2026-04-13 00-39-03
May 25, 2026 13:59
· 16:56
· English
· Whisper Turbo
· 2 གསལ་བཤད་
ཡིག་ཆ་འདི་ཕྱི་ཚེས་ ༡༥ ཉིན་མཇུག་བསྡུ་ནི་ཨིན་མས།
གནས་བརྟན་གྱི་གནས་བཞག་གོང་འཕེལ་བཏང། →
སྟོན་རྐྱངམ་ཅིག་
0:10
S…
Speaker 2 (2026-04-13 00-39-03)
When performing threat hunts,
0:12
S…
Speaker 2 (2026-04-13 00-39-03)
it's very important to be able to know what
0:16
S…
Speaker 2 (2026-04-13 00-39-03)
abnormal traffic looks like.
0:19
S…
Speaker 2 (2026-04-13 00-39-03)
So in the next few videos here,
0:21
S…
Speaker 2 (2026-04-13 00-39-03)
we're going to take a look at some examples of different types
0:25
S…
Speaker 2 (2026-04-13 00-39-03)
of normal versus abnormal traffic.
0:28
S…
Speaker 2 (2026-04-13 00-39-03)
We're going to start off by looking at both ARP packets and TCP
0:33
S…
Speaker 1 (2026-04-13 00-39-03)
traffic.
0:34
S…
Speaker 2 (2026-04-13 00-39-03)
Then we're going to look at ICMP,
0:36
S…
Speaker 2 (2026-04-13 00-39-03)
ping requests and replies.
0:39
S…
Speaker 2 (2026-04-13 00-39-03)
DHCP traffic.
0:40
S…
Speaker 2 (2026-04-13 00-39-03)
We're also going to look at HTTP,
0:43
S…
Speaker 2 (2026-04-13 00-39-03)
HTTPS traffic,
0:45
S…
Speaker 2 (2026-04-13 00-39-03)
as well as DNS to try and identify what
0:50
S…
Speaker 2 (2026-04-13 00-39-03)
is normal and what is suspicious or abnormal traffic.
0:54
S…
Speaker 2 (2026-04-13 00-39-03)
Now, a lot of the abnormal or suspicious traffic is going to
0:59
S…
Speaker 2 (2026-04-13 00-39-03)
depend a little bit on what the network is.
1:01
S…
Speaker 2 (2026-04-13 00-39-03)
What are the baselines in the network?
1:03
S…
Speaker 2 (2026-04-13 00-39-03)
What is normal in the network?
1:05
S…
Speaker 2 (2026-04-13 00-39-03)
Some things that may look suspicious on one network may be perfectly
1:09
S…
Speaker 2 (2026-04-13 00-39-03)
normal on another network,
1:11
S…
Speaker 2 (2026-04-13 00-39-03)
which is why you hear me talk about this all the time.
1:14
S…
Speaker 2 (2026-04-13 00-39-03)
Knowing your baselines,
1:16
S…
Speaker 2 (2026-04-13 00-39-03)
knowing what's normal in your specific environment is a critical
1:20
S…
Speaker 2 (2026-04-13 00-39-03)
piece of information.
1:22
S…
Speaker 2 (2026-04-13 00-39-03)
when we're talking about threat hunting.
1:24
S…
Speaker 2 (2026-04-13 00-39-03)
So let's go ahead and start looking at TCP traffic and
1:28
S…
Speaker 2 (2026-04-13 00-39-03)
what normal with TCP looks like.
1:31
S…
Speaker 2 (2026-04-13 00-39-03)
Now with TCP,
1:32
S…
Speaker 2 (2026-04-13 00-39-03)
we have our three -way handshake.
1:35
S…
Speaker 2 (2026-04-13 00-39-03)
This is communication between a client and a server in
1:39
S…
Speaker 1 (2026-04-13 00-39-03)
this case.
1:40
S…
Speaker 2 (2026-04-13 00-39-03)
And this is how all TCP traffic starts with that three -way
1:44
S…
Speaker 1 (2026-04-13 00-39-03)
handshake.
1:45
S…
Speaker 2 (2026-04-13 00-39-03)
The client starts out by sending a SIN packet or a
1:49
S…
Speaker 2 (2026-04-13 00-39-03)
TCP packet with the SIN flag turned on
1:53
S…
Speaker 2 (2026-04-13 00-39-03)
to the server it's trying to talk to.
1:57
S…
Speaker 2 (2026-04-13 00-39-03)
And this is the initiation of the TCP communication.
2:01
S…
Speaker 2 (2026-04-13 00-39-03)
Assuming the client is listening and responds,
2:04
S…
Speaker 2 (2026-04-13 00-39-03)
it sends back a SIN and ACK.
