1
1

00:00:00,240  -->  00:00:02,400
<v Instructor>Analyzing network IOCs</v>
2

2

00:00:02,400  -->  00:00:04,500
or indicators of compromise.
3

3

00:00:04,500  -->  00:00:06,840
Now, in this section, we're really going to focus
4

4

00:00:06,840  -->  00:00:08,190
on all of the different ways
5

5

00:00:08,190  -->  00:00:11,220
of identifying bad behavior on a network.
6

6

00:00:11,220  -->  00:00:13,380
Once we find an indicator of compromise,
7

7

00:00:13,380  -->  00:00:15,540
we can then use that to create defenses
8

8

00:00:15,540  -->  00:00:17,550
against these different types of attacks
9

9

00:00:17,550  -->  00:00:20,640
and then we can also use those inside of our threat hunting.
10

10

00:00:20,640  -->  00:00:23,550
Now, there's lots of reasons for using IOCs:
11

11

00:00:23,550  -->  00:00:26,100
we can use it to create defenses or do threat hunting.
12

12

00:00:26,100  -->  00:00:27,660
We can use it for instant response
13

13

00:00:27,660  -->  00:00:30,870
and forensic investigations and lots of other things.
14

14

00:00:30,870  -->  00:00:33,180
Now, while the way we'll use those different IOCs
15

15

00:00:33,180  -->  00:00:34,200
may be very different,
16

16

00:00:34,200  -->  00:00:36,810
the way we learn about these IOCs and gather them
17

17

00:00:36,810  -->  00:00:40,050
and analyze them is going to be very much the same.
18

18

00:00:40,050  -->  00:00:42,480
Now, when we start dealing with network related IOCs,
19

19

00:00:42,480  -->  00:00:44,760
there are lots of different ones out there.
20

20

00:00:44,760  -->  00:00:47,010
For example, what if we start seeing things
21

21

00:00:47,010  -->  00:00:48,840
like port scanning and sweeps?
22

22

00:00:48,840  -->  00:00:50,820
If we see that they may be the indicator
23

23

00:00:50,820  -->  00:00:52,890
that there's an attack coming next.
24

24

00:00:52,890  -->  00:00:55,800
We might identify things like non-standard port usage.
25

25

00:00:55,800  -->  00:00:58,620
For example, maybe I'm seeing SSL being used
26

26

00:00:58,620  -->  00:01:02,040
on some port for web traffic that isn't 443.
27

27

00:01:02,040  -->  00:01:03,780
Well, that would be something that would flag
28

28

00:01:03,780  -->  00:01:05,220
as something I should look for.
29

29

00:01:05,220  -->  00:01:07,080
And if the same attacker uses the same type
30

30

00:01:07,080  -->  00:01:08,610
of ports every single time
31

31

00:01:08,610  -->  00:01:09,990
for the same type of malware,
32

32

00:01:09,990  -->  00:01:13,230
that would be a good indicator or compromise we could use.
33

33

00:01:13,230  -->  00:01:15,690
Maybe we start identifying a covert channel.
34

34

00:01:15,690  -->  00:01:17,190
Like for instance, we start seeing data
35

35

00:01:17,190  -->  00:01:19,170
that's being sent out over a ping packet,
36

36

00:01:19,170  -->  00:01:22,140
because normally, ping packets don't carry data
37

37

00:01:22,140  -->  00:01:23,850
and so that would be something that would be unusual.
38

38

00:01:23,850  -->  00:01:24,960
And if we identify that
39

39

00:01:24,960  -->  00:01:27,270
that might be a sign of a data exfiltration
40

40

00:01:27,270  -->  00:01:30,060
or beaconing or C2 or something like that.
41

41

00:01:30,060  -->  00:01:32,010
Or maybe we start looking around our network
42

42

00:01:32,010  -->  00:01:34,470
and we start seeing devices that we don't recognize.
43

43

00:01:34,470  -->  00:01:36,450
For instance, there's a new wireless access point
44

44

00:01:36,450  -->  00:01:38,100
or a new wireless network out there
45

45

00:01:38,100  -->  00:01:39,720
or there's a new switch.
46

46

00:01:39,720  -->  00:01:41,430
Any of these things could be rogue devices
47

47

00:01:41,430  -->  00:01:42,960
and that could have been something that's an indicator
48

48

00:01:42,960  -->  00:01:44,460
of an insider threat.
49

49

00:01:44,460  -->  00:01:46,890
Now, that insider might have had intention with this
50

50

00:01:46,890  -->  00:01:48,510
or it might have just been something they were doing
51

51

00:01:48,510  -->  00:01:49,620
for convenience.
52

52

00:01:49,620  -->  00:01:51,720
Either way, they're bringing a threat to our network
53

53

00:01:51,720  -->  00:01:53,430
and it's something that we can identify
54

54

00:01:53,430  -->  00:01:55,410
and then relate that back to the intrusion set,
55

55

00:01:55,410  -->  00:01:57,510
in this case, an insider threat.
56

56

00:01:57,510  -->  00:01:59,340
All these things are what we're looking for
57

57

00:01:59,340  -->  00:02:02,550
when we start analyzing networks to identify these IOCs
58

58

00:02:02,550  -->  00:02:04,380
or indicators of compromise.
59

59

00:02:04,380  -->  00:02:06,240
And as we go through the next several lessons
60

60

00:02:06,240  -->  00:02:07,140
in this course,
61

61

00:02:07,140  -->  00:02:09,540
we're going to start talking about individual IOCs
62

62

00:02:09,540  -->  00:02:10,803
and how to identify them.
