2026-04-12 14-16-52
May 25, 2026 13:40
· 8:30
· English
· Whisper Turbo
· 1 ተናጋሪ
ይህ ትረካ ዛሬ ይቋረጣል
ለዘለቄታው ማስቀመጫ ማሻሻል →
ማሳየት ብቻ
0:07
S…
Speaker 1 (2026-04-12 14-16-52)
Before performing a network hunt on any of our network traffic,
0:11
S…
Speaker 1 (2026-04-12 14-16-52)
we have to make sure we are properly capturing this network traffic.
0:15
S…
Speaker 1 (2026-04-12 14-16-52)
And there's two primary ways to do this.
0:19
S…
Speaker 1 (2026-04-12 14-16-52)
One of the first methods is going to be using what are known as network
0:23
S…
Speaker 1 (2026-04-12 14-16-52)
sensors,
0:24
S…
Speaker 1 (2026-04-12 14-16-52)
and the other method is going to be application -based.
0:27
S…
Speaker 1 (2026-04-12 14-16-52)
Let's start by taking a look at our network sensors.
0:31
S…
Speaker 1 (2026-04-12 14-16-52)
These are essentially can be,
0:33
S…
Speaker 1 (2026-04-12 14-16-52)
you know, individual devices or it can be network devices
0:37
S…
Speaker 1 (2026-04-12 14-16-52)
that have certain configurations on them to
0:41
S…
Speaker 1 (2026-04-12 14-16-52)
be able to capture network traffic.
0:43
S…
Speaker 1 (2026-04-12 14-16-52)
And this allows this traffic to be captured,
0:46
S…
Speaker 1 (2026-04-12 14-16-52)
to be logged for later analysis in the purposes and
0:50
S…
Speaker 1 (2026-04-12 14-16-52)
for our purposes in a threat hunt.
0:53
S…
Speaker 1 (2026-04-12 14-16-52)
Now, where the network sensor is
0:58
S…
Speaker 1 (2026-04-12 14-16-52)
placed in the network is really going to determine
1:02
S…
Speaker 1 (2026-04-12 14-16-52)
what type of traffic it's able to capture.
1:06
S…
Speaker 1 (2026-04-12 14-16-52)
For example,
1:07
S…
Speaker 1 (2026-04-12 14-16-52)
if we're talking about a sensor that is on a switch
1:11
S…
Speaker 1 (2026-04-12 14-16-52)
or placed on a switch port,
1:15
S…
Speaker 1 (2026-04-12 14-16-52)
This can potentially see any traffic that is
1:20
S…
Speaker 1 (2026-04-12 14-16-52)
flowing through that switch depending on the configuration.
1:23
S…
Speaker 1 (2026-04-12 14-16-52)
If we're talking about a sensor that's placed between two
1:27
S…
Speaker 1 (2026-04-12 14-16-52)
routers, it's only going to see the traffic between those two devices.
1:31
S…
Speaker 1 (2026-04-12 14-16-52)
Anything that's traveling between,
1:33
S…
Speaker 1 (2026-04-12 14-16-52)
say,
1:34
S…
Speaker 1 (2026-04-12 14-16-52)
those two subnets that those routers are handling is going to depend
1:38
S…
Speaker 1 (2026-04-12 14-16-52)
on how the network is set up,
1:40
S…
Speaker 1 (2026-04-12 14-16-52)
but you get the gist of it there.
1:43
S…
Speaker 1 (2026-04-12 14-16-52)
The purpose for these network sensors is to be able to see
1:47
S…
Speaker 1 (2026-04-12 14-16-52)
exactly what's happening on the network,
1:50
S…
Speaker 1 (2026-04-12 14-16-52)
be able to record that data for future analysis for a threat
1:54
S…
Speaker 1 (2026-04-12 14-16-52)
hunt when it is needed.
1:55
S…
Speaker 1 (2026-04-12 14-16-52)
There are many other purposes for recording network traffic,
1:59
S…
Speaker 1 (2026-04-12 14-16-52)
such as network management,
2:01
S…
Speaker 1 (2026-04-12 14-16-52)
regular security audits,
2:03
S…
Speaker 1 (2026-04-12 14-16-52)
anything like that.
2:05
S…
Speaker 1 (2026-04-12 14-16-52)
But for the purposes of threat hunting,
2:07
S…
Speaker 1 (2026-04-12 14-16-52)
this allows us to be able to detect possible command and control activity,
2:12
S…
Speaker 1 (2026-04-12 14-16-52)
can be able to detect workstations that may be
2:16
S…
Speaker 1 (2026-04-12 14-16-52)
downloading payloads,
2:18
S…
Speaker 1 (2026-04-12 14-16-52)
or perhaps some sort of data exfiltration.
