word-image-129854-21.jpeg) Figure 21. Filtering for emails sent over unencrypted spambot traffic.

While not extensive, these are the most common filter expressions useful for examining spambot traffic.

## Conclusion

Wireshark display filter expressions are necessary to understand the contents of a pcap. When combined with an optimized column display, effective filters can immensely help security professionals investigate suspicious network activity.

Our [next tutorial in this series](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/) reviews how to identify hosts and users when investigating suspicious network activity.

Pcaps used in this tutorial contain traffic generated by Windows-based malware. Palo Alto Networks customers receive protection from these threats through [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and our [Next-Generation Firewall](https://www.paloaltonetworks.com/network-security/next-generation-firewall) with [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions) that include [WildFire](https://www.paloaltonetworks.com/network-security/wildfire), [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention) and [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering).

If you think you might have been compromised or have an urgent matter, contact the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Indicators of Compromise

The following are indicators of malicious activity from the pcaps used in this tutorial.

|--------------------------------------------|-------------------------------------------------------------------------------------------------------------------|
| **URL**                                    | hxxp://194.55.224\[.\]9/liuz/five/fre.php                                                                         |
| **Description**                            | Loki Bot C2 URL noted as early as 2023-08-15                                                                      |
| **IcedID C2 domains noted on 2023-07-27:** | \* vrondafarih\[.\]com - HTTP traffic \* magiketchinn\[.\]com - HTTPS traffic \* magizanqomo\[.\]com - HTTPS traffic |

|----------------------|------------------------------------------------------------------------|
| **URL**              | 87.121.221\[.\]212:7888 - tcp://adaisreal.ddns\[.\]net:7888/           |
| **Description**      | C2 for Ave Maria RAT (Warzone RAT) noted as early as 2023-06-05        |
| **SHA256 hash**      | adfa401cdfaac06df0e529bc9d54b74cea9a28d4266a49edafa5b8e04e3b3594       |
| **File size**        | 604,672 bytes                                                          |
| **Filename**         | unknown                                                                |
| **File description** | Windows executable (EXE), info stealer using FTP for data exfiltration |

|----------------------|-------------------------------------------------------------------------------------------------------------------------------|
| **URL**              | 190.107.177\[.\]239:21 - fxp://valvulasthermovalve\[.\]cl/                                                                    |
| **Description**      | Noted as early as 2023-06-07, FTP server on legitimate site used for data exfiltration, also used by the above malware sample |
| **SHA256 hash**      | f24259e65a935722c36ab36f6e4429a1d0f04c0ac3600e4286cc717acc5b03d7                                                              |
| **File size**        | 134,140 bytes                                                                                                                 |
| **Filename**         | Details-3922941.one                                                                                                           |
| **File description** | OneNote file as an attachment in unencrypted spambot emails for Emotet on 2023-03-16                                          |

## Additional Resources

* * [Wireshark Tutorial: Changing Your Column Display](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/) - Unit 42, Palo Alto Networks
  * [Wireshark Tutorial: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/) - Unit 42, Palo Alto Networks
  * [Wireshark Tutorial: Exporting Objects from a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/) - Unit 42, Palo Alto Networks
  * [Wireshark Tutorial: Decrypting HTTPS Traffic](https://unit42.paloaltonetworks.com/wireshark-tutorial-decrypting-https-traffic/) - Unit 42, Palo Alto Networks
  * [Wireshark Tutorial: Wireshark Workshop Videos Now Available](https://unit42.paloaltonetworks.com/wireshark-workshop-videos/) - Unit 42, Palo Alto Networks
  * [Full list of Wireshark Tutorials and Quizzes](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/) - Unit 42, Palo Alto Networks
    Back to top

### Tags

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")
* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")
* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: RedLine Stealer: Answers to Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/ "RedLine Stealer: Answers to Unit 42 Wireshark Quiz")

### Table of Contents

* 

### Related Articles

* [Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "article - table of contents")
* [From DarkGate to AsyncRAT: Malware Detected and Shared As Unit 42 Timely Threat Intelligence](https://unit42.paloaltonetworks.com/unit42-threat-intelligence-roundup/ "article - table of contents")
* [Wireshark Tutorial: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/ "article - table of contents")

## Related Cybersecurity Tutorials Resources

![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 1, 2024 [#### Wireshark Tutorial: Exporting Objects From a Pcap](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-exporting-objects-from-a-pcap/ "Wireshark Tutorial: Exporting Objects From a Pcap")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) October 10, 2023 [#### Wireshark Tutorial: Identifying Hosts and Users](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/using-wireshark-identifying-hosts-and-users/ "Wireshark Tutorial: Identifying Hosts and Users")  
  ![A person focuses intently on a screen, with many lines of code on the monitor reflected in their glasses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) September 1, 2023 [#### RedLine Stealer: Answers to Unit 42 Wireshark Quiz](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer-answers/ "RedLine Stealer: Answers to Unit 42 Wireshark Quiz")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 31, 2023 [#### Wireshark Tutorial: Changing Your Column Display](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit42-customizing-wireshark-changing-column-display/ "Wireshark Tutorial: Changing Your Column Display")  
  ![Person wearing glasses and a hoodie, sitting in a dimly lit room, focused on a computer screen displaying complex data visualizations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/06_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) August 18, 2023 [#### Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/)

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Redline infostealer](https://unit42.paloaltonetworks.com/tag/redline-infostealer/ "Redline infostealer")

* [Wireshark Tutorial](https://unit42.paloaltonetworks.com/tag/wireshark-tutorial/ "Wireshark Tutorial")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-redline-stealer/ "Crossing the Line: Unit 42 Wireshark Quiz for RedLine Stealer")  
  ![A man wearing headphones with a microphone is focused on multiple computer screens displaying graphs and data, indicating involvement in a professional tech or analytics environment.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/02_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 30, 2023 [#### Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid-answers/ "Cold as Ice: Answers to Unit 42 Wireshark Quiz for IcedID")  
  ![A woman is intently working on a computer in a modern office environment, surrounded by screens displaying dynamic digital data and stock market numbers, highlighting a focus on financial analysis.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/04_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) May 26, 2023 [#### Cold as Ice: Unit 42 Wireshark Quiz for IcedID](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/)

* [Banking trojans](https://unit42.paloaltonetworks.com/tag/banking-trojans/ "banking trojans")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/wireshark-quiz-icedid/ "Cold as Ice: Unit 42 Wireshark Quiz for IcedID")  
  ![Two people working in a modern office environment with one person concentrating on a computer screen displaying code while another person works in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/10_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) May 15, 2023 [#### It's All in the Name: How Unit 42 Defines and Tracks Threat Adversaries](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")

* [Threat actors](https://unit42.paloaltonetworks.com/tag/threat-actors/ "threat actors")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/from-activity-to-formal-naming/ "It’s All in the Name: How Unit 42 Defines and Tracks Threat Adversaries")  
  ![A Black man in business attire using a tablet, with illuminated skyscrapers in the background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/01_Tutorial_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-podcast-player.svg)Learning Hub](https://unit42.paloaltonetworks.com/category/learning-hub/) March 27, 2023 [#### Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/)

* [Gozi](https://unit42.paloaltonetworks.com/tag/gozi/ "Gozi")

* [Pcap](https://unit42.paloaltonetworks.com/tag/pcap/ "pcap")

* [Wireshark](https://unit42.paloaltonetworks.com/tag/wireshark/ "Wireshark")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/march-wireshark-gozi-answers/ "Finding Gozi: Answers to Unit 42 Wireshark Quiz, March 2023")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
