2026-04-12 14-16-52
May 25, 2026 13:40
· 8:30
· English
· Whisper Turbo
· 1 Konuşmacılar
Bu transkrip bugün sona eriyor.
Kalıcı depolama için yükselt →
Sadece göster
0:07
S…
Speaker 1 (2026-04-12 14-16-52)
Before performing a network hunt on any of our network traffic,
0:11
S…
Speaker 1 (2026-04-12 14-16-52)
we have to make sure we are properly capturing this network traffic.
0:15
S…
Speaker 1 (2026-04-12 14-16-52)
And there's two primary ways to do this.
0:19
S…
Speaker 1 (2026-04-12 14-16-52)
One of the first methods is going to be using what are known as network
0:23
S…
Speaker 1 (2026-04-12 14-16-52)
sensors,
0:24
S…
Speaker 1 (2026-04-12 14-16-52)
and the other method is going to be application -based.
0:27
S…
Speaker 1 (2026-04-12 14-16-52)
Let's start by taking a look at our network sensors.
0:31
S…
Speaker 1 (2026-04-12 14-16-52)
These are essentially can be,
0:33
S…
Speaker 1 (2026-04-12 14-16-52)
you know, individual devices or it can be network devices
0:37
S…
Speaker 1 (2026-04-12 14-16-52)
that have certain configurations on them to
0:41
S…
Speaker 1 (2026-04-12 14-16-52)
be able to capture network traffic.
0:43
S…
Speaker 1 (2026-04-12 14-16-52)
And this allows this traffic to be captured,
0:46
S…
Speaker 1 (2026-04-12 14-16-52)
to be logged for later analysis in the purposes and
0:50
S…
Speaker 1 (2026-04-12 14-16-52)
for our purposes in a threat hunt.
0:53
S…
Speaker 1 (2026-04-12 14-16-52)
Now, where the network sensor is
0:58
S…
Speaker 1 (2026-04-12 14-16-52)
placed in the network is really going to determine
1:02
S…
Speaker 1 (2026-04-12 14-16-52)
what type of traffic it's able to capture.
1:06
S…
Speaker 1 (2026-04-12 14-16-52)
For example,
1:07
S…
Speaker 1 (2026-04-12 14-16-52)
if we're talking about a sensor that is on a switch
1:11
S…
Speaker 1 (2026-04-12 14-16-52)
or placed on a switch port,
1:15
S…
Speaker 1 (2026-04-12 14-16-52)
This can potentially see any traffic that is
1:20
S…
Speaker 1 (2026-04-12 14-16-52)
flowing through that switch depending on the configuration.
1:23
S…
Speaker 1 (2026-04-12 14-16-52)
If we're talking about a sensor that's placed between two
1:27
S…
Speaker 1 (2026-04-12 14-16-52)
routers, it's only going to see the traffic between those two devices.
1:31
S…
Speaker 1 (2026-04-12 14-16-52)
Anything that's traveling between,
1:33
S…
Speaker 1 (2026-04-12 14-16-52)
say,
1:34
S…
Speaker 1 (2026-04-12 14-16-52)
those two subnets that those routers are handling is going to depend
1:38
S…
Speaker 1 (2026-04-12 14-16-52)
on how the network is set up,
1:40
S…
Speaker 1 (2026-04-12 14-16-52)
but you get the gist of it there.
1:43
S…
Speaker 1 (2026-04-12 14-16-52)
The purpose for these network sensors is to be able to see
1:47
S…
Speaker 1 (2026-04-12 14-16-52)
exactly what's happening on the network,
1:50
S…
Speaker 1 (2026-04-12 14-16-52)
be able to record that data for future analysis for a threat
1:54
S…
Speaker 1 (2026-04-12 14-16-52)
hunt when it is needed.
1:55
S…
Speaker 1 (2026-04-12 14-16-52)
There are many other purposes for recording network traffic,
1:59
S…
Speaker 1 (2026-04-12 14-16-52)
such as network management,
2:01
S…
Speaker 1 (2026-04-12 14-16-52)
regular security audits,
2:03
S…
Speaker 1 (2026-04-12 14-16-52)
anything like that.
2:05
S…
Speaker 1 (2026-04-12 14-16-52)
But for the purposes of threat hunting,
2:07
S…
Speaker 1 (2026-04-12 14-16-52)
this allows us to be able to detect possible command and control activity,
2:12
S…
Speaker 1 (2026-04-12 14-16-52)
can be able to detect workstations that may be
2:16
S…
Speaker 1 (2026-04-12 14-16-52)
downloading payloads,
2:18
S…
Speaker 1 (2026-04-12 14-16-52)
or perhaps some sort of data exfiltration.