2:21
S…
Speaker 1 (2026-04-12 14-16-52)
And there's many other places we can get information on these types
2:25
S…
Speaker 1 (2026-04-12 14-16-52)
of attacks as well,
2:26
S…
Speaker 1 (2026-04-12 14-16-52)
but network sensors are a good tool
2:30
S…
Speaker 1 (2026-04-12 14-16-52)
that can be used to be able to record this data.
2:35
S…
Speaker 1 (2026-04-12 14-16-52)
Now there's two primary types of network sensors
2:39
S…
Speaker 1 (2026-04-12 14-16-52)
that we're going to be talking about.
2:41
S…
Speaker 1 (2026-04-12 14-16-52)
One is called a network tap,
2:42
S…
Speaker 1 (2026-04-12 14-16-52)
and the other is called a port mirror.
2:45
S…
Speaker 1 (2026-04-12 14-16-52)
There's many different names for these,
2:48
S…
Speaker 1 (2026-04-12 14-16-52)
but these are the kind of the general terms for it.
2:50
S…
Speaker 1 (2026-04-12 14-16-52)
As far as a tap,
2:52
S…
Speaker 1 (2026-04-12 14-16-52)
this is typically,
2:55
S…
Speaker 1 (2026-04-12 14-16-52)
there's the word I was looking for,
2:57
S…
Speaker 1 (2026-04-12 14-16-52)
going to be a standalone device,
3:00
S…
Speaker 1 (2026-04-12 14-16-52)
but it is possible to have it built into other devices as
3:04
S…
Speaker 1 (2026-04-12 14-16-52)
well.
3:04
S…
Speaker 1 (2026-04-12 14-16-52)
For example,
3:05
S…
Speaker 1 (2026-04-12 14-16-52)
intrusion prevention systems are typically going to use a
3:10
S…
Speaker 1 (2026-04-12 14-16-52)
form of a network tap to be able to monitor traffic
3:14
S…
Speaker 1 (2026-04-12 14-16-52)
flowing through it and potentially block that traffic,
3:16
S…
Speaker 1 (2026-04-12 14-16-52)
again, depending on the configuration.
3:19
S…
Speaker 1 (2026-04-12 14-16-52)
But the kind of basic gist of a network tap is it's
3:23
S…
Speaker 1 (2026-04-12 14-16-52)
a device that has three network ports.
3:25
S…
Speaker 1 (2026-04-12 14-16-52)
Two of those ports,
3:27
S…
Speaker 1 (2026-04-12 14-16-52)
traffic just flows normally through.
3:29
S…
Speaker 1 (2026-04-12 14-16-52)
Your regular network traffic just flows through it.
3:32
S…
Speaker 1 (2026-04-12 14-16-52)
But then the third port is used to copy or duplicate that
3:36
S…
Speaker 1 (2026-04-12 14-16-52)
network traffic,
3:37
S…
Speaker 1 (2026-04-12 14-16-52)
routes it through that third port,
3:39
S…
Speaker 1 (2026-04-12 14-16-52)
which is known as a monitor port.
3:42
S…
Speaker 1 (2026-04-12 14-16-52)
To be able to log and record that data,
3:45
S…
Speaker 1 (2026-04-12 14-16-52)
many different uses there,
3:47
S…
Speaker 1 (2026-04-12 14-16-52)
but again, for the purposes of threat hunting here,
3:49
S…
Speaker 1 (2026-04-12 14-16-52)
we are recording this data for later analysis.
3:53
S…
Speaker 1 (2026-04-12 14-16-52)
That is a network tap,
3:55
S…
Speaker 1 (2026-04-12 14-16-52)
pretty simple type of device.
3:57
S…
Speaker 1 (2026-04-12 14-16-52)
And then you have what is known as a port mirror,
4:00
S…
Speaker 1 (2026-04-12 14-16-52)
or in the Cisco world,
4:01
S…
Speaker 1 (2026-04-12 14-16-52)
this is known as a Cisco SPAN.
4:03
S…
Speaker 1 (2026-04-12 14-16-52)
That stands for switched port analyzer.
4:08
S…
Speaker 1 (2026-04-12 14-16-52)
This is a device that is,
4:10
S…
Speaker 1 (2026-04-12 14-16-52)
or not a device,
4:10
S…
Speaker 1 (2026-04-12 14-16-52)
this is configured on a network device.
