what connections should be in my network connection logs?

I'm trying to trace a hacker that's in my computer and phone as well...basically my entire network. I've been recording my network connections and PCAPs but there are so many captures that log how can I tell which ones to research and which ones are simply apps running in the bankground?
also if the title of a capture reads "unknown"is that an automatic red flag??
any advice is greatly appreciated.
Fulgencio EresAsked:
Who is Participating?
 
JohnConnect With a Mentor Business Consultant (Owner)Commented:
Comm View reports this very nicely.

You could try Wireshark but I prefer Comm VIew because it does all this.
0
 
JohnConnect With a Mentor Business Consultant (Owner)Commented:
I suggest you get and install Comm View (Tamosoft). This will tell you on the main packet screen the Local and Remote IP, the Ports, the Hostname (if one) and the process used.

Any significant traffic (total bytes) to / from something you do not recognize is cause for concern.
0
 
MereteCommented:
Try the Process Hacker it's free
A free, powerful, multi-purpose tool that helps you
monitor system resources, debug software and detect malware.
http://processhacker.sourceforge.net/
What makes you think you have been hacked?
What are the signs?
Do you have any Peer to peer software installed for downloading like Bittorrent/Gnutella Napster if so check if you have disabled the uploading.
With Peer to Peer the file-transfer load is distributed between the computers exchanging files, but file searches and transfers from your computer to others can cause bottlenecks.
Some people download files and immediately disconnect without allowing others to obtain files from their system, which is called leeching.
This limits the number of computers the software can search for the requested file.
0
Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

 
MereteCommented:
Your two questions should be in the same so that the information is relevant to both
what info is needed to have the cops research a cybercrime?
https://www.experts-exchange.com/questions/28977688/what-info-is-needed-to-have-the-cops-research-a-cybercrime.html
0
 
Fulgencio EresAuthor Commented:
Thank you so much for replying (everyone)..
I have the report from CommView (I have WireShark also) what information is the information that is important?  what do I research more? what is the info needed for the police?
0
 
JohnBusiness Consultant (Owner)Commented:
The only information the police would want would be an identifiable external IP Address (that one can look up in Whois).
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.