2:21
S…
Speaker 1 (2026-04-12 14-16-52)
And there's many other places we can get information on these types
2:25
S…
Speaker 1 (2026-04-12 14-16-52)
of attacks as well,
2:26
S…
Speaker 1 (2026-04-12 14-16-52)
but network sensors are a good tool
2:30
S…
Speaker 1 (2026-04-12 14-16-52)
that can be used to be able to record this data.
2:35
S…
Speaker 1 (2026-04-12 14-16-52)
Now there's two primary types of network sensors
2:39
S…
Speaker 1 (2026-04-12 14-16-52)
that we're going to be talking about.
2:41
S…
Speaker 1 (2026-04-12 14-16-52)
One is called a network tap,
2:42
S…
Speaker 1 (2026-04-12 14-16-52)
and the other is called a port mirror.
2:45
S…
Speaker 1 (2026-04-12 14-16-52)
There's many different names for these,
2:48
S…
Speaker 1 (2026-04-12 14-16-52)
but these are the kind of the general terms for it.
2:50
S…
Speaker 1 (2026-04-12 14-16-52)
As far as a tap,
2:52
S…
Speaker 1 (2026-04-12 14-16-52)
this is typically,
2:55
S…
Speaker 1 (2026-04-12 14-16-52)
there's the word I was looking for,
2:57
S…
Speaker 1 (2026-04-12 14-16-52)
going to be a standalone device,
3:00
S…
Speaker 1 (2026-04-12 14-16-52)
but it is possible to have it built into other devices as
3:04
S…
Speaker 1 (2026-04-12 14-16-52)
well.
3:04
S…
Speaker 1 (2026-04-12 14-16-52)
For example,
3:05
S…
Speaker 1 (2026-04-12 14-16-52)
intrusion prevention systems are typically going to use a
3:10
S…
Speaker 1 (2026-04-12 14-16-52)
form of a network tap to be able to monitor traffic
3:14
S…
Speaker 1 (2026-04-12 14-16-52)
flowing through it and potentially block that traffic,
3:16
S…
Speaker 1 (2026-04-12 14-16-52)
again, depending on the configuration.
3:19
S…
Speaker 1 (2026-04-12 14-16-52)
But the kind of basic gist of a network tap is it's
3:23
S…
Speaker 1 (2026-04-12 14-16-52)
a device that has three network ports.
3:25
S…
Speaker 1 (2026-04-12 14-16-52)
Two of those ports,
3:27
S…
Speaker 1 (2026-04-12 14-16-52)
traffic just flows normally through.
3:29
S…
Speaker 1 (2026-04-12 14-16-52)
Your regular network traffic just flows through it.
3:32
S…
Speaker 1 (2026-04-12 14-16-52)
But then the third port is used to copy or duplicate that
3:36
S…
Speaker 1 (2026-04-12 14-16-52)
network traffic,
3:37
S…
Speaker 1 (2026-04-12 14-16-52)
routes it through that third port,
3:39
S…
Speaker 1 (2026-04-12 14-16-52)
which is known as a monitor port.
3:42
S…
Speaker 1 (2026-04-12 14-16-52)
To be able to log and record that data,
3:45
S…
Speaker 1 (2026-04-12 14-16-52)
many different uses there,
3:47
S…
Speaker 1 (2026-04-12 14-16-52)
but again, for the purposes of threat hunting here,
3:49
S…
Speaker 1 (2026-04-12 14-16-52)
we are recording this data for later analysis.
3:53
S…
Speaker 1 (2026-04-12 14-16-52)
That is a network tap,
3:55
S…
Speaker 1 (2026-04-12 14-16-52)
pretty simple type of device.
3:57
S…
Speaker 1 (2026-04-12 14-16-52)
And then you have what is known as a port mirror,
4:00
S…
Speaker 1 (2026-04-12 14-16-52)
or in the Cisco world,
4:01
S…
Speaker 1 (2026-04-12 14-16-52)
this is known as a Cisco SPAN.
4:03
S…
Speaker 1 (2026-04-12 14-16-52)
That stands for switched port analyzer.
4:08
S…
Speaker 1 (2026-04-12 14-16-52)
This is a device that is,
4:10
S…
Speaker 1 (2026-04-12 14-16-52)
or not a device,
4:10
S…
Speaker 1 (2026-04-12 14-16-52)
this is configured on a network device.
