מציג בלבד
0:10
S… Speaker 2 (2026-04-13 00-39-03)
When performing threat hunts,
0:12
S… Speaker 2 (2026-04-13 00-39-03)
it's very important to be able to know what
0:16
S… Speaker 2 (2026-04-13 00-39-03)
abnormal traffic looks like.
0:19
S… Speaker 2 (2026-04-13 00-39-03)
So in the next few videos here,
0:21
S… Speaker 2 (2026-04-13 00-39-03)
we're going to take a look at some examples of different types
0:25
S… Speaker 2 (2026-04-13 00-39-03)
of normal versus abnormal traffic.
0:28
S… Speaker 2 (2026-04-13 00-39-03)
We're going to start off by looking at both ARP packets and TCP
0:33
S… Speaker 1 (2026-04-13 00-39-03)
traffic.
0:34
S… Speaker 2 (2026-04-13 00-39-03)
Then we're going to look at ICMP,
0:36
S… Speaker 2 (2026-04-13 00-39-03)
ping requests and replies.
0:39
S… Speaker 2 (2026-04-13 00-39-03)
DHCP traffic.
0:40
S… Speaker 2 (2026-04-13 00-39-03)
We're also going to look at HTTP,
0:43
S… Speaker 2 (2026-04-13 00-39-03)
HTTPS traffic,
0:45
S… Speaker 2 (2026-04-13 00-39-03)
as well as DNS to try and identify what
0:50
S… Speaker 2 (2026-04-13 00-39-03)
is normal and what is suspicious or abnormal traffic.
0:54
S… Speaker 2 (2026-04-13 00-39-03)
Now, a lot of the abnormal or suspicious traffic is going to
0:59
S… Speaker 2 (2026-04-13 00-39-03)
depend a little bit on what the network is.
1:01
S… Speaker 2 (2026-04-13 00-39-03)
What are the baselines in the network?
1:03
S… Speaker 2 (2026-04-13 00-39-03)
What is normal in the network?
1:05
S… Speaker 2 (2026-04-13 00-39-03)
Some things that may look suspicious on one network may be perfectly
1:09
S… Speaker 2 (2026-04-13 00-39-03)
normal on another network,
1:11
S… Speaker 2 (2026-04-13 00-39-03)
which is why you hear me talk about this all the time.
1:14
S… Speaker 2 (2026-04-13 00-39-03)
Knowing your baselines,
1:16
S… Speaker 2 (2026-04-13 00-39-03)
knowing what's normal in your specific environment is a critical
1:20
S… Speaker 2 (2026-04-13 00-39-03)
piece of information.
1:22
S… Speaker 2 (2026-04-13 00-39-03)
when we're talking about threat hunting.
1:24
S… Speaker 2 (2026-04-13 00-39-03)
So let's go ahead and start looking at TCP traffic and
1:28
S… Speaker 2 (2026-04-13 00-39-03)
what normal with TCP looks like.
1:31
S… Speaker 2 (2026-04-13 00-39-03)
Now with TCP,
1:32
S… Speaker 2 (2026-04-13 00-39-03)
we have our three -way handshake.
1:35
S… Speaker 2 (2026-04-13 00-39-03)
This is communication between a client and a server in
1:39
S… Speaker 1 (2026-04-13 00-39-03)
this case.
1:40
S… Speaker 2 (2026-04-13 00-39-03)
And this is how all TCP traffic starts with that three -way
1:44
S… Speaker 1 (2026-04-13 00-39-03)
handshake.
1:45
S… Speaker 2 (2026-04-13 00-39-03)
The client starts out by sending a SIN packet or a
1:49
S… Speaker 2 (2026-04-13 00-39-03)
TCP packet with the SIN flag turned on
1:53
S… Speaker 2 (2026-04-13 00-39-03)
to the server it's trying to talk to.
1:57
S… Speaker 2 (2026-04-13 00-39-03)
And this is the initiation of the TCP communication.
2:01
S… Speaker 2 (2026-04-13 00-39-03)
Assuming the client is listening and responds,
2:04
S… Speaker 2 (2026-04-13 00-39-03)
it sends back a SIN and ACK.
2:08
S… Speaker 2 (2026-04-13 00-39-03)
packet or a TCP packet with the SIN and ACK flags
2:12
S… Speaker 1 (2026-04-13 00-39-03)
turned on.
