

It can be used as starting point in analysis for checking any suspicious dns request or http to identify any CC. It will show all the packets with protocol dns or http. This not filter can be used when you want to filter any noise from specific protocol

Easy to extract IoC (e.g Domain, IP etc) from pcap.We can use this Wireshark display filter after we capture pcap during dynamic malware analysis. We will look into some of the Wireshark display filters which can be used in malware analysis.
