1. Capture Strategy and Scoping
$ core idea: Before capturing, define the question: Are you troubleshooting an outage, validating an alert, or investigating suspected exfiltration? The question determines capture location, duration, and filter choices.
$ defender angle: Capture filters reduce volume at collection time; display filters narrow analysis after capture. Use them intentionally. Overly narrow capture filters can permanently exclude evidence you later need.
$ prove understanding: Capture traffic safely and understand capture scope limitations.