2:08
S…
Speaker 2 (2026-04-13 00-39-03)
packet or a TCP packet with the SIN and ACK flags
2:12
S…
Speaker 1 (2026-04-13 00-39-03)
turned on.
2:13
S…
Speaker 2 (2026-04-13 00-39-03)
And then to finish out the three -way handshake,
2:16
S…
Speaker 2 (2026-04-13 00-39-03)
the client then sends back a TCP packet with the ACK
2:20
S…
Speaker 1 (2026-04-13 00-39-03)
flag enabled.
2:22
S…
Speaker 2 (2026-04-13 00-39-03)
So that is what we are talking about when we're talking about the three -way handshake
2:26
S…
Speaker 1 (2026-04-13 00-39-03)
with TCP.
2:27
S…
Speaker 2 (2026-04-13 00-39-03)
And this is how all TCP...
2:29
S…
Speaker 2 (2026-04-13 00-39-03)
All legitimate TCP traffic should start
2:33
S…
Speaker 2 (2026-04-13 00-39-03)
out with, with this three -way handshake,
2:35
S…
Speaker 2 (2026-04-13 00-39-03)
SIN, SIN,
2:36
S…
Speaker 2 (2026-04-13 00-39-03)
ACK, and ACK in three different packets back
2:40
S…
Speaker 1 (2026-04-13 00-39-03)
and forth.
2:41
S…
Speaker 2 (2026-04-13 00-39-03)
So comparing normal versus suspicious TCP traffic,
2:45
S…
Speaker 2 (2026-04-13 00-39-03)
we know that normal traffic is going to have that three -way handshake.
2:50
S…
Speaker 2 (2026-04-13 00-39-03)
There's a number of different types of suspicious
2:54
S…
Speaker 2 (2026-04-13 00-39-03)
TCP traffic that we can see.
2:57
S…
Speaker 2 (2026-04-13 00-39-03)
Number one would be a lot of SIN
3:01
S…
Speaker 2 (2026-04-13 00-39-03)
packets with no corresponding SIN ACK or ACK packets
3:05
S…
Speaker 2 (2026-04-13 00-39-03)
being sent with that three -way handshake.
3:08
S…
Speaker 2 (2026-04-13 00-39-03)
And this can be an example of port scanning or a ping sweep
3:12
S…
Speaker 2 (2026-04-13 00-39-03)
or anything like that.
3:14
S…
Speaker 2 (2026-04-13 00-39-03)
some sort of scanning by an attacker,
3:17
S…
Speaker 2 (2026-04-13 00-39-03)
or it could be a legitimate purpose for a scan.
3:20
S…
Speaker 2 (2026-04-13 00-39-03)
But that is still could be suspicious depending on the network.
3:24
S…
Speaker 2 (2026-04-13 00-39-03)
You can also have TCP packets that are sent
3:28
S…
Speaker 2 (2026-04-13 00-39-03)
with a different combination of flags.
3:31
S…
Speaker 2 (2026-04-13 00-39-03)
And these different flags can be commonly abused
3:36
S…
Speaker 2 (2026-04-13 00-39-03)
to try and carry out scans against
3:40
S…
Speaker 1 (2026-04-13 00-39-03)
a network.
3:41
S…
Speaker 2 (2026-04-13 00-39-03)
and kind of ways of avoiding detection of those scans.
3:46
S…
Speaker 2 (2026-04-13 00-39-03)
And you can also have examples of maybe a single
3:50
S…
Speaker 2 (2026-04-13 00-39-03)
host sending multiple packets to multiple
3:55
S…
Speaker 2 (2026-04-13 00-39-03)
different ports on a server.
3:57
S…
Speaker 2 (2026-04-13 00-39-03)
Or a single host sending multiple TCP packets,
4:03
S…
Speaker 1 (2026-04-13 00-39-03)
there we go,
4:04
S…
Speaker 2 (2026-04-13 00-39-03)
to multiple other systems on a network.
4:08
S…
Speaker 2 (2026-04-13 00-39-03)
And those are both examples of scanning as well.
4:11
S…
Speaker 2 (2026-04-13 00-39-03)
So looking at TCP in Wireshark,
4:15
S…
Speaker 2 (2026-04-13 00-39-03)
normal traffic will look like this.
4:18
S…
Speaker 2 (2026-04-13 00-39-03)
We start off with the SIN packet right here as
4:22
S…
Speaker 2 (2026-04-13 00-39-03)
the very first packet the client sends.
4:25
S…
Speaker 2 (2026-04-13 00-39-03)
If the server is listening and responding,
4:28
S…
Speaker 2 (2026-04-13 00-39-03)
it sends the SYN ACK,
4:30
S…
Speaker 2 (2026-04-13 00-39-03)
and then the client finishes out the three -way handshake with the ACK packet
4:34
S…
Speaker 1 (2026-04-13 00-39-03)
right there.
