Приказујем само
0:08
S… Speaker 1 (2026-04-13 00-56-13)
In this video,
0:08
S… Speaker 2 (2026-04-13 00-56-13)
we're going to look at some normal ICMP
0:12
S… Speaker 2 (2026-04-13 00-56-13)
traffic, some normal DHCP traffic,
0:15
S… Speaker 2 (2026-04-13 00-56-13)
and then also look at what the equivalent of abnormal or suspicious
0:20
S… Speaker 2 (2026-04-13 00-56-13)
traffic for both of those protocols can be.
0:23
S… Speaker 2 (2026-04-13 00-56-13)
Starting with ICMP,
0:24
S… Speaker 2 (2026-04-13 00-56-13)
if you're not familiar with ICMP,
0:26
S… Speaker 2 (2026-04-13 00-56-13)
it stands for the Internet Control Messaging Protocol or Message Protocol.
0:30
S… Speaker 2 (2026-04-13 00-56-13)
It's designed to provide information about different devices and nodes
0:34
S… Speaker 1 (2026-04-13 00-56-13)
on the network.
0:35
S… Speaker 1 (2026-04-13 00-56-13)
Most commonly,
0:36
S… Speaker 2 (2026-04-13 00-56-13)
you'll see it used for things like ping and traceroute,
0:40
S… Speaker 2 (2026-04-13 00-56-13)
but we're going to look specifically at ping in this video.
0:43
S… Speaker 2 (2026-04-13 00-56-13)
So with a ping request and reply,
0:47
S… Speaker 2 (2026-04-13 00-56-13)
you have a client and a server,
0:49
S… Speaker 2 (2026-04-13 00-56-13)
or, you know,
0:50
S… Speaker 2 (2026-04-13 00-56-13)
we have basically it's communication between two machines.
0:53
S… Speaker 2 (2026-04-13 00-56-13)
They don't necessarily need to be considered client and server.
0:55
S… Speaker 2 (2026-04-13 00-56-13)
The first machine that's trying to see in a ping example,
1:00
S… Speaker 2 (2026-04-13 00-56-13)
basically to see if the machine is online.
1:02
S… Speaker 2 (2026-04-13 00-56-13)
it will send an echo request.
1:05
S… Speaker 1 (2026-04-13 00-56-13)
Now,
1:06
S… Speaker 2 (2026-04-13 00-56-13)
assuming the destination machine is online and
1:10
S… Speaker 2 (2026-04-13 00-56-13)
hasn't been configured to not reply to an echo
1:14
S… Speaker 2 (2026-04-13 00-56-13)
request, a ping request,
1:15
S… Speaker 2 (2026-04-13 00-56-13)
and there's nothing blocking the communication,
1:18
S… Speaker 2 (2026-04-13 00-56-13)
it will then reply with an echo response or a ping
1:22
S… Speaker 1 (2026-04-13 00-56-13)
response.
1:24
S… Speaker 2 (2026-04-13 00-56-13)
Looking at that in Wireshark,
1:26
S… Speaker 2 (2026-04-13 00-56-13)
it basically looks like this.
1:28
S… Speaker 2 (2026-04-13 00-56-13)
The ICMP ping protocol is fairly straightforward.
1:32
S… Speaker 2 (2026-04-13 00-56-13)
So we have our source machine of 192 .168 .43
1:37
S… Speaker 2 (2026-04-13 00-56-13)
.9 talking to a destination machine of 8 .8 .8
1:41
S… Speaker 1 (2026-04-13 00-56-13)
.8.
1:42
S… Speaker 2 (2026-04-13 00-56-13)
The source machine sends our echo request
1:46
S… Speaker 2 (2026-04-13 00-56-13)
right here,
1:46
S… Speaker 2 (2026-04-13 00-56-13)
our ping request.
1:47
S… Speaker 2 (2026-04-13 00-56-13)
The destination machine replies with an echo reply.
