I would recommend creating stringent capture filters, using editcap to deduplicate the capture, and then exporting to CSV and sorting/filtering further to refine the list down just to the unique hosts that are accessing the domain controller. A much easier method however would probably be using NetFlow Traffic Analyzer.
↧