2026-04-13 00-39-03
Zvočniki
Poglavja
-
0:10Poglavje 1: When performing threat hunts, it's very important to be able to know what abnormal traffic looks like. 301s · Speaker 2
When performing threat hunts, it's very important to be able to know what abnormal traffic looks like. So in the next few videos here, we're going to take a look at some examples of different types of normal versus abnormal traffic. We're g…
-
5:11Poglavje 2: Again, probably the start of HTTP traffic. 300s · Speaker 2
Again, probably the start of HTTP traffic. We don't know for sure without additional information. We see the source port here is a randomly generated high -numbered port, and our reply, our SYN ACK packet, will be going back to this same po…
-
10:12Poglavje 3: so it knows where to route certain packets. 128s · Speaker 1
so it knows where to route certain packets. So let's take a look at what is some normal ARP communication versus suspicious ARP communication. Number one, we see that ARP broadcasts should go out at a reasonable rate. Again, reasonable is g…
-
12:21Poglavje 4: replies. And it's basically another way for it's an indicator that there may be an attacker on the machine trying to reroute traffic. 268s · Speaker 2
replies. And it's basically another way for it's an indicator that there may be an attacker on the machine trying to reroute traffic. Again, suspicious is going to be determined based on your network specifically. So normal traffic in Wires…