Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC1-LAB-010Medium
Browser LabLD-SOC1-LAB-010Medium20 min

Behaviour Over Content: Beacon, Tunnel, Exfil

An NDR flagged 'unusual outbound activity' on the 10.20.4.0/24 subnet. There is no full PCAP — only flow records, a DNS aggregation, and TLS metadata. Read behaviour, not content: find the beacon, the DNS tunnel and the exfiltration, decide which single host is compromised, and map what you found to MITRE ATT&CK. Encryption hides payloads here; it does not hide the shapes.

What you will be able to do

  • Identify beaconing from a fixed interval, without packet content
  • Identify DNS tunnelling from distinct-subdomain volume
  • Identify exfiltration from sustained outbound bytes and direction
Network AnalysisIOC AnalysisIncident TriageT1071.001Application Layer Protocol: Web ProtocolsT1048Exfiltration Over Alternative ProtocolT1071.004Application Layer Protocol: DNS

Sign in to start this lab.

Sign in