4:14
S…
Speaker 1 (2026-04-12 14-16-52)
Normally, you're going to see this on something like a switch,
4:17
S…
Speaker 1 (2026-04-12 14-16-52)
where you have one port that is basically going to be
4:21
S…
Speaker 1 (2026-04-12 14-16-52)
configured as the mirror port,
4:24
S…
Speaker 1 (2026-04-12 14-16-52)
which then allows all traffic that is on that device,
4:28
S…
Speaker 1 (2026-04-12 14-16-52)
switch in this case,
4:29
S…
Speaker 1 (2026-04-12 14-16-52)
to be copied to that port for logging.
4:34
S…
Speaker 1 (2026-04-12 14-16-52)
Similar functionality as the network tap where it copies any data
4:38
S…
Speaker 1 (2026-04-12 14-16-52)
that flows through the device to a specific port to be sent
4:42
S…
Speaker 1 (2026-04-12 14-16-52)
for, you know,
4:43
S…
Speaker 1 (2026-04-12 14-16-52)
capturing or logging or anything like that.
4:46
S…
Speaker 1 (2026-04-12 14-16-52)
But in this case,
4:47
S…
Speaker 1 (2026-04-12 14-16-52)
it is done on a switch and it can see any traffic on
4:51
S…
Speaker 1 (2026-04-12 14-16-52)
the switch.
4:52
S…
Speaker 1 (2026-04-12 14-16-52)
Now, depending on network bandwidth and throughput,
4:56
S…
Speaker 1 (2026-04-12 14-16-52)
this has the potential to have
5:00
S…
Speaker 1 (2026-04-12 14-16-52)
some performance implications there.
5:04
S…
Speaker 1 (2026-04-12 14-16-52)
It can potentially result in some dropped packets.
5:07
S…
Speaker 1 (2026-04-12 14-16-52)
It depends,
5:08
S…
Speaker 1 (2026-04-12 14-16-52)
again, on the amount of traffic on the network and what the switch
5:12
S…
Speaker 1 (2026-04-12 14-16-52)
can actually handle.
5:14
S…
Speaker 1 (2026-04-12 14-16-52)
So those are your types of,
5:16
S…
Speaker 1 (2026-04-12 14-16-52)
you know, more of your physical network sensors,
5:19
S…
Speaker 1 (2026-04-12 14-16-52)
a standalone network tap device or a configuration done
5:23
S…
Speaker 1 (2026-04-12 14-16-52)
as part of a port mirror setup.
5:26
S…
Speaker 1 (2026-04-12 14-16-52)
Then we get into our applications that can be used for
5:30
S…
Speaker 1 (2026-04-12 14-16-52)
capturing network data.
5:32
S…
Speaker 1 (2026-04-12 14-16-52)
One of the most popular of those is going to be Wireshark,
5:35
S…
Speaker 1 (2026-04-12 14-16-52)
or this is a cross -platform application.
5:39
S…
Speaker 1 (2026-04-12 14-16-52)
Then we'll get into,
5:40
S…
Speaker 1 (2026-04-12 14-16-52)
you know, Wireshark in a lot more detail in later videos in this course
5:44
S…
Speaker 1 (2026-04-12 14-16-52)
as well.
5:45
S…
Speaker 1 (2026-04-12 14-16-52)
But there's many different applications that can be used for capturing
5:49
S…
Speaker 1 (2026-04-12 14-16-52)
network data on a specific endpoint.
5:53
S…
Speaker 1 (2026-04-12 14-16-52)
Now, these are installed on a specific endpoint.
5:57
S…
Speaker 1 (2026-04-12 14-16-52)
We're talking about these applications.
5:58
S…
Speaker 1 (2026-04-12 14-16-52)
We're only talking about something on a specific device.
6:02
S…
Speaker 1 (2026-04-12 14-16-52)
We're not talking about something on the network that can capture any of the traffic going
6:06
S…
Speaker 1 (2026-04-12 14-16-52)
there. We're only capturing any traffic that is on
6:10
S…
Speaker 1 (2026-04-12 14-16-52)
that workstation.
6:11
S…
Speaker 1 (2026-04-12 14-16-52)
It is not going to capture any of that traffic if
6:15
S…
Speaker 1 (2026-04-12 14-16-52)
the source or the destination is not that workstation.
6:20
S…
Speaker 1 (2026-04-12 14-16-52)
With the exception of broadcast traffic,
6:23
S…
Speaker 1 (2026-04-12 14-16-52)
it will capture that because technically the workstation is one of the destinations
6:27
S…
Speaker 1 (2026-04-12 14-16-52)
for that broadcast.
6:28
S…
Speaker 1 (2026-04-12 14-16-52)
So that is a caveat there.
6:30
S…
Speaker 1 (2026-04-12 14-16-52)
It is only going to capture traffic if the workstation
6:34
S…
Speaker 1 (2026-04-12 14-16-52)
that the application is running on is the source or the destination for
6:38
S…
Speaker 1 (2026-04-12 14-16-52)
that traffic.
