Agent Skills: implementing-network-traffic-analysis-with-arkime

>-

UncategorizedID: autohandai/community-skills/implementing-network-traffic-analysis-with-arkime

Install this agent skill to your local

pnpm dlx add-skill https://github.com/autohandai/community-skills/tree/HEAD/implementing-network-traffic-analysis-with-arkime

Skill Files

Browse the full folder contents for implementing-network-traffic-analysis-with-arkime.

Download Skill

Loading file tree…

implementing-network-traffic-analysis-with-arkime/SKILL.md

Skill Metadata

Name
implementing-network-traffic-analysis-with-arkime
Description
>-

Instructions

  1. Install dependencies: pip install requests
  2. Configure Arkime viewer URL and credentials.
  3. Run the agent to query Arkime sessions and analyze traffic:
    • Search sessions by IP, port, protocol, or expression
    • Download PCAP data for forensic analysis
    • Detect C2 beaconing via connection interval analysis
    • Identify DNS tunneling through query length statistics
    • Flag connections to known-bad TLS certificate issuers
python scripts/agent.py --arkime-url https://arkime.local:8005 --user admin --password secret --output arkime_report.json

Examples

Beaconing Detection

Source: 10.1.2.50 -> 185.220.101.34:443
Sessions: 288 over 24 hours
Avg interval: 300s, Jitter: 4.2%
Verdict: HIGH confidence C2 beaconing (jitter < 5%)