I’ve noticed a significant uptick in unusual traffic patterns on our network over the past week. Using tools like Wireshark, I’ve been pinpointing possible sources, but I’d love to hear how others approach identifying and mitigating these types of anomalies. Any insights or experiences to share?
It sounds like you’re on the right track with Wireshark! I’ve found that sometimes it helps to look at user patterns first — like trying to catch a gremlin in the attic by just turning on the lights. Have you considered tracking logins or changes in user behavior alongside the traffic?
I’ve had some success using flow analysis tools alongside Wireshark to get a clearer picture of anomalies. Sometimes the patterns can give away more than the individual packets. Have you tried correlating traffic spikes with specific user activities?