Wireshark-dev: [Wireshark-dev] Visualising the opening and accessing a file via SMB
From: Richard Sharpe <realrichardsharpe@xxxxxxxxx>
Date: Fri, 28 Jun 2013 10:44:26 -0700
Hi folks,

I see a need for a tool like the following.

Take a capture of SMB1 or SMB2 traffic and draw a chart vertically showing:

Opens and closes of a specified (or all) file(s) with
nested/overlapping opens/closes showing up in different colors.
OpLock breaks and locks and reads/writes showing up as well.

The reason for this is so we can more easily see what is happening
between one or more clients.

Has anyone done anything like this or is there a framework I can start with?

-- 
Regards,
Richard Sharpe
(何以解憂?唯有杜康。--曹操)