Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-NET-LAB-003Medium
Browser LabLD-NET-LAB-003Medium32 min

Boss Lab: Read the Capture

Meridian reports intermittent 'suspicious network activity' and hands you an hour of captured traffic from one office segment, summarised as conversations plus the DNS log. The capture is mostly normal — DNS lookups, web browsing, internal ARP, ICMP, healthy TCP handshakes — with ONE communication pattern that does not belong. Investigate it the way lesson 8.3 taught: filter, group, compare, and reach an evidence-based conclusion. Claim only what the packets support.

What you will be able to do

  • Separate the outlier conversation from a normal baseline.
  • Identify affected host, destination, initiator, protocol and related DNS.
  • State a conclusion that cites specific packet evidence.
Network AnalysisLog AnalysisAnalyst ReportingT1071.001Application Layer Protocol: Web ProtocolsT1571Non-Standard Port

Sign in to start this lab.

Sign in