wireshark_detect_arp_spoofing
Detect ARP spoofing attacks in network captures by identifying duplicate IP-MAC mappings, gratuitous ARP floods, and reply storms from pcap files.
Instructions
[ARP] Detect potential ARP spoofing (duplicate IP-MAC, gratuitous floods, reply storms).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| pcap_file | Yes |