1:52
S… Speaker 2 (2026-04-13 00-56-13)
And then we can see that actually repeats two more times,
1:55
S… Speaker 2 (2026-04-13 00-56-13)
a request and a reply,
1:56
S… Speaker 2 (2026-04-13 00-56-13)
and another request and reply by the same source
2:01
S… Speaker 2 (2026-04-13 00-56-13)
and destination machines.
2:02
S… Speaker 2 (2026-04-13 00-56-13)
This is what normal ICMP echo
2:07
S… Speaker 2 (2026-04-13 00-56-13)
requests and replies look like.
2:09
S… Speaker 2 (2026-04-13 00-56-13)
Again, there's a lot other types of ICMP traffic,
2:12
S… Speaker 2 (2026-04-13 00-56-13)
but in here we're just going to look at ping requests and replies.
2:18
S… Speaker 2 (2026-04-13 00-56-13)
Expanding on that a little bit,
2:20
S… Speaker 2 (2026-04-13 00-56-13)
an ICMP echo request is going to start out.
2:24
S… Speaker 2 (2026-04-13 00-56-13)
We see if we expand the ICMP information in
2:28
S… Speaker 1 (2026-04-13 00-56-13)
Wireshark,
2:28
S… Speaker 2 (2026-04-13 00-56-13)
we see it as a packet of type 8 code 0.
2:33
S… Speaker 2 (2026-04-13 00-56-13)
That basically is the equivalent of an echo request.
2:38
S… Speaker 2 (2026-04-13 00-56-13)
The other thing we see,
2:39
S… Speaker 2 (2026-04-13 00-56-13)
besides the normal source and destination that we see in most
2:43
S… Speaker 2 (2026-04-13 00-56-13)
TCP and ICMP,
2:45
S… Speaker 2 (2026-04-13 00-56-13)
in this case it's IP traffic,
2:47
S… Speaker 2 (2026-04-13 00-56-13)
we see the data field is filled with what
2:51
S… Speaker 2 (2026-04-13 00-56-13)
appears to be randomly generated information.
2:53
S… Speaker 2 (2026-04-13 00-56-13)
And that's exactly what it is.
2:55
S… Speaker 2 (2026-04-13 00-56-13)
It is a randomly generated string.
2:57
S… Speaker 2 (2026-04-13 00-56-13)
And that string will show up in the echo reply as
3:01
S… Speaker 2 (2026-04-13 00-56-13)
well. So the reply here we see is going to be ICMP.
3:06
S… Speaker 2 (2026-04-13 00-56-13)
Type 0,
3:06
S… Speaker 2 (2026-04-13 00-56-13)
code 0,
3:07
S… Speaker 2 (2026-04-13 00-56-13)
which is the equivalent or indicates this is an echo reply.
3:11
S… Speaker 2 (2026-04-13 00-56-13)
And in the data field in Wireshark here,
3:14
S… Speaker 2 (2026-04-13 00-56-13)
we see the exact same randomly generated string.
3:19
S… Speaker 2 (2026-04-13 00-56-13)
That is essentially how the echo requests and replies are
3:23
S… Speaker 2 (2026-04-13 00-56-13)
tied together so that the receiving machine knows
3:28
S… Speaker 2 (2026-04-13 00-56-13)
what this is in reply to.
3:30
S… Speaker 2 (2026-04-13 00-56-13)
It's in reply to this specific request because that data field
3:34
S… Speaker 1 (2026-04-13 00-56-13)
matches up.
3:35
S… Speaker 2 (2026-04-13 00-56-13)
So how do we identify normal versus suspicious ICMP
3:40
S… Speaker 2 (2026-04-13 00-56-13)
echo requests or ping requests?
3:42
S… Speaker 1 (2026-04-13 00-56-13)
Number one,
3:43
S… Speaker 2 (2026-04-13 00-56-13)
there should be a limited number of these occurring on the network.
3:47
S… Speaker 2 (2026-04-13 00-56-13)
And again, this is going to be subjective based on your individual network.
