Link to home
Start Free TrialLog in
Avatar of Fulgencio Eres
Fulgencio Eres

asked on

what connections should be in my network connection logs?

I'm trying to trace a hacker that's in my computer and phone as well...basically my entire network. I've been recording my network connections and PCAPs but there are so many captures that log how can I tell which ones to research and which ones are simply apps running in the bankground?
also if the title of a capture reads "unknown"is that an automatic red flag??
any advice is greatly appreciated.
SOLUTION
Avatar of John
John
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Merete
Try the Process Hacker it's free
A free, powerful, multi-purpose tool that helps you
monitor system resources, debug software and detect malware.
http://processhacker.sourceforge.net/
What makes you think you have been hacked?
What are the signs?
Do you have any Peer to peer software installed for downloading like Bittorrent/Gnutella Napster if so check if you have disabled the uploading.
With Peer to Peer the file-transfer load is distributed between the computers exchanging files, but file searches and transfers from your computer to others can cause bottlenecks.
Some people download files and immediately disconnect without allowing others to obtain files from their system, which is called leeching.
This limits the number of computers the software can search for the requested file.
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Your two questions should be in the same so that the information is relevant to both
what info is needed to have the cops research a cybercrime?
https://www.experts-exchange.com/questions/28977688/what-info-is-needed-to-have-the-cops-research-a-cybercrime.html
Avatar of Fulgencio Eres
Fulgencio Eres

ASKER

Thank you so much for replying (everyone)..
I have the report from CommView (I have WireShark also) what information is the information that is important?  what do I research more? what is the info needed for the police?
The only information the police would want would be an identifiable external IP Address (that one can look up in Whois).