6:39
S…
Speaker 1 (2026-04-12 14-16-52)
It will capture encrypted traffic.
6:42
S…
Speaker 1 (2026-04-12 14-16-52)
But it's going to capture it encrypted.
6:45
S…
Speaker 1 (2026-04-12 14-16-52)
Keep that in mind.
6:46
S…
Speaker 1 (2026-04-12 14-16-52)
And we'll talk about encrypted traffic and some potential
6:50
S…
Speaker 1 (2026-04-12 14-16-52)
ways to analyze it in later videos where we start getting more hands
6:54
S…
Speaker 1 (2026-04-12 14-16-52)
-on with applications like Wireshark.
6:58
S…
Speaker 1 (2026-04-12 14-16-52)
Now, when you're doing a network capture with these applications,
7:01
S…
Speaker 1 (2026-04-12 14-16-52)
you have the potential to have a very large capture
7:05
S…
Speaker 1 (2026-04-12 14-16-52)
file, again,
7:06
S…
Speaker 1 (2026-04-12 14-16-52)
depending on the amount of traffic that is going to that workstation.
7:11
S…
Speaker 1 (2026-04-12 14-16-52)
So it's all going to be very,
7:13
S…
Speaker 1 (2026-04-12 14-16-52)
you know,
7:14
S…
Speaker 1 (2026-04-12 14-16-52)
it's going to depend on the traffic.
7:16
S…
Speaker 1 (2026-04-12 14-16-52)
There are ways to be able to reduce the size
7:20
S…
Speaker 1 (2026-04-12 14-16-52)
of the captured data,
7:22
S…
Speaker 1 (2026-04-12 14-16-52)
to reduce the amount of data that is captured using capture filters.
7:25
S…
Speaker 1 (2026-04-12 14-16-52)
And again,
7:26
S…
Speaker 1 (2026-04-12 14-16-52)
We'll take a look at those in later videos in this course.
7:30
S…
Speaker 1 (2026-04-12 14-16-52)
But one caveat there with capture filters,
7:32
S…
Speaker 1 (2026-04-12 14-16-52)
if you are using those,
7:34
S…
Speaker 1 (2026-04-12 14-16-52)
yes, you're reducing the size of the capture file.
7:37
S…
Speaker 1 (2026-04-12 14-16-52)
You're reducing the amount of data that's captured,
7:40
S…
Speaker 1 (2026-04-12 14-16-52)
but you have the potential to miss important data depending
7:44
S…
Speaker 1 (2026-04-12 14-16-52)
on how the filter is set up.
7:46
S…
Speaker 1 (2026-04-12 14-16-52)
And if you miss capturing it,
7:48
S…
Speaker 1 (2026-04-12 14-16-52)
you miss capturing it.
7:49
S…
Speaker 1 (2026-04-12 14-16-52)
You don't get a second chance to capture that network data.
7:54
S…
Speaker 1 (2026-04-12 14-16-52)
So keep that in mind when you're talking about capture filters on
7:58
S…
Speaker 1 (2026-04-12 14-16-52)
these application methods for capturing network traffic.
8:02
S…
Speaker 1 (2026-04-12 14-16-52)
And again,
8:03
S…
Speaker 1 (2026-04-12 14-16-52)
we're going to get a lot more in -depth on using various applications
8:07
S…
Speaker 1 (2026-04-12 14-16-52)
to capture network traffic as we progress with this
8:12
S…
Speaker 1 (2026-04-12 14-16-52)
course.
8:12
S…
Speaker 1 (2026-04-12 14-16-52)
But this was just meant to be a brief introduction to some
8:16
S…
Speaker 1 (2026-04-12 14-16-52)
of the ways that you can capture network traffic on an
8:20
S…
Speaker 1 (2026-04-12 14-16-52)
enterprise network.
ይህ ትርክት በ AI (አቶማቲክ የንግግር ማወቅ) የተፈጠረ ነው. ስህተቶች ሊኖሩ ይችላሉ - ለጥብቅ ጥቅም በመጀመሪያው ድምፅ ላይ ይመልከቱ የAI ፖሊሲ
ማጠቃለያ
የዚህን ትራንስክሪፕት AI ማጠቃለያ ለማምጣት ማጠቃለያ ላይ ጠቅ ያድርጉ
ማጠቃለያ...
ስለዚህ ትራንስክሪፕት AI ጠይቅ
ስለዚህ ጽሑፍ ማንኛውንም ነገር ጠይቁ - AI የሚመለከታቸውን ክፍሎች ያገኛል እናም መልስ ይሰጣል.