This video explains how evidence acquisition works through an ARP table.
- [Narrator] ARP stands for Address Resolution Protocol. … In the previous lessons I talked about the use of … two addressing schemes in computer networking. … One was MAC for switches … and the other was IP for routers. … Because of this difference between the addressing schemes, … when a router forwards a message to a switch … the IP address needs to be converted … to a corresponding MAC address. … Hosts use a table called ARP table to keep track of … the mapping between IP addresses and their MAC versions. … Let's check this out on our Windows box. … In your Command Prompt window, type arp -a. … Press enter. … See the mapping between the internet addresses … and physical addresses? … This table is useful for network forensics specialists … because they can find out the MAC addresses associated with … the IP addresses they're investigating … without signing onto each host. … ARP obtains MAC addresses by using a net broadcast request … that asks for the MAC address for a device … that is configured with an specific IP. …
- Goals of network forensics
- Using a syslog and Microsoft Log Parser
- Investigating network traffic
- How protocol analysis works
- ARP and DNS poisoning
- Working with network forensics tools
- Using packet sniffers
Skill Level Intermediate
Learning Cryptography and Network Securitywith Lisa Bock1h 45m Intermediate
Insights from a Cybersecurity Professionalwith Mike Chapple32m 15s Intermediate
What you should know2m 11s
1. Understanding Network Forensics
2. Preparing for a Network Forensics Investigation
3. Investigating Network Events
4. Investigating Network Traffic
5. Network Forensics Tools
Next steps1m 15s
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.