2:13
S… Speaker 2 (2026-04-13 00-39-03)
And then to finish out the three -way handshake,
2:16
S… Speaker 2 (2026-04-13 00-39-03)
the client then sends back a TCP packet with the ACK
2:20
S… Speaker 1 (2026-04-13 00-39-03)
flag enabled.
2:22
S… Speaker 2 (2026-04-13 00-39-03)
So that is what we are talking about when we're talking about the three -way handshake
2:26
S… Speaker 1 (2026-04-13 00-39-03)
with TCP.
2:27
S… Speaker 2 (2026-04-13 00-39-03)
And this is how all TCP...
2:29
S… Speaker 2 (2026-04-13 00-39-03)
All legitimate TCP traffic should start
2:33
S… Speaker 2 (2026-04-13 00-39-03)
out with, with this three -way handshake,
2:35
S… Speaker 2 (2026-04-13 00-39-03)
SIN, SIN,
2:36
S… Speaker 2 (2026-04-13 00-39-03)
ACK, and ACK in three different packets back
2:40
S… Speaker 1 (2026-04-13 00-39-03)
and forth.
2:41
S… Speaker 2 (2026-04-13 00-39-03)
So comparing normal versus suspicious TCP traffic,
2:45
S… Speaker 2 (2026-04-13 00-39-03)
we know that normal traffic is going to have that three -way handshake.
2:50
S… Speaker 2 (2026-04-13 00-39-03)
There's a number of different types of suspicious
2:54
S… Speaker 2 (2026-04-13 00-39-03)
TCP traffic that we can see.
2:57
S… Speaker 2 (2026-04-13 00-39-03)
Number one would be a lot of SIN
3:01
S… Speaker 2 (2026-04-13 00-39-03)
packets with no corresponding SIN ACK or ACK packets
3:05
S… Speaker 2 (2026-04-13 00-39-03)
being sent with that three -way handshake.
3:08
S… Speaker 2 (2026-04-13 00-39-03)
And this can be an example of port scanning or a ping sweep
3:12
S… Speaker 2 (2026-04-13 00-39-03)
or anything like that.
3:14
S… Speaker 2 (2026-04-13 00-39-03)
some sort of scanning by an attacker,
3:17
S… Speaker 2 (2026-04-13 00-39-03)
or it could be a legitimate purpose for a scan.
3:20
S… Speaker 2 (2026-04-13 00-39-03)
But that is still could be suspicious depending on the network.
3:24
S… Speaker 2 (2026-04-13 00-39-03)
You can also have TCP packets that are sent
3:28
S… Speaker 2 (2026-04-13 00-39-03)
with a different combination of flags.
3:31
S… Speaker 2 (2026-04-13 00-39-03)
And these different flags can be commonly abused
3:36
S… Speaker 2 (2026-04-13 00-39-03)
to try and carry out scans against
3:40
S… Speaker 1 (2026-04-13 00-39-03)
a network.
3:41
S… Speaker 2 (2026-04-13 00-39-03)
and kind of ways of avoiding detection of those scans.
3:46
S… Speaker 2 (2026-04-13 00-39-03)
And you can also have examples of maybe a single
3:50
S… Speaker 2 (2026-04-13 00-39-03)
host sending multiple packets to multiple
3:55
S… Speaker 2 (2026-04-13 00-39-03)
different ports on a server.
3:57
S… Speaker 2 (2026-04-13 00-39-03)
Or a single host sending multiple TCP packets,
4:03
S… Speaker 1 (2026-04-13 00-39-03)
there we go,
4:04
S… Speaker 2 (2026-04-13 00-39-03)
to multiple other systems on a network.
4:08
S… Speaker 2 (2026-04-13 00-39-03)
And those are both examples of scanning as well.
4:11
S… Speaker 2 (2026-04-13 00-39-03)
So looking at TCP in Wireshark,
4:15
S… Speaker 2 (2026-04-13 00-39-03)
normal traffic will look like this.
4:18
S… Speaker 2 (2026-04-13 00-39-03)
We start off with the SIN packet right here as
4:22
S… Speaker 2 (2026-04-13 00-39-03)
the very first packet the client sends.
4:25
S… Speaker 2 (2026-04-13 00-39-03)
If the server is listening and responding,
4:28
S… Speaker 2 (2026-04-13 00-39-03)
it sends the SYN ACK,
4:30
S… Speaker 2 (2026-04-13 00-39-03)
and then the client finishes out the three -way handshake with the ACK packet
4:34
S… Speaker 1 (2026-04-13 00-39-03)
right there.
