Browser LabLD-SOC1-LAB-010Medium
Browser LabLD-SOC1-LAB-010Medium20 min
Behaviour Over Content: Beacon, Tunnel, Exfil
An NDR flagged 'unusual outbound activity' on the 10.20.4.0/24 subnet. There is no full PCAP — only flow records, a DNS aggregation, and TLS metadata. Read behaviour, not content: find the beacon, the DNS tunnel and the exfiltration, decide which single host is compromised, and map what you found to MITRE ATT&CK. Encryption hides payloads here; it does not hide the shapes.
What you will be able to do
- Identify beaconing from a fixed interval, without packet content
- Identify DNS tunnelling from distinct-subdomain volume
- Identify exfiltration from sustained outbound bytes and direction
Network AnalysisIOC AnalysisIncident TriageT1071.001 — Application Layer Protocol: Web ProtocolsT1048 — Exfiltration Over Alternative ProtocolT1071.004 — Application Layer Protocol: DNS
Sign in to start this lab.
Sign in