3:52
S… Speaker 2 (2026-04-13 00-56-13)
But an indication of suspicious traffic here would be hundreds
3:56
S… Speaker 2 (2026-04-13 00-56-13)
or thousands of these requests in a small amount of time.
4:00
S… Speaker 2 (2026-04-13 00-56-13)
That can be an indication there's attacker trying to
4:05
S… Speaker 2 (2026-04-13 00-56-13)
do a ping sweep on the network to determine what
4:09
S… Speaker 2 (2026-04-13 00-56-13)
systems are on the network.
4:10
S… Speaker 2 (2026-04-13 00-56-13)
This is very noisy and usually is seen by security systems,
4:14
S… Speaker 2 (2026-04-13 00-56-13)
so it's not something you're going to see very often,
4:16
S… Speaker 2 (2026-04-13 00-56-13)
but it is an indication of suspicious traffic.
4:20
S… Speaker 2 (2026-04-13 00-56-13)
In normal ping request traffic,
4:23
S… Speaker 2 (2026-04-13 00-56-13)
the reply should always follow the request.
4:27
S… Speaker 1 (2026-04-13 00-56-13)
Now,
4:28
S… Speaker 2 (2026-04-13 00-56-13)
that doesn't mean there's always going to be a reply.
4:31
S… Speaker 2 (2026-04-13 00-56-13)
If a machine is not online or if there is some other mechanism
4:36
S… Speaker 2 (2026-04-13 00-56-13)
in place that prevents the reply or the request from even
4:40
S… Speaker 2 (2026-04-13 00-56-13)
reaching the destination,
4:41
S… Speaker 2 (2026-04-13 00-56-13)
then you may not always see a reply.
4:44
S… Speaker 2 (2026-04-13 00-56-13)
A request does not always receive that reply.
4:47
S… Speaker 2 (2026-04-13 00-56-13)
However, it is a bit suspicious if you see a number of replies
4:51
S… Speaker 2 (2026-04-13 00-56-13)
without any requests at all.
4:55
S… Speaker 2 (2026-04-13 00-56-13)
Now, there's some legitimate reasons you may see this,
4:57
S… Speaker 2 (2026-04-13 00-56-13)
and it depends on how the information,
4:59
S… Speaker 2 (2026-04-13 00-56-13)
how these...
5:00
S… Speaker 2 (2026-04-13 00-56-13)
packets are being captured.
5:01
S… Speaker 2 (2026-04-13 00-56-13)
But that would be something suspicious you would want to check on
5:05
S… Speaker 1 (2026-04-13 00-56-13)
when you're doing threat hunting.
5:06
S… Speaker 2 (2026-04-13 00-56-13)
Normal ICMP traffic or echo traffic
5:10
S… Speaker 2 (2026-04-13 00-56-13)
that we saw in Wireshark will have a very small amount of
5:15
S… Speaker 2 (2026-04-13 00-56-13)
information in that data field.
5:18
S… Speaker 2 (2026-04-13 00-56-13)
It is suspicious if you see a number of larger ICMP
5:22
S… Speaker 1 (2026-04-13 00-56-13)
packets,
5:23
S… Speaker 2 (2026-04-13 00-56-13)
especially a large amount of information in that data field.
5:27
S… Speaker 2 (2026-04-13 00-56-13)
That could potentially be an indication that there is an attacker
5:31
S… Speaker 2 (2026-04-13 00-56-13)
trying to communicate using ICMP packets.
5:34
S… Speaker 2 (2026-04-13 00-56-13)
Whether it's something like command and control communication or data exfiltration
5:39
S… Speaker 1 (2026-04-13 00-56-13)
or anything like that,
5:40
S… Speaker 1 (2026-04-13 00-56-13)
that is something to keep an eye on.
5:43
S… Speaker 2 (2026-04-13 00-56-13)
So ICMP echo requests and replies fairly simple
5:47
S… Speaker 2 (2026-04-13 00-56-13)
in how they function,
5:48
S… Speaker 2 (2026-04-13 00-56-13)
but there are a number of ways they can be abused that you should keep
5:53
S… Speaker 1 (2026-04-13 00-56-13)
an eye out for when you're performing a threat hunt.
