net_icmp_payload
Analyze ICMP echo payloads to detect covert data exfiltration by examining entropy, printable content ratio, payload size anomalies, and pattern consistency.
Instructions
ICMP echo payload analysis. Examines entropy, printable content ratio, payload size anomalies, and pattern consistency of ICMP echo request/reply payloads to detect covert data exfiltration.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| file_path | Yes | Path to PCAP capture file |