This might be the wrong forum for that type of question, it sounds more like an incident response/intrusion analysis/network forensics type of question, not a penetration testing type of question.
Anyway, you could try something like the below:
Pulling binaries from pcaps « SANS Computer Forensics, Investigation, and Response