5:55
S… Speaker 2 (2026-04-13 00-56-13)
Let's move on to DHCP now.
5:57
S… Speaker 1 (2026-04-13 00-56-13)
If you're not familiar,
5:58
S… Speaker 2 (2026-04-13 00-56-13)
DHCP stands for the Dynamic Host Configuration
6:02
S… Speaker 1 (2026-04-13 00-56-13)
Protocol.
6:03
S… Speaker 1 (2026-04-13 00-56-13)
Essentially,
6:04
S… Speaker 2 (2026-04-13 00-56-13)
you have a DHCP client that is trying to get an IP address
6:08
S… Speaker 1 (2026-04-13 00-56-13)
on the network,
6:09
S… Speaker 2 (2026-04-13 00-56-13)
and it will request that information from a DHCP server,
6:13
S… Speaker 1 (2026-04-13 00-56-13)
and the server will then assign various bits of information.
6:16
S… Speaker 1 (2026-04-13 00-56-13)
Now,
6:17
S… Speaker 2 (2026-04-13 00-56-13)
the process that this goes through is known as the DHCP DORA
6:21
S… Speaker 1 (2026-04-13 00-56-13)
process,
6:22
S… Speaker 2 (2026-04-13 00-56-13)
and we'll see that here.
6:24
S… Speaker 2 (2026-04-13 00-56-13)
It starts off with a DHCP discover message.
6:27
S… Speaker 2 (2026-04-13 00-56-13)
That's the D in the DORA there.
6:29
S… Speaker 2 (2026-04-13 00-56-13)
If there is a DHCP server online and it receives that
6:33
S… Speaker 2 (2026-04-13 00-56-13)
discover request or discover packet,
6:35
S… Speaker 2 (2026-04-13 00-56-13)
it will respond with an offer packet.
6:38
S… Speaker 2 (2026-04-13 00-56-13)
We'll take a look at these in more detail in a second to see what all of these messages
6:42
S… Speaker 1 (2026-04-13 00-56-13)
contain.
6:44
S… Speaker 2 (2026-04-13 00-56-13)
So a discover and then an offer,
6:46
S… Speaker 2 (2026-04-13 00-56-13)
and then assuming the DHCP client is good
6:51
S… Speaker 2 (2026-04-13 00-56-13)
with what it's received back from the DHCP server,
6:54
S… Speaker 2 (2026-04-13 00-56-13)
it will actually formally request that information in a DHCP
6:59
S… Speaker 1 (2026-04-13 00-56-13)
request.
7:00
S… Speaker 2 (2026-04-13 00-56-13)
And then once the server has processed that information,
7:03
S… Speaker 2 (2026-04-13 00-56-13)
it will reply with the DHCP acknowledgement packet.
7:07
S… Speaker 2 (2026-04-13 00-56-13)
So we see there that maps out to a DORA process,
7:11
S… Speaker 2 (2026-04-13 00-56-13)
discover,
7:11
S… Speaker 1 (2026-04-13 00-56-13)
offer,
7:12
S… Speaker 1 (2026-04-13 00-56-13)
request, and acknowledgement.
7:15
S… Speaker 2 (2026-04-13 00-56-13)
And that's kind of what that looks like at a very high level in
7:19
S… Speaker 1 (2026-04-13 00-56-13)
Wireshark.
7:20
S… Speaker 2 (2026-04-13 00-56-13)
You see it starts off with the discover,
7:22
S… Speaker 2 (2026-04-13 00-56-13)
the server then replies back with the offer,
7:25
S… Speaker 2 (2026-04-13 00-56-13)
the client requests that information,
7:28
S… Speaker 2 (2026-04-13 00-56-13)
and then the server processes it and replies back with
7:32
S… Speaker 1 (2026-04-13 00-56-13)
the acknowledgement.