4:35
S…
Speaker 2 (2026-04-13 00-39-03)
And we can tell just based on the information that we see in these three
4:39
S…
Speaker 2 (2026-04-13 00-39-03)
lines in Wireshark that this is probably going to be HTTP
4:43
S…
Speaker 2 (2026-04-13 00-39-03)
traffic because the client is starting out by sending to
4:47
S…
Speaker 2 (2026-04-13 00-39-03)
port 80 here.
4:49
S…
Speaker 2 (2026-04-13 00-39-03)
So this is probably going to be HTTP traffic.
4:53
S…
Speaker 2 (2026-04-13 00-39-03)
Again, there could be other traffic on this port.
4:56
S…
Speaker 2 (2026-04-13 00-39-03)
It depends on what normal is for this network.
5:00
S…
Speaker 1 (2026-04-13 00-39-03)
But if we expand this out a little bit,
5:01
S…
Speaker 1 (2026-04-13 00-39-03)
the very first packet expanded out in the bottom pane in Wireshark
5:06
S…
Speaker 1 (2026-04-13 00-39-03)
should look something like this.
5:08
S…
Speaker 1 (2026-04-13 00-39-03)
So we see the destination port right here going to port 80.
5:11
S…
Speaker 2 (2026-04-13 00-39-03)
Again,
5:12
S…
Speaker 1 (2026-04-13 00-39-03)
probably the start of HTTP traffic.
5:15
S…
Speaker 1 (2026-04-13 00-39-03)
We don't know for sure without additional information.
5:18
S…
Speaker 1 (2026-04-13 00-39-03)
We see the source port here is a randomly
5:23
S…
Speaker 1 (2026-04-13 00-39-03)
generated high -numbered port,
5:25
S…
Speaker 1 (2026-04-13 00-39-03)
and our reply,
5:27
S…
Speaker 1 (2026-04-13 00-39-03)
our SYN ACK packet,
5:29
S…
Speaker 1 (2026-04-13 00-39-03)
will be going back to this same port.
5:32
S…
Speaker 1 (2026-04-13 00-39-03)
And then we see the flag set down here as a SYN flag
5:36
S…
Speaker 1 (2026-04-13 00-39-03)
with that first part of the three -way handshake.
5:41
S…
Speaker 1 (2026-04-13 00-39-03)
So then our second packet,
5:42
S…
Speaker 1 (2026-04-13 00-39-03)
our reply,
5:43
S…
Speaker 1 (2026-04-13 00-39-03)
will look something like this.
5:45
S…
Speaker 1 (2026-04-13 00-39-03)
Again, the source port is going to be port 80 because that is where the
5:49
S…
Speaker 1 (2026-04-13 00-39-03)
client was sending it to the server.
5:51
S…
Speaker 1 (2026-04-13 00-39-03)
Our destination port is the randomly generated port
5:55
S…
Speaker 1 (2026-04-13 00-39-03)
that the client had that the server is replying back
5:59
S…
Speaker 1 (2026-04-13 00-39-03)
to that.
6:00
S…
Speaker 1 (2026-04-13 00-39-03)
And we see that same information here with our source and destination ports.
6:04
S…
Speaker 1 (2026-04-13 00-39-03)
And then we see our flag set here with both the SIN and
6:08
S…
Speaker 1 (2026-04-13 00-39-03)
ACK flags enabled in this reply.
6:12
S…
Speaker 1 (2026-04-13 00-39-03)
And then the final ACK reply from
6:17
S…
Speaker 1 (2026-04-13 00-39-03)
the client back to the server would look very similar.
6:20
S…
Speaker 1 (2026-04-13 00-39-03)
So we're not going to take a look at that in detail there.
6:24
S…
Speaker 1 (2026-04-13 00-39-03)
Now, here's some examples of suspicious or potentially suspicious,
6:28
S…
Speaker 1 (2026-04-13 00-39-03)
not necessarily malicious.
6:30
S…
Speaker 1 (2026-04-13 00-39-03)
Again, it's going to depend on your network.
6:34
S…
Speaker 1 (2026-04-13 00-39-03)
Now the first one we see here,
6:36
S…
Speaker 1 (2026-04-13 00-39-03)
some details here.
6:37
S…
Speaker 1 (2026-04-13 00-39-03)
We see the source here is all the same.
6:40
S…
Speaker 1 (2026-04-13 00-39-03)
These are all the same IP addresses.
6:42
S…
Speaker 1 (2026-04-13 00-39-03)
Same with the destination.
6:44
S…
Speaker 1 (2026-04-13 00-39-03)
These are all the same destination.
6:46
S…
Speaker 1 (2026-04-13 00-39-03)
So we have one machine talking to one other machine
6:50
S…
Speaker 1 (2026-04-13 00-39-03)
here.
