I am taking part in a practice sandbox, and have a pcap file in Wireshark: with the traffic depicting a Vertical Port Scan. Is there anyway to find out the "victim"'s Operating System? The packets are all TCP SYNs, and I tried to filter http GET requests (information can be in User Agent) but there are none. Any help would be much appreciated.

1 Answers1


Probably you should use http://lcamtuf.coredump.cx/p0f3/, this is a good tool for start to understand passive os detection, but bear in mind that there is techniques to fake the results but definitively a good starting point

  • 2,172
  • 1
  • 10
  • 10