4:35
S… Speaker 2 (2026-04-13 00-39-03)
And we can tell just based on the information that we see in these three
4:39
S… Speaker 2 (2026-04-13 00-39-03)
lines in Wireshark that this is probably going to be HTTP
4:43
S… Speaker 2 (2026-04-13 00-39-03)
traffic because the client is starting out by sending to
4:47
S… Speaker 2 (2026-04-13 00-39-03)
port 80 here.
4:49
S… Speaker 2 (2026-04-13 00-39-03)
So this is probably going to be HTTP traffic.
4:53
S… Speaker 2 (2026-04-13 00-39-03)
Again, there could be other traffic on this port.
4:56
S… Speaker 2 (2026-04-13 00-39-03)
It depends on what normal is for this network.
5:00
S… Speaker 1 (2026-04-13 00-39-03)
But if we expand this out a little bit,
5:01
S… Speaker 1 (2026-04-13 00-39-03)
the very first packet expanded out in the bottom pane in Wireshark
5:06
S… Speaker 1 (2026-04-13 00-39-03)
should look something like this.
5:08
S… Speaker 1 (2026-04-13 00-39-03)
So we see the destination port right here going to port 80.
5:11
S… Speaker 2 (2026-04-13 00-39-03)
Again,
5:12
S… Speaker 1 (2026-04-13 00-39-03)
probably the start of HTTP traffic.
5:15
S… Speaker 1 (2026-04-13 00-39-03)
We don't know for sure without additional information.
5:18
S… Speaker 1 (2026-04-13 00-39-03)
We see the source port here is a randomly
5:23
S… Speaker 1 (2026-04-13 00-39-03)
generated high -numbered port,
5:25
S… Speaker 1 (2026-04-13 00-39-03)
and our reply,
5:27
S… Speaker 1 (2026-04-13 00-39-03)
our SYN ACK packet,
5:29
S… Speaker 1 (2026-04-13 00-39-03)
will be going back to this same port.
5:32
S… Speaker 1 (2026-04-13 00-39-03)
And then we see the flag set down here as a SYN flag
5:36
S… Speaker 1 (2026-04-13 00-39-03)
with that first part of the three -way handshake.
5:41
S… Speaker 1 (2026-04-13 00-39-03)
So then our second packet,
5:42
S… Speaker 1 (2026-04-13 00-39-03)
our reply,
5:43
S… Speaker 1 (2026-04-13 00-39-03)
will look something like this.
5:45
S… Speaker 1 (2026-04-13 00-39-03)
Again, the source port is going to be port 80 because that is where the
5:49
S… Speaker 1 (2026-04-13 00-39-03)
client was sending it to the server.
5:51
S… Speaker 1 (2026-04-13 00-39-03)
Our destination port is the randomly generated port
5:55
S… Speaker 1 (2026-04-13 00-39-03)
that the client had that the server is replying back
5:59
S… Speaker 1 (2026-04-13 00-39-03)
to that.
6:00
S… Speaker 1 (2026-04-13 00-39-03)
And we see that same information here with our source and destination ports.
6:04
S… Speaker 1 (2026-04-13 00-39-03)
And then we see our flag set here with both the SIN and
6:08
S… Speaker 1 (2026-04-13 00-39-03)
ACK flags enabled in this reply.
6:12
S… Speaker 1 (2026-04-13 00-39-03)
And then the final ACK reply from
6:17
S… Speaker 1 (2026-04-13 00-39-03)
the client back to the server would look very similar.
6:20
S… Speaker 1 (2026-04-13 00-39-03)
So we're not going to take a look at that in detail there.
6:24
S… Speaker 1 (2026-04-13 00-39-03)
Now, here's some examples of suspicious or potentially suspicious,
6:28
S… Speaker 1 (2026-04-13 00-39-03)
not necessarily malicious.
6:30
S… Speaker 1 (2026-04-13 00-39-03)
Again, it's going to depend on your network.
6:34
S… Speaker 1 (2026-04-13 00-39-03)
Now the first one we see here,
6:36
S… Speaker 1 (2026-04-13 00-39-03)
some details here.
6:37
S… Speaker 1 (2026-04-13 00-39-03)
We see the source here is all the same.
6:40
S… Speaker 1 (2026-04-13 00-39-03)
These are all the same IP addresses.
6:42
S… Speaker 1 (2026-04-13 00-39-03)
Same with the destination.
6:44
S… Speaker 1 (2026-04-13 00-39-03)
These are all the same destination.