6:50
S…
Speaker 1 (2026-04-13 00-39-03)
We see multiple different protocols being used.
6:54
S…
Speaker 1 (2026-04-13 00-39-03)
We see ICMP,
6:55
S…
Speaker 1 (2026-04-13 00-39-03)
we see TCP,
6:57
S…
Speaker 1 (2026-04-13 00-39-03)
and then more ICMP,
6:59
S…
Speaker 1 (2026-04-13 00-39-03)
but different types of ICMP.
7:01
S…
Speaker 1 (2026-04-13 00-39-03)
Those first couple lines.
7:03
S…
Speaker 1 (2026-04-13 00-39-03)
are echo requests or pings.
7:05
S…
Speaker 1 (2026-04-13 00-39-03)
The next two in gray there are requests,
7:09
S…
Speaker 1 (2026-04-13 00-39-03)
our SIN requests on port 443.
7:12
S…
Speaker 1 (2026-04-13 00-39-03)
The next few are ACK flags being
7:16
S…
Speaker 1 (2026-04-13 00-39-03)
sent on port 80,
7:18
S…
Speaker 1 (2026-04-13 00-39-03)
and the bottom four are timestamp requests.
7:21
S…
Speaker 2 (2026-04-13 00-39-03)
Now,
7:22
S…
Speaker 1 (2026-04-13 00-39-03)
this could all be normal traffic because we also see another
7:26
S…
Speaker 1 (2026-04-13 00-39-03)
context clue here is this is taking part
7:29
S…
Speaker 1 (2026-04-13 00-39-03)
occurring over a period of about 20 seconds
7:33
S…
Speaker 1 (2026-04-13 00-39-03)
or so, 19 to 20 seconds.
7:36
S…
Speaker 1 (2026-04-13 00-39-03)
So this may not be malicious,
7:38
S…
Speaker 1 (2026-04-13 00-39-03)
but it may be.
7:39
S…
Speaker 1 (2026-04-13 00-39-03)
Again, there's more context information that's needed here.
7:43
S…
Speaker 1 (2026-04-13 00-39-03)
But this could be an example of this one source machine
7:48
S…
Speaker 1 (2026-04-13 00-39-03)
trying to determine
7:50
S…
Speaker 1 (2026-04-13 00-39-03)
if this host at .115,
7:53
S…
Speaker 1 (2026-04-13 00-39-03)
the destination,
7:53
S…
Speaker 1 (2026-04-13 00-39-03)
is alive and what it's running.
7:56
S…
Speaker 1 (2026-04-13 00-39-03)
It may be trying to identify whether it's running a web server and getting
8:00
S…
Speaker 1 (2026-04-13 00-39-03)
other information from this.
8:02
S…
Speaker 1 (2026-04-13 00-39-03)
So again, context is important.
8:05
S…
Speaker 1 (2026-04-13 00-39-03)
Another example of what is almost definitely suspicious
8:09
S…
Speaker 1 (2026-04-13 00-39-03)
or malicious TCP traffic is right here.
8:12
S…
Speaker 1 (2026-04-13 00-39-03)
So we see again one source going to one destination.
8:17
S…
Speaker 1 (2026-04-13 00-39-03)
All the source IPs are the same,
8:18
S…
Speaker 1 (2026-04-13 00-39-03)
all the destination IPs are the same,
8:21
S…
Speaker 1 (2026-04-13 00-39-03)
and these are all SIN packets that are going
8:25
S…
Speaker 1 (2026-04-13 00-39-03)
to this machine.
8:26
S…
Speaker 1 (2026-04-13 00-39-03)
Now the one thing here that's telling me,
8:28
S…
Speaker 1 (2026-04-13 00-39-03)
well two things really that is telling me that this is
8:31
S…
Speaker 1 (2026-04-13 00-39-03)
Almost definitely some type of port scam is,
8:35
S…
Speaker 1 (2026-04-13 00-39-03)
number one,
8:35
S…
Speaker 1 (2026-04-13 00-39-03)
the short amount of time between all of the packets.
8:38
S…
Speaker 1 (2026-04-13 00-39-03)
All of this is taking place in
8:42
S…
Speaker 1 (2026-04-13 00-39-03)
mere milliseconds here.
8:44
S…
Speaker 1 (2026-04-13 00-39-03)
There's not even a full second between all 15 of these packets we can
8:49
S…
Speaker 2 (2026-04-13 00-39-03)
see here.
8:50
S…
Speaker 1 (2026-04-13 00-39-03)
And also the port numbers that this client is trying to reach out to are
8:54
S…
Speaker 1 (2026-04-13 00-39-03)
sequential.
