1. List all of the IP addresses found within this packet capture. While running the lab, it looks like there were 9 packets captured for the IP

As you have done within other classes to build Snort rules, you will now take the information you gathered to create Snort rules. Use the details you collected within this lab to create three Snort rules to detect the activity.

For example, 

alert tcp any any -> 80 (msg: “Malicious Payload Upload”; sid:1000002; content:”FileUploader”; http_uri; content:”POST”; http_method; flow:to_server,established;)