7:33
S… Speaker 2 (2026-04-13 00-56-13)
So let's switch over to our lab environment and we're going to take
7:37
S… Speaker 2 (2026-04-13 00-56-13)
a look at these packets in a little more detail in Wireshark.
7:42
S… Speaker 1 (2026-04-13 00-56-13)
Alright, over in our lab environment here,
7:46
S… Speaker 2 (2026-04-13 00-56-13)
first thing we're going to look at is a DHCP discoverer
7:50
S… Speaker 2 (2026-04-13 00-56-13)
packet. So we have our DHCP client,
7:53
S… Speaker 2 (2026-04-13 00-56-13)
or basically normally going to be a workstation or something like
7:57
S… Speaker 1 (2026-04-13 00-56-13)
that.
7:58
S… Speaker 2 (2026-04-13 00-56-13)
It sends out a broadcast packet.
8:00
S… Speaker 2 (2026-04-13 00-56-13)
So we can see right here it is sending to the broadcast MAC address
8:05
S… Speaker 2 (2026-04-13 00-56-13)
as well as a broadcast IP address as
8:09
S… Speaker 1 (2026-04-13 00-56-13)
well.
8:10
S… Speaker 2 (2026-04-13 00-56-13)
It doesn't know where the DHCP server is
8:15
S… Speaker 2 (2026-04-13 00-56-13)
because this is a lot of times the very first communication it has
8:19
S… Speaker 1 (2026-04-13 00-56-13)
on the network.
8:19
S… Speaker 2 (2026-04-13 00-56-13)
It doesn't even have an IP address,
8:21
S… Speaker 2 (2026-04-13 00-56-13)
so it has to broadcast this request out.
8:23
S… Speaker 2 (2026-04-13 00-56-13)
It is trying to discover where the DHCP server
8:28
S… Speaker 1 (2026-04-13 00-56-13)
is.
8:28
S… Speaker 2 (2026-04-13 00-56-13)
It doesn't know what device has that information.
8:32
S… Speaker 2 (2026-04-13 00-56-13)
So we see that it is a request here.
8:35
S… Speaker 2 (2026-04-13 00-56-13)
The client doesn't have any IP address information
8:39
S… Speaker 1 (2026-04-13 00-56-13)
or anything like that,
8:41
S… Speaker 2 (2026-04-13 00-56-13)
and it is a DHCP discover message that we see
8:45
S… Speaker 1 (2026-04-13 00-56-13)
in the options here.
8:48
S… Speaker 1 (2026-04-13 00-56-13)
So that's the very first thing,
8:50
S… Speaker 2 (2026-04-13 00-56-13)
and we also see what it's requesting.
8:52
S… Speaker 1 (2026-04-13 00-56-13)
So it's requesting,
8:54
S… Speaker 1 (2026-04-13 00-56-13)
obviously, an IP address,
8:55
S… Speaker 1 (2026-04-13 00-56-13)
but we're also looking at...
8:56
S… Speaker 2 (2026-04-13 00-56-13)
requesting the subnet mask,
8:59
S… Speaker 1 (2026-04-13 00-56-13)
router, DNS,
9:00
S… Speaker 2 (2026-04-13 00-56-13)
and NTP information for what this network is.
9:04
S… Speaker 2 (2026-04-13 00-56-13)
Moving on to the offer,
9:07
S… Speaker 2 (2026-04-13 00-56-13)
this is where the DHCP server is replying back
9:11
S… Speaker 2 (2026-04-13 00-56-13)
to the client that sent out that broadcast saying,
9:15
S… Speaker 2 (2026-04-13 00-56-13)
hey, this is the information I would like to assign to you
9:19
S… Speaker 2 (2026-04-13 00-56-13)
as well as the other information.
9:21
S… Speaker 2 (2026-04-13 00-56-13)
So more detail in Wireshark,
9:22
S… Speaker 2 (2026-04-13 00-56-13)
we see this is a DHCP offer.