8:55
S…
Speaker 1 (2026-04-13 00-39-03)
They're starting at one and just counting up,
8:58
S…
Speaker 1 (2026-04-13 00-39-03)
although we are missing number three and five in there.
9:02
S…
Speaker 1 (2026-04-13 00-39-03)
But either way,
9:03
S…
Speaker 1 (2026-04-13 00-39-03)
they're going up in order.
9:05
S…
Speaker 1 (2026-04-13 00-39-03)
They started at one.
9:06
S…
Speaker 1 (2026-04-13 00-39-03)
This does not appear to be normal traffic.
9:09
S…
Speaker 1 (2026-04-13 00-39-03)
So this would be something that should catch your eye during a
9:14
S…
Speaker 1 (2026-04-13 00-39-03)
threat hunt.
9:16
S…
Speaker 1 (2026-04-13 00-39-03)
So an example of potentially malicious or suspicious
9:20
S…
Speaker 1 (2026-04-13 00-39-03)
TCP traffic,
9:21
S…
Speaker 1 (2026-04-13 00-39-03)
and then an example of what's almost definitely going to
9:25
S…
Speaker 1 (2026-04-13 00-39-03)
be malicious or suspicious.
9:27
S…
Speaker 2 (2026-04-13 00-39-03)
Again,
9:28
S…
Speaker 1 (2026-04-13 00-39-03)
context is everything when we're trying to identify
9:32
S…
Speaker 1 (2026-04-13 00-39-03)
suspicious traffic.
9:35
S…
Speaker 1 (2026-04-13 00-39-03)
Let's take a look at ARP traffic here.
9:37
S…
Speaker 1 (2026-04-13 00-39-03)
If you're not familiar with ARP,
9:39
S…
Speaker 1 (2026-04-13 00-39-03)
ARP stands for Address Resolution Protocol.
9:41
S…
Speaker 1 (2026-04-13 00-39-03)
It is basically,
9:43
S…
Speaker 1 (2026-04-13 00-39-03)
you can think of it as the equivalent
9:47
S…
Speaker 1 (2026-04-13 00-39-03)
of basic DNS,
9:48
S…
Speaker 1 (2026-04-13 00-39-03)
but it is a layer two protocol that its sole job is
9:52
S…
Speaker 1 (2026-04-13 00-39-03)
to map IP addresses to hardware addresses or
9:56
S…
Speaker 1 (2026-04-13 00-39-03)
MAC addresses of devices on a network.
10:00
S…
Speaker 1 (2026-04-13 00-39-03)
switches,
10:00
S…
Speaker 1 (2026-04-13 00-39-03)
the routers,
10:01
S…
Speaker 1 (2026-04-13 00-39-03)
they don't know where to send these packets without having the physical address
10:06
S…
Speaker 1 (2026-04-13 00-39-03)
of where to send them to.
10:08
S…
Speaker 1 (2026-04-13 00-39-03)
So various devices will kind of build up what is known as an ARP table,
10:12
S…
Speaker 1 (2026-04-13 00-39-03)
so it knows where to route certain packets.
10:15
S…
Speaker 1 (2026-04-13 00-39-03)
So let's take a look at what is some normal ARP communication
10:19
S…
Speaker 1 (2026-04-13 00-39-03)
versus suspicious ARP communication.
10:22
S…
Speaker 1 (2026-04-13 00-39-03)
Number one,
10:23
S…
Speaker 1 (2026-04-13 00-39-03)
we see that ARP broadcasts should go out at a reasonable rate.
10:26
S…
Speaker 1 (2026-04-13 00-39-03)
Again, reasonable is going to be subjective.
10:29
S…
Speaker 1 (2026-04-13 00-39-03)
based on your network.
10:31
S…
Speaker 1 (2026-04-13 00-39-03)
It is normal to see even a large amount of ARP broadcasts,
10:36
S…
Speaker 1 (2026-04-13 00-39-03)
and they are broadcast because,
10:37
S…
Speaker 1 (2026-04-13 00-39-03)
again, the nodes on the network don't know exactly where
10:41
S…
Speaker 1 (2026-04-13 00-39-03)
these devices live.
10:42
S…
Speaker 1 (2026-04-13 00-39-03)
They're trying to figure it out,
10:43
S…
Speaker 1 (2026-04-13 00-39-03)
so they have to send a broadcast out to the entire subnet to figure out
10:48
S…
Speaker 1 (2026-04-13 00-39-03)
where the device is.
10:49
S…
Speaker 1 (2026-04-13 00-39-03)
So all ARP requests are going to be broadcast.
10:53
S…
Speaker 1 (2026-04-13 00-39-03)
Responses go back to an individual device that
10:57
S…
Speaker 1 (2026-04-13 00-39-03)
sent the request.
