CyberForensicLab

Network Forensics Teaching Suite

NeSA

Packet Analysis

Upload and analyze PCAP files. Reconstruct TCP sessions, inspect packet headers, view protocol distribution, and trace network conversations.

PCAP TCP/UDP DNS HTTP

CyberInvestigator

Log Analysis

Analyze Apache, Syslog, auth, IIS, and Windows event logs. Detect brute force, SQL injection, XSS attacks, and suspicious patterns automatically.

Apache Syslog Auth IDS

EmailTracer

Email Forensics

Trace email origin by analyzing headers. Extract sender IP, geolocation, mail route, SPF/DKIM/DMARC results, and detect spoofing indicators.

Headers SPF/DKIM GeoIP .eml

Lab Instructions

Packet Analysis (NeSA)

Upload a .pcap file captured using Wireshark or tcpdump. The tool will parse packets, reconstruct sessions, and show protocol statistics.

Log Analysis (CyberInvestigator)

Upload server logs (Apache, syslog, auth.log, Windows Events). The tool auto-detects log format and runs intrusion detection heuristics.

Email Tracing (EmailTracer)

Paste email headers or upload .eml files. The tool parses Received headers, extracts IPs, checks SPF/DKIM, and maps the email route.