Cyber Security Labs (Beginner → Advanced)

Lesson 3 of 6

Lab 3 — Reading Network Traffic

Interpret a packet capture, spot plaintext credentials, port scans and beaconing malware.

🟡 Intermediate 110 XP

Learn it

Everything you send online is chopped into packets. Each packet carries an address label (headers) and a bit of your data (payload).

On an old HTTP site the payload is readable by anyone on the path. On HTTPS it is scrambled, though the destination is still visible.

Security teams record packets and look for patterns that humans do not make — like a device contacting the same unknown server every 60 seconds, all night.

Key terms

Packet
A small unit of data with headers describing where it came from and where it is going.
Three-way handshake
The SYN, SYN-ACK, ACK exchange that opens a TCP connection.
Port scan
Probing many ports on a host to discover which services are listening.
Beaconing
Regular check-in traffic from infected malware to its command-and-control server.
TTL
Time To Live — a hop counter in the IP header that also hints at the sending operating system.

Triage a capture

Twelve seconds of traffic from a school laptop, 10.0.5.31. What happened?

  1. 11. 09:14:02: 10.0.5.31 → 10.0.5.1 DNS query for 'updates-cdn-eu4.click'. Unusual TLD, never seen before on this network.
  2. 22. 09:14:02: DNS response: 185.62.x.x. Hosting provider with no relationship to the school.
  3. 33. 09:14:03: TCP SYN → 185.62.x.x:443, SYN-ACK, ACK. Connection opens. TLS, so the payload is unreadable.
  4. 44. 09:14:03: 312 bytes out, 96 bytes in. Tiny, uniform exchange — not a web page.
  5. 55. 09:15:03 and 09:16:03: Identical exchange, exactly 60 seconds apart, ±0.4s jitter. That regularity is machine-made.
  6. 66. 09:16:10: Same host sends SYN to 10.0.5.20 ports 22, 23, 80, 139, 445, 3389 in 900ms. Internal port scan — lateral movement.
  7. 77. Verdict: Beaconing plus internal scanning: assume compromise. Isolate the host, preserve the capture, and hunt the domain across all DNS logs.

Detecting beaconing from connection timestamps

pythontimes = [0, 60.2, 119.8, 180.3, 240.1, 299.9]
gaps = [round(b - a, 1) for a, b in zip(times, times[1:])]
avg = sum(gaps) / len(gaps)
jitter = max(abs(g - avg) for g in gaps)

print("gaps:", gaps)
print("avg:", round(avg, 1), "jitter:", round(jitter, 1))
if jitter < 2:
    print("ALERT: regular beacon detected")

Humans browse irregularly. A jitter under a couple of seconds across many connections is a strong malware indicator.

Sandbox lab

Practise the real technique in a fully simulated environment — no live systems, no real data, nothing leaves your browser.

Packet capture triage console

A frozen, fake capture from a school network. Flag every malicious packet, then check your triage.

Safe simulation
FlagTimeSourceDestinationProto/PortBytesInfo
09:00:0110.0.0.14142.250.187.4TCP/4431,420TLS application data
09:00:0410.0.0.1410.0.0.1UDP/5386DNS query school-portal.local
09:02:0010.0.0.31185.62.190.7TCP/8080312POST /gate.php (heartbeat)
09:04:0010.0.0.31185.62.190.7TCP/8080314POST /gate.php (heartbeat)
09:05:1110.0.0.2210.0.0.14TCP/445980SMB file read report.docx
09:06:0010.0.0.31185.62.190.7TCP/8080313POST /gate.php (heartbeat)
09:06:4110.0.0.910.0.0.2TCP/22640SSH session to admin server
09:07:0210.0.0.7710.0.0.14TCP/2160SYN (no reply)
09:07:0210.0.0.7710.0.0.14TCP/2260SYN (no reply)
09:07:0210.0.0.7710.0.0.14TCP/2360SYN (no reply)
09:08:3010.0.0.14104.18.32.11TCP/4435,210TLS download update.pkg
09:09:1010.0.0.31185.62.190.7TCP/80804,210,000POST /upload (4.2 MB)

Try it

Match each capture observation to what it means.

Many SYNs to sequential ports, mostly RST replies
POST to http:// with 'user=tim&pass=letmein' visible
Identical 300-byte request every 60s to one host
Huge UDP flood from thousands of sources
DNS queries for long random subdomains

Challenge

You are the analyst on duty. Using the Explore capture, write the incident ticket: what you observed (with timestamps), your hypothesis, your confidence level, the containment steps you will take in order, and what extra evidence you need before declaring a breach.

Pick whichever way suits you — every mode earns the same bonus XP.

Write at least 40 more characters to submit.

Mark your own work

Guided walkthrough — 0/7 clues revealed

  1. Clue 1 locked — reveal it only if you get stuck.
  2. Clue 2 locked — reveal it only if you get stuck.
  3. Clue 3 locked — reveal it only if you get stuck.
  4. Clue 4 locked — reveal it only if you get stuck.
  5. Clue 5 locked — reveal it only if you get stuck.
  6. Clue 6 locked — reveal it only if you get stuck.
  7. Clue 7 locked — reveal it only if you get stuck.

Each clue costs 6 XP (never below 28 XP). You'd earn 55 XP right now.

Extension: Write the Wireshark display filter you would use to pull every connection to that IP out of a week of captures.

Quiz time

Question 1 of 4Score 0

Which flag combination opens a TCP connection?