Now when reading such articles, basically I am dizzy....
Anyway, I notice Wireshark was mentioned in the article.
QUOTE
Wireshark is the world's foremost and widely-used network protocol analyzer.
This reminds me of PCAP:
QUOTE
Packet Capture or PCAP (also known as libpcap) is an application programming interface (API) that captures live network packet data from OSI model Layers 2-7. Network analyzers like Wireshark create . pcap files to collect and record packet data from a network.
Unlike in native Windows, you use all those debugger and disassembler, as well as sysinternal's Process Monitor (to monitor real time registry R/W, disk I/O activities)-- In networking, additional tools like Wireshark is needed.
It would take me another 10 years to understand how digital forensic and malware analysis work.