4:14
S…
Speaker 1 (2026-04-12 14-16-52)
Normally, you're going to see this on something like a switch,
4:17
S…
Speaker 1 (2026-04-12 14-16-52)
where you have one port that is basically going to be
4:21
S…
Speaker 1 (2026-04-12 14-16-52)
configured as the mirror port,
4:24
S…
Speaker 1 (2026-04-12 14-16-52)
which then allows all traffic that is on that device,
4:28
S…
Speaker 1 (2026-04-12 14-16-52)
switch in this case,
4:29
S…
Speaker 1 (2026-04-12 14-16-52)
to be copied to that port for logging.
4:34
S…
Speaker 1 (2026-04-12 14-16-52)
Similar functionality as the network tap where it copies any data
4:38
S…
Speaker 1 (2026-04-12 14-16-52)
that flows through the device to a specific port to be sent
4:42
S…
Speaker 1 (2026-04-12 14-16-52)
for, you know,
4:43
S…
Speaker 1 (2026-04-12 14-16-52)
capturing or logging or anything like that.
4:46
S…
Speaker 1 (2026-04-12 14-16-52)
But in this case,
4:47
S…
Speaker 1 (2026-04-12 14-16-52)
it is done on a switch and it can see any traffic on
4:51
S…
Speaker 1 (2026-04-12 14-16-52)
the switch.
4:52
S…
Speaker 1 (2026-04-12 14-16-52)
Now, depending on network bandwidth and throughput,
4:56
S…
Speaker 1 (2026-04-12 14-16-52)
this has the potential to have
5:00
S…
Speaker 1 (2026-04-12 14-16-52)
some performance implications there.
5:04
S…
Speaker 1 (2026-04-12 14-16-52)
It can potentially result in some dropped packets.
5:07
S…
Speaker 1 (2026-04-12 14-16-52)
It depends,
5:08
S…
Speaker 1 (2026-04-12 14-16-52)
again, on the amount of traffic on the network and what the switch
5:12
S…
Speaker 1 (2026-04-12 14-16-52)
can actually handle.
5:14
S…
Speaker 1 (2026-04-12 14-16-52)
So those are your types of,
5:16
S…
Speaker 1 (2026-04-12 14-16-52)
you know, more of your physical network sensors,
5:19
S…
Speaker 1 (2026-04-12 14-16-52)
a standalone network tap device or a configuration done
5:23
S…
Speaker 1 (2026-04-12 14-16-52)
as part of a port mirror setup.
5:26
S…
Speaker 1 (2026-04-12 14-16-52)
Then we get into our applications that can be used for
5:30
S…
Speaker 1 (2026-04-12 14-16-52)
capturing network data.
5:32
S…
Speaker 1 (2026-04-12 14-16-52)
One of the most popular of those is going to be Wireshark,
5:35
S…
Speaker 1 (2026-04-12 14-16-52)
or this is a cross -platform application.
5:39
S…
Speaker 1 (2026-04-12 14-16-52)
Then we'll get into,
5:40
S…
Speaker 1 (2026-04-12 14-16-52)
you know, Wireshark in a lot more detail in later videos in this course
5:44
S…
Speaker 1 (2026-04-12 14-16-52)
as well.
5:45
S…
Speaker 1 (2026-04-12 14-16-52)
But there's many different applications that can be used for capturing
5:49
S…
Speaker 1 (2026-04-12 14-16-52)
network data on a specific endpoint.
5:53
S…
Speaker 1 (2026-04-12 14-16-52)
Now, these are installed on a specific endpoint.
5:57
S…
Speaker 1 (2026-04-12 14-16-52)
We're talking about these applications.
5:58
S…
Speaker 1 (2026-04-12 14-16-52)
We're only talking about something on a specific device.
6:02
S…
Speaker 1 (2026-04-12 14-16-52)
We're not talking about something on the network that can capture any of the traffic going
6:06
S…
Speaker 1 (2026-04-12 14-16-52)
there. We're only capturing any traffic that is on
6:10
S…
Speaker 1 (2026-04-12 14-16-52)
that workstation.
6:11
S…
Speaker 1 (2026-04-12 14-16-52)
It is not going to capture any of that traffic if
6:15
S…
Speaker 1 (2026-04-12 14-16-52)
the source or the destination is not that workstation.
6:20
S…
Speaker 1 (2026-04-12 14-16-52)
With the exception of broadcast traffic,
6:23
S…
Speaker 1 (2026-04-12 14-16-52)
it will capture that because technically the workstation is one of the destinations
6:27
S…
Speaker 1 (2026-04-12 14-16-52)
for that broadcast.
6:28
S…
Speaker 1 (2026-04-12 14-16-52)
So that is a caveat there.