10:59
S…
Speaker 1 (2026-04-13 00-39-03)
So they should occur at a reasonable rate.
11:02
S…
Speaker 1 (2026-04-13 00-39-03)
Again, reasonable depends on the network you're on.
11:05
S…
Speaker 1 (2026-04-13 00-39-03)
Suspicious is going to be seeing hundreds or thousands of
11:09
S…
Speaker 1 (2026-04-13 00-39-03)
ARP requests in a very
11:13
S…
Speaker 1 (2026-04-13 00-39-03)
small amount of time.
11:15
S…
Speaker 1 (2026-04-13 00-39-03)
That can be an example of some sort of attack.
11:18
S…
Speaker 1 (2026-04-13 00-39-03)
Normally you're going to see the response immediately
11:23
S…
Speaker 1 (2026-04-13 00-39-03)
following the request.
11:25
S…
Speaker 1 (2026-04-13 00-39-03)
If you see a response without a request or a
11:29
S…
Speaker 1 (2026-04-13 00-39-03)
reply without a request,
11:31
S…
Speaker 1 (2026-04-13 00-39-03)
that is what we call a gratuitous ARP reply.
11:34
S…
Speaker 1 (2026-04-13 00-39-03)
Basically,
11:35
S…
Speaker 1 (2026-04-13 00-39-03)
an unsolicited ARP reply,
11:38
S…
Speaker 1 (2026-04-13 00-39-03)
reply without a request.
11:40
S…
Speaker 1 (2026-04-13 00-39-03)
This can be done as something like an ARP
11:44
S…
Speaker 1 (2026-04-13 00-39-03)
poisoning attack,
11:45
S…
Speaker 1 (2026-04-13 00-39-03)
which is where an attacker tries to force a client to have multiple
11:50
S…
Speaker 1 (2026-04-13 00-39-03)
different fake or malicious ARP entries.
11:53
S…
Speaker 1 (2026-04-13 00-39-03)
essentially telling that client,
11:55
S…
Speaker 1 (2026-04-13 00-39-03)
hey, all of these IP addresses all point back to my
11:59
S…
Speaker 1 (2026-04-13 00-39-03)
attacker -controlled machine.
12:01
S…
Speaker 1 (2026-04-13 00-39-03)
So it's sending out all of these ARP replies without any requests.
12:05
S…
Speaker 1 (2026-04-13 00-39-03)
Another possible suspicious bit of ARP traffic would be
12:09
S…
Speaker 1 (2026-04-13 00-39-03)
if you have responses that have identical MAC addresses,
12:14
S…
Speaker 1 (2026-04-13 00-39-03)
but with different IP addresses.
12:16
S…
Speaker 1 (2026-04-13 00-39-03)
Again, this can be tied in with the gratuitous ARP
12:21
S…
Speaker 2 (2026-04-13 00-39-03)
replies.
12:21
S…
Speaker 1 (2026-04-13 00-39-03)
And it's basically another way for it's an indicator that
12:25
S…
Speaker 1 (2026-04-13 00-39-03)
there may be an attacker on the machine trying to reroute
12:30
S…
Speaker 2 (2026-04-13 00-39-03)
traffic.
12:31
S…
Speaker 1 (2026-04-13 00-39-03)
Again, suspicious is going to be determined based on your
12:35
S…
Speaker 1 (2026-04-13 00-39-03)
network specifically.
12:37
S…
Speaker 1 (2026-04-13 00-39-03)
So normal traffic in Wireshark,
12:41
S…
Speaker 1 (2026-04-13 00-39-03)
normal ARP traffic looks like this.
12:43
S…
Speaker 1 (2026-04-13 00-39-03)
You have the request where you have the client
12:47
S…
Speaker 1 (2026-04-13 00-39-03)
is essentially asking,
12:48
S…
Speaker 1 (2026-04-13 00-39-03)
hey, who has this IP address?
12:50
S…
Speaker 1 (2026-04-13 00-39-03)
Please tell me.
12:52
S…
Speaker 1 (2026-04-13 00-39-03)
And that is a broadcast packet.
12:54
S…
Speaker 1 (2026-04-13 00-39-03)
We will see that in the next bit here.
12:57
S…
Speaker 1 (2026-04-13 00-39-03)
And then whoever does have that IP address says,
13:00
S…
Speaker 1 (2026-04-13 00-39-03)
hey, I am at this MAC address right here.
13:03
S…
Speaker 1 (2026-04-13 00-39-03)
That's where you can find me.
13:05
S…
Speaker 1 (2026-04-13 00-39-03)
That is the entirety of ARP communication,
13:08
S…
Speaker 1 (2026-04-13 00-39-03)
a broadcast request followed by a reply,
13:12
S…
Speaker 1 (2026-04-13 00-39-03)
assuming that there is anything listening at that IP address.