6:46
S… Speaker 1 (2026-04-13 00-39-03)
So we have one machine talking to one other machine
6:50
S… Speaker 1 (2026-04-13 00-39-03)
here.
6:50
S… Speaker 1 (2026-04-13 00-39-03)
We see multiple different protocols being used.
6:54
S… Speaker 1 (2026-04-13 00-39-03)
We see ICMP,
6:55
S… Speaker 1 (2026-04-13 00-39-03)
we see TCP,
6:57
S… Speaker 1 (2026-04-13 00-39-03)
and then more ICMP,
6:59
S… Speaker 1 (2026-04-13 00-39-03)
but different types of ICMP.
7:01
S… Speaker 1 (2026-04-13 00-39-03)
Those first couple lines.
7:03
S… Speaker 1 (2026-04-13 00-39-03)
are echo requests or pings.
7:05
S… Speaker 1 (2026-04-13 00-39-03)
The next two in gray there are requests,
7:09
S… Speaker 1 (2026-04-13 00-39-03)
our SIN requests on port 443.
7:12
S… Speaker 1 (2026-04-13 00-39-03)
The next few are ACK flags being
7:16
S… Speaker 1 (2026-04-13 00-39-03)
sent on port 80,
7:18
S… Speaker 1 (2026-04-13 00-39-03)
and the bottom four are timestamp requests.
7:21
S… Speaker 2 (2026-04-13 00-39-03)
Now,
7:22
S… Speaker 1 (2026-04-13 00-39-03)
this could all be normal traffic because we also see another
7:26
S… Speaker 1 (2026-04-13 00-39-03)
context clue here is this is taking part
7:29
S… Speaker 1 (2026-04-13 00-39-03)
occurring over a period of about 20 seconds
7:33
S… Speaker 1 (2026-04-13 00-39-03)
or so, 19 to 20 seconds.
7:36
S… Speaker 1 (2026-04-13 00-39-03)
So this may not be malicious,
7:38
S… Speaker 1 (2026-04-13 00-39-03)
but it may be.
7:39
S… Speaker 1 (2026-04-13 00-39-03)
Again, there's more context information that's needed here.
7:43
S… Speaker 1 (2026-04-13 00-39-03)
But this could be an example of this one source machine
7:48
S… Speaker 1 (2026-04-13 00-39-03)
trying to determine
7:50
S… Speaker 1 (2026-04-13 00-39-03)
if this host at .115,
7:53
S… Speaker 1 (2026-04-13 00-39-03)
the destination,
7:53
S… Speaker 1 (2026-04-13 00-39-03)
is alive and what it's running.
7:56
S… Speaker 1 (2026-04-13 00-39-03)
It may be trying to identify whether it's running a web server and getting
8:00
S… Speaker 1 (2026-04-13 00-39-03)
other information from this.
8:02
S… Speaker 1 (2026-04-13 00-39-03)
So again, context is important.
8:05
S… Speaker 1 (2026-04-13 00-39-03)
Another example of what is almost definitely suspicious
8:09
S… Speaker 1 (2026-04-13 00-39-03)
or malicious TCP traffic is right here.
8:12
S… Speaker 1 (2026-04-13 00-39-03)
So we see again one source going to one destination.
8:17
S… Speaker 1 (2026-04-13 00-39-03)
All the source IPs are the same,
8:18
S… Speaker 1 (2026-04-13 00-39-03)
all the destination IPs are the same,
8:21
S… Speaker 1 (2026-04-13 00-39-03)
and these are all SIN packets that are going
8:25
S… Speaker 1 (2026-04-13 00-39-03)
to this machine.
8:26
S… Speaker 1 (2026-04-13 00-39-03)
Now the one thing here that's telling me,
8:28
S… Speaker 1 (2026-04-13 00-39-03)
well two things really that is telling me that this is
8:31
S… Speaker 1 (2026-04-13 00-39-03)
Almost definitely some type of port scam is,
8:35
S… Speaker 1 (2026-04-13 00-39-03)
number one,
8:35
S… Speaker 1 (2026-04-13 00-39-03)
the short amount of time between all of the packets.
8:38
S… Speaker 1 (2026-04-13 00-39-03)
All of this is taking place in
8:42
S… Speaker 1 (2026-04-13 00-39-03)
mere milliseconds here.
8:44
S… Speaker 1 (2026-04-13 00-39-03)
There's not even a full second between all 15 of these packets we can
8:49
S… Speaker 2 (2026-04-13 00-39-03)
see here.
