drop pcap pcapng or zeek conn log · detect smb admin share rdp hops credential reuse pivot patterns · movement chain · export csv · runs locally
drop .pcap / .pcapng and/or zeek conn.log