13:16
S…
Speaker 1 (2026-04-13 00-39-03)
If there's not, you're not going to see a reply.
13:19
S…
Speaker 1 (2026-04-13 00-39-03)
So the request looks like this in more detail.
13:22
S…
Speaker 1 (2026-04-13 00-39-03)
Again, the destination is going to be a broadcast
13:26
S…
Speaker 1 (2026-04-13 00-39-03)
MAC address because whatever node is requesting it doesn't know
13:31
S…
Speaker 1 (2026-04-13 00-39-03)
where to find this device on the network.
13:33
S…
Speaker 1 (2026-04-13 00-39-03)
So it has to ask everything on the network.
13:35
S…
Speaker 1 (2026-04-13 00-39-03)
So it is sent as a broadcast.
13:37
S…
Speaker 2 (2026-04-13 00-39-03)
Again,
13:38
S…
Speaker 1 (2026-04-13 00-39-03)
doesn't know where it's sending it.
13:40
S…
Speaker 1 (2026-04-13 00-39-03)
So the target MAC address here in here is going to be blank because
13:44
S…
Speaker 1 (2026-04-13 00-39-03)
it doesn't know what the MAC address is.
13:46
S…
Speaker 1 (2026-04-13 00-39-03)
That's what's trying to figure out.
13:48
S…
Speaker 1 (2026-04-13 00-39-03)
The reply looks like this.
13:50
S…
Speaker 1 (2026-04-13 00-39-03)
So it goes back to the destination here is not a broadcast
13:54
S…
Speaker 2 (2026-04-13 00-39-03)
address.
13:55
S…
Speaker 1 (2026-04-13 00-39-03)
The destination is the MAC address of whatever
13:59
S…
Speaker 1 (2026-04-13 00-39-03)
system was requesting the information,
14:03
S…
Speaker 1 (2026-04-13 00-39-03)
whatever system sent the ARP request.
14:06
S…
Speaker 1 (2026-04-13 00-39-03)
And the reply contains the MAC address
14:10
S…
Speaker 1 (2026-04-13 00-39-03)
of whatever they were trying to figure out of.
14:14
S…
Speaker 1 (2026-04-13 00-39-03)
Whoever is sending this reply,
14:15
S…
Speaker 1 (2026-04-13 00-39-03)
that MAC address is sent in there.
14:17
S…
Speaker 2 (2026-04-13 00-39-03)
And again,
14:18
S…
Speaker 1 (2026-04-13 00-39-03)
that is the entirety of ARP communication.
14:20
S…
Speaker 1 (2026-04-13 00-39-03)
You have a request followed by a response or reply.
14:24
S…
Speaker 1 (2026-04-13 00-39-03)
And it looks a bit more like this in the details section in
14:28
S…
Speaker 1 (2026-04-13 00-39-03)
Wireshark.
14:30
S…
Speaker 1 (2026-04-13 00-39-03)
There's a couple different ways that suspicious ARP traffic can
14:34
S…
Speaker 1 (2026-04-13 00-39-03)
show up.
14:35
S…
Speaker 1 (2026-04-13 00-39-03)
Now this first one may or may not be suspicious.
14:39
S…
Speaker 1 (2026-04-13 00-39-03)
We see the source here.
14:41
S…
Speaker 1 (2026-04-13 00-39-03)
Wireshark is identifying it through its internal MAC address information
14:45
S…
Speaker 1 (2026-04-13 00-39-03)
it has in its database as a possible Cisco device.
14:49
S…
Speaker 1 (2026-04-13 00-39-03)
So we have one device.
14:51
S…
Speaker 1 (2026-04-13 00-39-03)
That is sending out a series of ARP requests asking for
14:55
S…
Speaker 1 (2026-04-13 00-39-03)
information about multiple different IP addresses on the network.
14:59
S…
Speaker 1 (2026-04-13 00-39-03)
So how do we know whether this is going to be suspicious or
15:03
S…
Speaker 1 (2026-04-13 00-39-03)
not? Well, first of all,
15:04
S…
Speaker 1 (2026-04-13 00-39-03)
do we have Cisco devices on our network?
15:08
S…
Speaker 1 (2026-04-13 00-39-03)
Are we running any Cisco equipment?
15:10
S…
Speaker 1 (2026-04-13 00-39-03)
If we are,
15:11
S…
Speaker 1 (2026-04-13 00-39-03)
then this could be legitimate.
15:12
S…
Speaker 1 (2026-04-13 00-39-03)
If we're not,
15:13
S…
Speaker 1 (2026-04-13 00-39-03)
probably is suspicious or malicious.
15:16
S…
Speaker 1 (2026-04-13 00-39-03)
Is this Cisco equipment?
