Lesson 3 of 6
Lab 3 — Reading Network Traffic
Interpret a packet capture, spot plaintext credentials, port scans and beaconing malware.
Learn it
Everything you send online is chopped into packets. Each packet carries an address label (headers) and a bit of your data (payload).
On an old HTTP site the payload is readable by anyone on the path. On HTTPS it is scrambled, though the destination is still visible.
Security teams record packets and look for patterns that humans do not make — like a device contacting the same unknown server every 60 seconds, all night.
Key terms
- Packet
- A small unit of data with headers describing where it came from and where it is going.
- Three-way handshake
- The SYN, SYN-ACK, ACK exchange that opens a TCP connection.
- Port scan
- Probing many ports on a host to discover which services are listening.
- Beaconing
- Regular check-in traffic from infected malware to its command-and-control server.
- TTL
- Time To Live — a hop counter in the IP header that also hints at the sending operating system.
Triage a capture
Twelve seconds of traffic from a school laptop, 10.0.5.31. What happened?
- 11. 09:14:02: 10.0.5.31 → 10.0.5.1 DNS query for 'updates-cdn-eu4.click'. Unusual TLD, never seen before on this network.
- 22. 09:14:02: DNS response: 185.62.x.x. Hosting provider with no relationship to the school.
- 33. 09:14:03: TCP SYN → 185.62.x.x:443, SYN-ACK, ACK. Connection opens. TLS, so the payload is unreadable.
- 44. 09:14:03: 312 bytes out, 96 bytes in. Tiny, uniform exchange — not a web page.
- 55. 09:15:03 and 09:16:03: Identical exchange, exactly 60 seconds apart, ±0.4s jitter. That regularity is machine-made.
- 66. 09:16:10: Same host sends SYN to 10.0.5.20 ports 22, 23, 80, 139, 445, 3389 in 900ms. Internal port scan — lateral movement.
- 77. Verdict: Beaconing plus internal scanning: assume compromise. Isolate the host, preserve the capture, and hunt the domain across all DNS logs.
Detecting beaconing from connection timestamps
pythontimes = [0, 60.2, 119.8, 180.3, 240.1, 299.9]
gaps = [round(b - a, 1) for a, b in zip(times, times[1:])]
avg = sum(gaps) / len(gaps)
jitter = max(abs(g - avg) for g in gaps)
print("gaps:", gaps)
print("avg:", round(avg, 1), "jitter:", round(jitter, 1))
if jitter < 2:
print("ALERT: regular beacon detected")Humans browse irregularly. A jitter under a couple of seconds across many connections is a strong malware indicator.
Sandbox lab
Practise the real technique in a fully simulated environment — no live systems, no real data, nothing leaves your browser.
Packet capture triage console
A frozen, fake capture from a school network. Flag every malicious packet, then check your triage.
| Flag | Time | Source | Destination | Proto/Port | Bytes | Info |
|---|---|---|---|---|---|---|
| 09:00:01 | 10.0.0.14 | 142.250.187.4 | TCP/443 | 1,420 | TLS application data | |
| 09:00:04 | 10.0.0.14 | 10.0.0.1 | UDP/53 | 86 | DNS query school-portal.local | |
| 09:02:00 | 10.0.0.31 | 185.62.190.7 | TCP/8080 | 312 | POST /gate.php (heartbeat) | |
| 09:04:00 | 10.0.0.31 | 185.62.190.7 | TCP/8080 | 314 | POST /gate.php (heartbeat) | |
| 09:05:11 | 10.0.0.22 | 10.0.0.14 | TCP/445 | 980 | SMB file read report.docx | |
| 09:06:00 | 10.0.0.31 | 185.62.190.7 | TCP/8080 | 313 | POST /gate.php (heartbeat) | |
| 09:06:41 | 10.0.0.9 | 10.0.0.2 | TCP/22 | 640 | SSH session to admin server | |
| 09:07:02 | 10.0.0.77 | 10.0.0.14 | TCP/21 | 60 | SYN (no reply) | |
| 09:07:02 | 10.0.0.77 | 10.0.0.14 | TCP/22 | 60 | SYN (no reply) | |
| 09:07:02 | 10.0.0.77 | 10.0.0.14 | TCP/23 | 60 | SYN (no reply) | |
| 09:08:30 | 10.0.0.14 | 104.18.32.11 | TCP/443 | 5,210 | TLS download update.pkg | |
| 09:09:10 | 10.0.0.31 | 185.62.190.7 | TCP/8080 | 4,210,000 | POST /upload (4.2 MB) |
Try it
Match each capture observation to what it means.
Challenge
You are the analyst on duty. Using the Explore capture, write the incident ticket: what you observed (with timestamps), your hypothesis, your confidence level, the containment steps you will take in order, and what extra evidence you need before declaring a breach.
Pick whichever way suits you — every mode earns the same bonus XP.
Write at least 40 more characters to submit.
Mark your own work
Guided walkthrough — 0/7 clues revealed
- Clue 1 locked — reveal it only if you get stuck.
- Clue 2 locked — reveal it only if you get stuck.
- Clue 3 locked — reveal it only if you get stuck.
- Clue 4 locked — reveal it only if you get stuck.
- Clue 5 locked — reveal it only if you get stuck.
- Clue 6 locked — reveal it only if you get stuck.
- Clue 7 locked — reveal it only if you get stuck.
Each clue costs 6 XP (never below 28 XP). You'd earn 55 XP right now.
Extension: Write the Wireshark display filter you would use to pull every connection to that IP out of a week of captures.