There are three clients in this month's exercise pcap.
Check endpoints, find local IPs
Check NetBIOS
ip.addr == 10.0.0.149 and nbns
→ DESKTOP-C10SKPY
ip.addr == 10.0.0.167 and nbns
→ DESKTOP-GRIONXA
ip.addr == 10.0.0.202 and nbns
→ none (good, as only two Windows)
Check Kerberos
ip.addr == 10.0.0.149 and kerberos.CNameString
→ alyssa.fitzgerald
ip.addr == 10.0.0.167 and kerberos.CNameString
→ elmer.obrien
Summary
10.0.0.149 — DESKTOP-C10SKPY — alyssa.fitzgerald
10.0.0.167 — DESKTOP-GRIONXA — elmer.obrien
Image
ip.src == 119.31.234.40 and ip.dst == 10.0.0.167 and http
→ follow TCP stream
If nothing found, download and hash file and search online for hash