Browser LabLD-NET-LAB-003Medium
Browser LabLD-NET-LAB-003Medium32 min
Boss Lab: Read the Capture
Meridian reports intermittent 'suspicious network activity' and hands you an hour of captured traffic from one office segment, summarised as conversations plus the DNS log. The capture is mostly normal — DNS lookups, web browsing, internal ARP, ICMP, healthy TCP handshakes — with ONE communication pattern that does not belong. Investigate it the way lesson 8.3 taught: filter, group, compare, and reach an evidence-based conclusion. Claim only what the packets support.
What you will be able to do
- Separate the outlier conversation from a normal baseline.
- Identify affected host, destination, initiator, protocol and related DNS.
- State a conclusion that cites specific packet evidence.
Network AnalysisLog AnalysisAnalyst ReportingT1071.001 — Application Layer Protocol: Web ProtocolsT1571 — Non-Standard Port
Sign in to start this lab.
Sign in