BTJA (Blue Team Junior Analyst) Wireshark Activity PCAP 1 Walkthrough!

Safiullah Khan
3 min readFeb 23, 2024


My walkthrough of analyzing PCAP 1 of the Wireshark Challenge from Security Blue Team Junior Analyst Pathway.

In this article we have been going to test our Wireshark skill by analyzing a pcap 1 file and will answer the following questions.

  1. Which protocol was used over port 3942?

. Statistics >Endpoints >UDP tab

. See port 3942 associated with IP

. Right-click > Apply as Filter > Selected.

Now go to main screen of the Wireshark and get protocol name.

Figure 1: Answer of question 1

Answer: SSDP

2. What is the IP address of the host that was pinged twice?

To get the IP Address we will use icmp(protocol for ping utility) filter in display filter and will get back with results.

Answer: pinged twice by

3. How many DNS query response packets were captured?

To get the DNS query response packets captured we will apply the dns filter in display filter and select the first packet that says, “standard query response.” and then go the packet details pane and open the details about Flags. The first flag says “Message is a response”; right-click this and select Apply as Filter > Selected.

Display filter get set automatically on top and at the bottom, see the number of displayed packets with the filter applied.

Anwer: 90

4. What is the IP address of the host which sent the greatest number of bytes?

To get the host which has sent the greatest number of bytes by clicking Statistics > Endpoints > IPv4 > click Tx Bytes (transmit bytes) to display the results in descending order. Rx Packets are received by a device, while Tx Packets are transmitted by a device.



Looking in Endpoints was very helpful in finding the information needed to answer the questions and remember that if you can click on something, then you can apply it as a filter as we have learned a little about digging into DNS packets.



Safiullah Khan

IT & Network Support || Vulnerability Assessment || Google CPC || Blue Team Junior Analyst || SIEM || IDS/IPS || Wazuh || Cortex XDR || Splunk