Anonymizing pcaps for sharing/analysis

asked 2021-04-20

HappySailor gravatar image

Hi there I'd like to share a PCAP file for comments. How can I strip MAC address info and data so that it can safely shared on this boeard?

1 Answer

answered 2021-04-20

SYN-bit gravatar image

Have a look at this blog-post by @Jasper (who wrote Tracewrangler)

HappySailor ( 2021-04-20 09:25:21 +0000 )

Tracewrangler works great. The only limitation I have bumped into is that it can only remove single VLAN tag. Use editcap to remove multiple VLAN tags.

BigFatCat ( 2021-04-20 12:16:28 +0000 )

Glad to hear it worked great for you and maybe @Jasper can add Q-in-Q (or rather, recursive) vlan scrubbing :-)

SYN-bit ( 2021-04-21 06:11:51 +0000 )

I'll have to check into that - Tracewrangler can parse stacked VLAN tags but maybe I forgot to actually add code to remove them...

Jasper ( 2021-04-21 07:47:59 +0000 )

Why would people want to anonymise VLAN tags? Frankly, why would people want also to remove private ip addresses? Is there any reason why you would want to anonymise anything else than mac address and payload?

HappySailor ( 2021-04-21 08:08:54 +0000 )

Asked: 2021-04-20

Seen: 734 times

Last updated: Apr 21 '21