8:50
S… Speaker 1 (2026-04-13 00-39-03)
And also the port numbers that this client is trying to reach out to are
8:54
S… Speaker 1 (2026-04-13 00-39-03)
sequential.
8:55
S… Speaker 1 (2026-04-13 00-39-03)
They're starting at one and just counting up,
8:58
S… Speaker 1 (2026-04-13 00-39-03)
although we are missing number three and five in there.
9:02
S… Speaker 1 (2026-04-13 00-39-03)
But either way,
9:03
S… Speaker 1 (2026-04-13 00-39-03)
they're going up in order.
9:05
S… Speaker 1 (2026-04-13 00-39-03)
They started at one.
9:06
S… Speaker 1 (2026-04-13 00-39-03)
This does not appear to be normal traffic.
9:09
S… Speaker 1 (2026-04-13 00-39-03)
So this would be something that should catch your eye during a
9:14
S… Speaker 1 (2026-04-13 00-39-03)
threat hunt.
9:16
S… Speaker 1 (2026-04-13 00-39-03)
So an example of potentially malicious or suspicious
9:20
S… Speaker 1 (2026-04-13 00-39-03)
TCP traffic,
9:21
S… Speaker 1 (2026-04-13 00-39-03)
and then an example of what's almost definitely going to
9:25
S… Speaker 1 (2026-04-13 00-39-03)
be malicious or suspicious.
9:27
S… Speaker 2 (2026-04-13 00-39-03)
Again,
9:28
S… Speaker 1 (2026-04-13 00-39-03)
context is everything when we're trying to identify
9:32
S… Speaker 1 (2026-04-13 00-39-03)
suspicious traffic.
9:35
S… Speaker 1 (2026-04-13 00-39-03)
Let's take a look at ARP traffic here.
9:37
S… Speaker 1 (2026-04-13 00-39-03)
If you're not familiar with ARP,
9:39
S… Speaker 1 (2026-04-13 00-39-03)
ARP stands for Address Resolution Protocol.
9:41
S… Speaker 1 (2026-04-13 00-39-03)
It is basically,
9:43
S… Speaker 1 (2026-04-13 00-39-03)
you can think of it as the equivalent
9:47
S… Speaker 1 (2026-04-13 00-39-03)
of basic DNS,
9:48
S… Speaker 1 (2026-04-13 00-39-03)
but it is a layer two protocol that its sole job is
9:52
S… Speaker 1 (2026-04-13 00-39-03)
to map IP addresses to hardware addresses or
9:56
S… Speaker 1 (2026-04-13 00-39-03)
MAC addresses of devices on a network.
10:00
S… Speaker 1 (2026-04-13 00-39-03)
switches,
10:00
S… Speaker 1 (2026-04-13 00-39-03)
the routers,
10:01
S… Speaker 1 (2026-04-13 00-39-03)
they don't know where to send these packets without having the physical address
10:06
S… Speaker 1 (2026-04-13 00-39-03)
of where to send them to.
10:08
S… Speaker 1 (2026-04-13 00-39-03)
So various devices will kind of build up what is known as an ARP table,
10:12
S… Speaker 1 (2026-04-13 00-39-03)
so it knows where to route certain packets.
10:15
S… Speaker 1 (2026-04-13 00-39-03)
So let's take a look at what is some normal ARP communication
10:19
S… Speaker 1 (2026-04-13 00-39-03)
versus suspicious ARP communication.
10:22
S… Speaker 1 (2026-04-13 00-39-03)
Number one,
10:23
S… Speaker 1 (2026-04-13 00-39-03)
we see that ARP broadcasts should go out at a reasonable rate.
10:26
S… Speaker 1 (2026-04-13 00-39-03)
Again, reasonable is going to be subjective.
10:29
S… Speaker 1 (2026-04-13 00-39-03)
based on your network.
10:31
S… Speaker 1 (2026-04-13 00-39-03)
It is normal to see even a large amount of ARP broadcasts,
10:36
S… Speaker 1 (2026-04-13 00-39-03)
and they are broadcast because,
10:37
S… Speaker 1 (2026-04-13 00-39-03)
again, the nodes on the network don't know exactly where
10:41
S… Speaker 1 (2026-04-13 00-39-03)
these devices live.
10:42
S… Speaker 1 (2026-04-13 00-39-03)
They're trying to figure it out,
10:43
S… Speaker 1 (2026-04-13 00-39-03)
so they have to send a broadcast out to the entire subnet to figure out
10:48
S… Speaker 1 (2026-04-13 00-39-03)
where the device is.