6:30
S…
Speaker 1 (2026-04-12 14-16-52)
It is only going to capture traffic if the workstation
6:34
S…
Speaker 1 (2026-04-12 14-16-52)
that the application is running on is the source or the destination for
6:38
S…
Speaker 1 (2026-04-12 14-16-52)
that traffic.
6:39
S…
Speaker 1 (2026-04-12 14-16-52)
It will capture encrypted traffic.
6:42
S…
Speaker 1 (2026-04-12 14-16-52)
But it's going to capture it encrypted.
6:45
S…
Speaker 1 (2026-04-12 14-16-52)
Keep that in mind.
6:46
S…
Speaker 1 (2026-04-12 14-16-52)
And we'll talk about encrypted traffic and some potential
6:50
S…
Speaker 1 (2026-04-12 14-16-52)
ways to analyze it in later videos where we start getting more hands
6:54
S…
Speaker 1 (2026-04-12 14-16-52)
-on with applications like Wireshark.
6:58
S…
Speaker 1 (2026-04-12 14-16-52)
Now, when you're doing a network capture with these applications,
7:01
S…
Speaker 1 (2026-04-12 14-16-52)
you have the potential to have a very large capture
7:05
S…
Speaker 1 (2026-04-12 14-16-52)
file, again,
7:06
S…
Speaker 1 (2026-04-12 14-16-52)
depending on the amount of traffic that is going to that workstation.
7:11
S…
Speaker 1 (2026-04-12 14-16-52)
So it's all going to be very,
7:13
S…
Speaker 1 (2026-04-12 14-16-52)
you know,
7:14
S…
Speaker 1 (2026-04-12 14-16-52)
it's going to depend on the traffic.
7:16
S…
Speaker 1 (2026-04-12 14-16-52)
There are ways to be able to reduce the size
7:20
S…
Speaker 1 (2026-04-12 14-16-52)
of the captured data,
7:22
S…
Speaker 1 (2026-04-12 14-16-52)
to reduce the amount of data that is captured using capture filters.
7:25
S…
Speaker 1 (2026-04-12 14-16-52)
And again,
7:26
S…
Speaker 1 (2026-04-12 14-16-52)
We'll take a look at those in later videos in this course.
7:30
S…
Speaker 1 (2026-04-12 14-16-52)
But one caveat there with capture filters,
7:32
S…
Speaker 1 (2026-04-12 14-16-52)
if you are using those,
7:34
S…
Speaker 1 (2026-04-12 14-16-52)
yes, you're reducing the size of the capture file.
7:37
S…
Speaker 1 (2026-04-12 14-16-52)
You're reducing the amount of data that's captured,
7:40
S…
Speaker 1 (2026-04-12 14-16-52)
but you have the potential to miss important data depending
7:44
S…
Speaker 1 (2026-04-12 14-16-52)
on how the filter is set up.
7:46
S…
Speaker 1 (2026-04-12 14-16-52)
And if you miss capturing it,
7:48
S…
Speaker 1 (2026-04-12 14-16-52)
you miss capturing it.
7:49
S…
Speaker 1 (2026-04-12 14-16-52)
You don't get a second chance to capture that network data.
7:54
S…
Speaker 1 (2026-04-12 14-16-52)
So keep that in mind when you're talking about capture filters on
7:58
S…
Speaker 1 (2026-04-12 14-16-52)
these application methods for capturing network traffic.
8:02
S…
Speaker 1 (2026-04-12 14-16-52)
And again,
8:03
S…
Speaker 1 (2026-04-12 14-16-52)
we're going to get a lot more in -depth on using various applications
8:07
S…
Speaker 1 (2026-04-12 14-16-52)
to capture network traffic as we progress with this
8:12
S…
Speaker 1 (2026-04-12 14-16-52)
course.
8:12
S…
Speaker 1 (2026-04-12 14-16-52)
But this was just meant to be a brief introduction to some
8:16
S…
Speaker 1 (2026-04-12 14-16-52)
of the ways that you can capture network traffic on an
8:20
S…
Speaker 1 (2026-04-12 14-16-52)
enterprise network.
Bu transkrip AI (otomatik konuşma tanıma) tarafından üretildi. Hatalar içerebilir - kritik kullanım için orijinal sesle karşılaştırınız. Yapay zeka politikası
Özet
Bu transkrip için bir AI özeti oluşturmak için Özetle' ye tıklayın.
Toplamlayarak...
Bu transkrip hakkında AI'ye sor
Bu transkrip hakkında herhangi bir şey sor — yapay zeka ilgili bölümleri bulur ve cevap verir.