9:26
S… Speaker 2 (2026-04-13 00-56-13)
And we see here under the your client address,
9:30
S… Speaker 2 (2026-04-13 00-56-13)
this is the IP address that the server is offering to
9:34
S… Speaker 1 (2026-04-13 00-56-13)
the client.
9:35
S… Speaker 1 (2026-04-13 00-56-13)
Scroll down a little more information.
9:38
S… Speaker 2 (2026-04-13 00-56-13)
We also see here's the subnet mask that it's offering as
9:42
S… Speaker 2 (2026-04-13 00-56-13)
long as some other information about the IP address,
9:46
S… Speaker 2 (2026-04-13 00-56-13)
how long the lease will last,
9:49
S… Speaker 2 (2026-04-13 00-56-13)
and the IP address for the DHCP server
9:53
S… Speaker 1 (2026-04-13 00-56-13)
as well.
9:54
S… Speaker 2 (2026-04-13 00-56-13)
So that's the DHCP offer packet.
9:57
S… Speaker 2 (2026-04-13 00-56-13)
The DHCP request packet,
10:00
S… Speaker 2 (2026-04-13 00-56-13)
that goes back out to the DHCP server.
10:02
S… Speaker 2 (2026-04-13 00-56-13)
You see here,
10:03
S… Speaker 2 (2026-04-13 00-56-13)
it is actually a broadcast packet.
10:05
S… Speaker 2 (2026-04-13 00-56-13)
But it is basically saying,
10:07
S… Speaker 2 (2026-04-13 00-56-13)
the client says,
10:09
S… Speaker 2 (2026-04-13 00-56-13)
yes, please give me that IP address.
10:11
S… Speaker 2 (2026-04-13 00-56-13)
I am formally requesting that IP address in this DHCP
10:15
S… Speaker 1 (2026-04-13 00-56-13)
request.
10:17
S… Speaker 1 (2026-04-13 00-56-13)
And it does have,
10:18
S… Speaker 2 (2026-04-13 00-56-13)
again, the additional information that it was requesting,
10:21
S… Speaker 2 (2026-04-13 00-56-13)
but we also have the requested IP address.
10:24
S… Speaker 2 (2026-04-13 00-56-13)
This is the same IP address that the DHCP server was
10:29
S… Speaker 2 (2026-04-13 00-56-13)
just offering in the DHCP offer packet.
10:32
S… Speaker 2 (2026-04-13 00-56-13)
And then the final part is the DHCP acknowledgement
10:36
S… Speaker 2 (2026-04-13 00-56-13)
or the DHCP ACK packet.
10:39
S… Speaker 1 (2026-04-13 00-56-13)
Let's go back up to the top.
10:40
S… Speaker 2 (2026-04-13 00-56-13)
This goes back to the destination of the machine,
10:43
S… Speaker 2 (2026-04-13 00-56-13)
the DHCP client.
10:45
S… Speaker 2 (2026-04-13 00-56-13)
And we see here that it is assigning the IP address,
10:49
S… Speaker 2 (2026-04-13 00-56-13)
and it is giving additional information as well.
10:53
S… Speaker 2 (2026-04-13 00-56-13)
The lease time,
10:55
S… Speaker 2 (2026-04-13 00-56-13)
in this case one hour,
10:56
S… Speaker 2 (2026-04-13 00-56-13)
it's saying the DHCP server information again.
11:00
S… Speaker 2 (2026-04-13 00-56-13)
So it's repeating a lot of the same information,
11:02
S… Speaker 2 (2026-04-13 00-56-13)
but it is basically just confirming all of the information
11:07
S… Speaker 1 (2026-04-13 00-56-13)
in the initial request.
11:10
S… Speaker 2 (2026-04-13 00-56-13)
So that's what the full DHCP kind of communication looks
11:14
S… Speaker 2 (2026-04-13 00-56-13)
like. Starts with the request and then progresses through the offer
11:18
S… Speaker 1 (2026-04-13 00-56-13)
from the server.