10:49
S… Speaker 1 (2026-04-13 00-39-03)
So all ARP requests are going to be broadcast.
10:53
S… Speaker 1 (2026-04-13 00-39-03)
Responses go back to an individual device that
10:57
S… Speaker 1 (2026-04-13 00-39-03)
sent the request.
10:59
S… Speaker 1 (2026-04-13 00-39-03)
So they should occur at a reasonable rate.
11:02
S… Speaker 1 (2026-04-13 00-39-03)
Again, reasonable depends on the network you're on.
11:05
S… Speaker 1 (2026-04-13 00-39-03)
Suspicious is going to be seeing hundreds or thousands of
11:09
S… Speaker 1 (2026-04-13 00-39-03)
ARP requests in a very
11:13
S… Speaker 1 (2026-04-13 00-39-03)
small amount of time.
11:15
S… Speaker 1 (2026-04-13 00-39-03)
That can be an example of some sort of attack.
11:18
S… Speaker 1 (2026-04-13 00-39-03)
Normally you're going to see the response immediately
11:23
S… Speaker 1 (2026-04-13 00-39-03)
following the request.
11:25
S… Speaker 1 (2026-04-13 00-39-03)
If you see a response without a request or a
11:29
S… Speaker 1 (2026-04-13 00-39-03)
reply without a request,
11:31
S… Speaker 1 (2026-04-13 00-39-03)
that is what we call a gratuitous ARP reply.
11:34
S… Speaker 1 (2026-04-13 00-39-03)
Basically,
11:35
S… Speaker 1 (2026-04-13 00-39-03)
an unsolicited ARP reply,
11:38
S… Speaker 1 (2026-04-13 00-39-03)
reply without a request.
11:40
S… Speaker 1 (2026-04-13 00-39-03)
This can be done as something like an ARP
11:44
S… Speaker 1 (2026-04-13 00-39-03)
poisoning attack,
11:45
S… Speaker 1 (2026-04-13 00-39-03)
which is where an attacker tries to force a client to have multiple
11:50
S… Speaker 1 (2026-04-13 00-39-03)
different fake or malicious ARP entries.
11:53
S… Speaker 1 (2026-04-13 00-39-03)
essentially telling that client,
11:55
S… Speaker 1 (2026-04-13 00-39-03)
hey, all of these IP addresses all point back to my
11:59
S… Speaker 1 (2026-04-13 00-39-03)
attacker -controlled machine.
12:01
S… Speaker 1 (2026-04-13 00-39-03)
So it's sending out all of these ARP replies without any requests.
12:05
S… Speaker 1 (2026-04-13 00-39-03)
Another possible suspicious bit of ARP traffic would be
12:09
S… Speaker 1 (2026-04-13 00-39-03)
if you have responses that have identical MAC addresses,
12:14
S… Speaker 1 (2026-04-13 00-39-03)
but with different IP addresses.
12:16
S… Speaker 1 (2026-04-13 00-39-03)
Again, this can be tied in with the gratuitous ARP
12:21
S… Speaker 2 (2026-04-13 00-39-03)
replies.
12:21
S… Speaker 1 (2026-04-13 00-39-03)
And it's basically another way for it's an indicator that
12:25
S… Speaker 1 (2026-04-13 00-39-03)
there may be an attacker on the machine trying to reroute
12:30
S… Speaker 2 (2026-04-13 00-39-03)
traffic.
12:31
S… Speaker 1 (2026-04-13 00-39-03)
Again, suspicious is going to be determined based on your
12:35
S… Speaker 1 (2026-04-13 00-39-03)
network specifically.
12:37
S… Speaker 1 (2026-04-13 00-39-03)
So normal traffic in Wireshark,
12:41
S… Speaker 1 (2026-04-13 00-39-03)
normal ARP traffic looks like this.
12:43
S… Speaker 1 (2026-04-13 00-39-03)
You have the request where you have the client
12:47
S… Speaker 1 (2026-04-13 00-39-03)
is essentially asking,
12:48
S… Speaker 1 (2026-04-13 00-39-03)
hey, who has this IP address?
12:50
S… Speaker 1 (2026-04-13 00-39-03)
Please tell me.
12:52
S… Speaker 1 (2026-04-13 00-39-03)
And that is a broadcast packet.
12:54
S… Speaker 1 (2026-04-13 00-39-03)
We will see that in the next bit here.