15:18
S…
Speaker 1 (2026-04-13 00-39-03)
If we do have it,
15:19
S…
Speaker 1 (2026-04-13 00-39-03)
is it potentially misconfigured?
15:21
S…
Speaker 1 (2026-04-13 00-39-03)
Or is this just a router that's handling a lot of traffic and
15:25
S…
Speaker 1 (2026-04-13 00-39-03)
this is completely normal?
15:27
S…
Speaker 1 (2026-04-13 00-39-03)
This is again where the context comes in.
15:30
S…
Speaker 1 (2026-04-13 00-39-03)
So this first example here might be malicious or it might be
15:34
S…
Speaker 1 (2026-04-13 00-39-03)
perfectly normal.
15:35
S…
Speaker 1 (2026-04-13 00-39-03)
All depends on what the baseline is for the network.
15:40
S…
Speaker 1 (2026-04-13 00-39-03)
This second one here is like we've seen previously with our port scans
15:44
S…
Speaker 1 (2026-04-13 00-39-03)
when looking at TCP.
15:45
S…
Speaker 1 (2026-04-13 00-39-03)
This one is almost certainly going to be malicious
15:50
S…
Speaker 2 (2026-04-13 00-39-03)
here.
15:50
S…
Speaker 1 (2026-04-13 00-39-03)
The indicators here of why this could potentially be
15:55
S…
Speaker 1 (2026-04-13 00-39-03)
malicious, number one,
15:56
S…
Speaker 1 (2026-04-13 00-39-03)
the short amount of time between all of these requests.
16:00
S…
Speaker 1 (2026-04-13 00-39-03)
Again, we're talking about less than a second.
16:03
S…
Speaker 1 (2026-04-13 00-39-03)
We look about roughly a half second between all of these
16:07
S…
Speaker 1 (2026-04-13 00-39-03)
requests here.
16:08
S…
Speaker 1 (2026-04-13 00-39-03)
And the other indication here is that again the IP addresses
16:12
S…
Speaker 1 (2026-04-13 00-39-03)
are incrementing.
16:14
S…
Speaker 1 (2026-04-13 00-39-03)
We're starting at one and basically counting up.
16:17
S…
Speaker 1 (2026-04-13 00-39-03)
So this is an indicator of some machine possibly trying
16:22
S…
Speaker 1 (2026-04-13 00-39-03)
to map out the network,
16:24
S…
Speaker 1 (2026-04-13 00-39-03)
trying to figure out what devices are alive on the network
16:28
S…
Speaker 1 (2026-04-13 00-39-03)
and where they might be on the network,
16:30
S…
Speaker 1 (2026-04-13 00-39-03)
where they can be reached.
16:31
S…
Speaker 2 (2026-04-13 00-39-03)
Again,
16:32
S…
Speaker 1 (2026-04-13 00-39-03)
this does not look like a very legitimate usage
16:36
S…
Speaker 1 (2026-04-13 00-39-03)
of ARP.
16:38
S…
Speaker 1 (2026-04-13 00-39-03)
So we've taken a look at some suspicious TCP.
16:42
S…
Speaker 1 (2026-04-13 00-39-03)
and ARP traffic in this video.
16:45
S…
Speaker 1 (2026-04-13 00-39-03)
Next we're going to take a look at ICMP and DHCP.
ཡིག་སྒྱུར་འདི་ བཅོས་མའི་བློ་རིག་ (སྒྲ་ངོས་འཛིན་བྱེད་པའི་འཕྲུལ་རིག་) གིས་བཟོ་སྟེ་ཡོདཔ་ཨིན། འཛོལ་བ་འབྱུང་སྲིད་པ་ལ་ — གལ་སྲིད་ཁག་ཆེ་བའི་དོན་ལས་ ངོ་མ་གི་སྒྲ་སྐད་དང་འཕྱད་ཞིབ་འབད་དགོཔ་ཨིན། བཅོས་མའི་བློ་རིག་གི་སྲིད་བྱུས་
བཅུད་དོན་
ཡིག་ཆ་འདི་གི་ AI བཅུད་བསྡུ་ཐོན་ནི་གི་དོན་ལས་ བཅུད་བསྡུ་ ཟེར་བའི་བསྒང་འདི་བསྒང་བསྒ
དྲན་ཐོ་བསྡུ་གསོག...
དྲན་ཤེས་ལ་དྲི་བ་དྲིས་ལན་ཞུ།
ཡིག་ཆ་འདི་གི་སྐོར་ལ་དྲི་བ་ཅི་རིགས་ཞུས་ནའང་ བཅོས་མའི་བློ་རིག་གིས་ འབྲེལ་བ་ཡོད་པའི་དོན་ཚན་ཚུ་ འཚོལ་ཞིབ་ དང་ལན་འདེབས་ འབད་འོང་།