11:19
S… Speaker 1 (2026-04-13 00-56-13)
Or excuse me,
11:20
S… Speaker 2 (2026-04-13 00-56-13)
starts with the discovery.
11:21
S… Speaker 1 (2026-04-13 00-56-13)
I misspoke there.
11:22
S… Speaker 2 (2026-04-13 00-56-13)
Starts with the discovery from the client.
11:25
S… Speaker 2 (2026-04-13 00-56-13)
Server offers an IP address,
11:27
S… Speaker 1 (2026-04-13 00-56-13)
the client requests it,
11:28
S… Speaker 1 (2026-04-13 00-56-13)
and the server processes and acknowledges it.
11:31
S… Speaker 2 (2026-04-13 00-56-13)
So that's what the process looks like in Wireshark.
11:35
S… Speaker 2 (2026-04-13 00-56-13)
Let's take a look at some ways we can recognize suspicious versus
11:40
S… Speaker 2 (2026-04-13 00-56-13)
regular DHCP traffic now.
11:43
S… Speaker 2 (2026-04-13 00-56-13)
The process follows the DORA steps,
11:47
S… Speaker 2 (2026-04-13 00-56-13)
the discovery,
11:48
S… Speaker 2 (2026-04-13 00-56-13)
the offer,
11:49
S… Speaker 1 (2026-04-13 00-56-13)
the request,
11:50
S… Speaker 1 (2026-04-13 00-56-13)
and the acknowledgement.
11:51
S… Speaker 2 (2026-04-13 00-56-13)
Suspicious traffic would look like DHCP offers
11:56
S… Speaker 2 (2026-04-13 00-56-13)
without any requests or perhaps any other of the traffic
12:00
S… Speaker 1 (2026-04-13 00-56-13)
being out of order.
12:02
S… Speaker 2 (2026-04-13 00-56-13)
The requests coming in out of order,
12:06
S… Speaker 1 (2026-04-13 00-56-13)
any of that,
12:07
S… Speaker 1 (2026-04-13 00-56-13)
like not following the DORA process.
12:11
S… Speaker 2 (2026-04-13 00-56-13)
Another one that is very important to keep a lookout for is
12:15
S… Speaker 2 (2026-04-13 00-56-13)
going to be rogue DHCP servers.
12:17
S… Speaker 2 (2026-04-13 00-56-13)
Normal DHCP traffic,
12:20
S… Speaker 2 (2026-04-13 00-56-13)
the offers should originate from a legitimate,
12:23
S… Speaker 1 (2026-04-13 00-56-13)
known,
12:24
S… Speaker 2 (2026-04-13 00-56-13)
configured,
12:25
S… Speaker 2 (2026-04-13 00-56-13)
and authorized DHCP server on the network.
12:30
S… Speaker 1 (2026-04-13 00-56-13)
If you're looking,
12:31
S… Speaker 1 (2026-04-13 00-56-13)
if you're performing a threat hunt,
12:32
S… Speaker 2 (2026-04-13 00-56-13)
and you see DHCP offers coming from
12:36
S… Speaker 2 (2026-04-13 00-56-13)
a server or an IP address that is not the registered
12:41
S… Speaker 2 (2026-04-13 00-56-13)
DHCP server on the network,
12:43
S… Speaker 2 (2026-04-13 00-56-13)
that is a very big indication that something suspicious or
12:47
S… Speaker 2 (2026-04-13 00-56-13)
malicious is happening on the network and should definitely be
12:52
S… Speaker 1 (2026-04-13 00-56-13)
investigated further.

Овај транскрипт је створио АИ (автоматско препознавање говора). Може садржати грешке — проверити оригинални аудио за критичну употребу. Политика ВИ

❤️ Љубав STT.ai?
сажетак
Кликните на Summarise да бисте направили ВИ сажетак овог транскрипта.
Сажетак...
Питај ВИ о овом транкрипту
Питајте било шта о овом транскрипту - АИ ће наћи релевантне секције и одговор.