12:57
S… Speaker 1 (2026-04-13 00-39-03)
And then whoever does have that IP address says,
13:00
S… Speaker 1 (2026-04-13 00-39-03)
hey, I am at this MAC address right here.
13:03
S… Speaker 1 (2026-04-13 00-39-03)
That's where you can find me.
13:05
S… Speaker 1 (2026-04-13 00-39-03)
That is the entirety of ARP communication,
13:08
S… Speaker 1 (2026-04-13 00-39-03)
a broadcast request followed by a reply,
13:12
S… Speaker 1 (2026-04-13 00-39-03)
assuming that there is anything listening at that IP address.
13:16
S… Speaker 1 (2026-04-13 00-39-03)
If there's not, you're not going to see a reply.
13:19
S… Speaker 1 (2026-04-13 00-39-03)
So the request looks like this in more detail.
13:22
S… Speaker 1 (2026-04-13 00-39-03)
Again, the destination is going to be a broadcast
13:26
S… Speaker 1 (2026-04-13 00-39-03)
MAC address because whatever node is requesting it doesn't know
13:31
S… Speaker 1 (2026-04-13 00-39-03)
where to find this device on the network.
13:33
S… Speaker 1 (2026-04-13 00-39-03)
So it has to ask everything on the network.
13:35
S… Speaker 1 (2026-04-13 00-39-03)
So it is sent as a broadcast.
13:37
S… Speaker 2 (2026-04-13 00-39-03)
Again,
13:38
S… Speaker 1 (2026-04-13 00-39-03)
doesn't know where it's sending it.
13:40
S… Speaker 1 (2026-04-13 00-39-03)
So the target MAC address here in here is going to be blank because
13:44
S… Speaker 1 (2026-04-13 00-39-03)
it doesn't know what the MAC address is.
13:46
S… Speaker 1 (2026-04-13 00-39-03)
That's what's trying to figure out.
13:48
S… Speaker 1 (2026-04-13 00-39-03)
The reply looks like this.
13:50
S… Speaker 1 (2026-04-13 00-39-03)
So it goes back to the destination here is not a broadcast
13:54
S… Speaker 2 (2026-04-13 00-39-03)
address.
13:55
S… Speaker 1 (2026-04-13 00-39-03)
The destination is the MAC address of whatever
13:59
S… Speaker 1 (2026-04-13 00-39-03)
system was requesting the information,
14:03
S… Speaker 1 (2026-04-13 00-39-03)
whatever system sent the ARP request.
14:06
S… Speaker 1 (2026-04-13 00-39-03)
And the reply contains the MAC address
14:10
S… Speaker 1 (2026-04-13 00-39-03)
of whatever they were trying to figure out of.
14:14
S… Speaker 1 (2026-04-13 00-39-03)
Whoever is sending this reply,
14:15
S… Speaker 1 (2026-04-13 00-39-03)
that MAC address is sent in there.
14:17
S… Speaker 2 (2026-04-13 00-39-03)
And again,
14:18
S… Speaker 1 (2026-04-13 00-39-03)
that is the entirety of ARP communication.
14:20
S… Speaker 1 (2026-04-13 00-39-03)
You have a request followed by a response or reply.
14:24
S… Speaker 1 (2026-04-13 00-39-03)
And it looks a bit more like this in the details section in
14:28
S… Speaker 1 (2026-04-13 00-39-03)
Wireshark.
14:30
S… Speaker 1 (2026-04-13 00-39-03)
There's a couple different ways that suspicious ARP traffic can
14:34
S… Speaker 1 (2026-04-13 00-39-03)
show up.
14:35
S… Speaker 1 (2026-04-13 00-39-03)
Now this first one may or may not be suspicious.
14:39
S… Speaker 1 (2026-04-13 00-39-03)
We see the source here.
14:41
S… Speaker 1 (2026-04-13 00-39-03)
Wireshark is identifying it through its internal MAC address information
14:45
S… Speaker 1 (2026-04-13 00-39-03)
it has in its database as a possible Cisco device.
14:49
S… Speaker 1 (2026-04-13 00-39-03)
So we have one device.
14:51
S… Speaker 1 (2026-04-13 00-39-03)
That is sending out a series of ARP requests asking for
14:55
S… Speaker 1 (2026-04-13 00-39-03)
information about multiple different IP addresses on the network.
14:59
S… Speaker 1 (2026-04-13 00-39-03)
So how do we know whether this is going to be suspicious or
15:03
S… Speaker 1 (2026-04-13 00-39-03)
not? Well, first of all,
15:04
S… Speaker 1 (2026-04-13 00-39-03)
do we have Cisco devices on our network?
15:08
S… Speaker 1 (2026-04-13 00-39-03)
Are we running any Cisco equipment?
15:10
S… Speaker 1 (2026-04-13 00-39-03)
If we are,
15:11
S… Speaker 1 (2026-04-13 00-39-03)
then this could be legitimate.
15:12
S… Speaker 1 (2026-04-13 00-39-03)
If we're not,
15:13
S… Speaker 1 (2026-04-13 00-39-03)
probably is suspicious or malicious.
15:16
S… Speaker 1 (2026-04-13 00-39-03)
Is this Cisco equipment?
15:18
S… Speaker 1 (2026-04-13 00-39-03)
If we do have it,
15:19
S… Speaker 1 (2026-04-13 00-39-03)
is it potentially misconfigured?
15:21
S… Speaker 1 (2026-04-13 00-39-03)
Or is this just a router that's handling a lot of traffic and
15:25
S… Speaker 1 (2026-04-13 00-39-03)
this is completely normal?
15:27
S… Speaker 1 (2026-04-13 00-39-03)
This is again where the context comes in.
15:30
S… Speaker 1 (2026-04-13 00-39-03)
So this first example here might be malicious or it might be
15:34
S… Speaker 1 (2026-04-13 00-39-03)
perfectly normal.
15:35
S… Speaker 1 (2026-04-13 00-39-03)
All depends on what the baseline is for the network.
15:40
S… Speaker 1 (2026-04-13 00-39-03)
This second one here is like we've seen previously with our port scans
15:44
S… Speaker 1 (2026-04-13 00-39-03)
when looking at TCP.
15:45
S… Speaker 1 (2026-04-13 00-39-03)
This one is almost certainly going to be malicious
15:50
S… Speaker 2 (2026-04-13 00-39-03)
here.
15:50
S… Speaker 1 (2026-04-13 00-39-03)
The indicators here of why this could potentially be
15:55
S… Speaker 1 (2026-04-13 00-39-03)
malicious, number one,
15:56
S… Speaker 1 (2026-04-13 00-39-03)
the short amount of time between all of these requests.
16:00
S… Speaker 1 (2026-04-13 00-39-03)
Again, we're talking about less than a second.
16:03
S… Speaker 1 (2026-04-13 00-39-03)
We look about roughly a half second between all of these
16:07
S… Speaker 1 (2026-04-13 00-39-03)
requests here.
16:08
S… Speaker 1 (2026-04-13 00-39-03)
And the other indication here is that again the IP addresses
16:12
S… Speaker 1 (2026-04-13 00-39-03)
are incrementing.
16:14
S… Speaker 1 (2026-04-13 00-39-03)
We're starting at one and basically counting up.
16:17
S… Speaker 1 (2026-04-13 00-39-03)
So this is an indicator of some machine possibly trying
16:22
S… Speaker 1 (2026-04-13 00-39-03)
to map out the network,
16:24
S… Speaker 1 (2026-04-13 00-39-03)
trying to figure out what devices are alive on the network
16:28
S… Speaker 1 (2026-04-13 00-39-03)
and where they might be on the network,
16:30
S… Speaker 1 (2026-04-13 00-39-03)
where they can be reached.
16:31
S… Speaker 2 (2026-04-13 00-39-03)
Again,
16:32
S… Speaker 1 (2026-04-13 00-39-03)
this does not look like a very legitimate usage
16:36
S… Speaker 1 (2026-04-13 00-39-03)
of ARP.
16:38
S… Speaker 1 (2026-04-13 00-39-03)
So we've taken a look at some suspicious TCP.
16:42
S… Speaker 1 (2026-04-13 00-39-03)
and ARP traffic in this video.
16:45
S… Speaker 1 (2026-04-13 00-39-03)
Next we're going to take a look at ICMP and DHCP.

תעתיק זה נוצר על ידי AI (הכרה אוטומטית של דיבור). ייתכן שיש בו שגיאות אשר מאשרות את השמע המקורי לשימוש קריטי. מדיניות AI

❤️ אוהבים את STT.ai? ספרו לחברים שלכם!
תקציר
לחץ לסכם כדי ליצור סיכום AI של תעתיק זה.
מסכם...
שאל את אל על התעתיק הזה.
שאל כל דבר על התמליל הזה, הבינה המלאכותית תמצא חלקים רלוונטיים ותענה.