1
00:00:00,000 --> 00:00:00,882
In this lesson,

2
00:00:00,882 --> 00:00:03,262
we're going to take a look at some Packet Captures.

3
00:00:03,262 --> 00:00:05,475
Now, a packet capture is used to be able to capture

4
00:00:05,475 --> 00:00:09,483
all the data going to or from a given network device.

5
00:00:09,483 --> 00:00:11,997
You can also set up a packet capture over a SPAN port

6
00:00:11,997 --> 00:00:13,915
and capture all the data going to and from

7
00:00:13,915 --> 00:00:15,967
all of the devices on your network,

8
00:00:15,967 --> 00:00:17,083
depending on how you can configure

9
00:00:17,083 --> 00:00:18,881
your packet capture software.

10
00:00:18,881 --> 00:00:21,713
Now, when we look at a packet capture in this lesson,

11
00:00:21,713 --> 00:00:23,067
we're going to be looking at snippets,

12
00:00:23,067 --> 00:00:24,184
because on the exam,

13
00:00:24,184 --> 00:00:25,884
they're not going to give you a full packet capture

14
00:00:25,884 --> 00:00:28,353
of gigabytes and gigabytes of data,

15
00:00:28,353 --> 00:00:29,609
but instead, they're going to give you something

16
00:00:29,609 --> 00:00:32,292
like 5 lines or 10 lines or 20 lines

17
00:00:32,292 --> 00:00:33,841
inside of a packet capture,

18
00:00:33,841 --> 00:00:36,068
and so that's what we're going to be focusing on here.

19
00:00:36,068 --> 00:00:37,850
Now, as we go through these three packet captures,

20
00:00:37,850 --> 00:00:40,065
I'm going to show you three different types of attacks

21
00:00:40,065 --> 00:00:42,829
that a threat actor might use against your network.

22
00:00:42,829 --> 00:00:44,397
Let's take a look at the first one.

23
00:00:44,397 --> 00:00:45,249
Now, in this first one,

24
00:00:45,249 --> 00:00:47,735
you can see this whole packet capture that I'm showing you

25
00:00:47,735 --> 00:00:49,850
only has 19 lines.

26
00:00:49,850 --> 00:00:51,274
Now, it's actually going to be the longest packet capture

27
00:00:51,274 --> 00:00:53,758
we're going to look at, but it's also one of the easiest.

28
00:00:53,758 --> 00:00:55,174
Now, as we look at these, you can see

29
00:00:55,174 --> 00:00:56,927
that we have a couple of different columns here,

30
00:00:56,927 --> 00:00:58,433
going across the top.

31
00:00:58,433 --> 00:01:00,996
The first one that we have is what's known as the Number,

32
00:01:00,996 --> 00:01:03,562
and this is the packet number in the capture sequence.

33
00:01:03,562 --> 00:01:05,706
So we start out with 1, then 2, then 3,

34
00:01:05,706 --> 00:01:08,122
and we went all the way down to 19.

35
00:01:08,122 --> 00:01:11,902
The second column we have is the Time. When did this happen?

36
00:01:11,902 --> 00:01:13,808
Now you'll notice this isn't actually a date and time

37
00:01:13,808 --> 00:01:15,092
like you're used to,

38
00:01:15,092 --> 00:01:17,457
but instead, it's actually written as the amount of time

39
00:01:17,457 --> 00:01:20,586
that has elapsed since we started the packet capture.

40
00:01:20,586 --> 00:01:22,877
So, it's important to make sure you capture the time

41
00:01:22,877 --> 00:01:24,285
you begin your packet capture,

42
00:01:24,285 --> 00:01:25,675
so you can then coordinate this

43
00:01:25,675 --> 00:01:27,943
as you bring this packet capture into your SIEM

44
00:01:27,943 --> 00:01:30,308
or other types of incident response systems,

45
00:01:30,308 --> 00:01:32,843
so you'll be able to consolidate this and correlate it

46
00:01:32,843 --> 00:01:35,044
across all of your different logs and devices.

47
00:01:35,044 --> 00:01:38,148
Because just knowing that this happened at 0.002 second

48
00:01:38,148 --> 00:01:40,740
after the ability of us starting this packet capture

49
00:01:40,740 --> 00:01:41,604
isn't as helpful

50
00:01:41,604 --> 00:01:44,522
if we can't correlate that across all of our systems.

51
00:01:44,522 --> 00:01:46,043
The next two columns have IP addresses,

52
00:01:46,043 --> 00:01:48,806
and you'll see the source and the destination.

53
00:01:48,806 --> 00:01:50,337
Essentially, it's our perspective

54
00:01:50,337 --> 00:01:52,973
based on the sensor of where the data's coming from

55
00:01:52,973 --> 00:01:54,802
and where the data is going to.

56
00:01:54,802 --> 00:01:57,673
In this case, we have two sample IP addresses being used

57
00:01:57,673 --> 00:02:00,090
of 99.88.77.66 as our source,

58
00:02:01,735 --> 00:02:03,610
and we're trying to go to our destination,

59
00:02:03,610 --> 00:02:05,360
which is 11.22.33.44.

60
00:02:07,866 --> 00:02:10,026
Next, you'll see the column for Protocol,

61
00:02:10,026 --> 00:02:13,453
and this will either be TCP, UDP, or something else.

62
00:02:13,453 --> 00:02:15,466
For example, if we're operating at layer two,

63
00:02:15,466 --> 00:02:17,708
you might see things like ARP being used.

64
00:02:17,708 --> 00:02:19,812
But since we're here at layer three and layer four,

65
00:02:19,812 --> 00:02:22,557
we're going to be talking about TCP and UDP.

66
00:02:22,557 --> 00:02:23,914
Next, we have length,

67
00:02:23,914 --> 00:02:26,630
and this is how long or how big that packet is,

68
00:02:26,630 --> 00:02:29,328
and all of them are only 74 in this case.

69
00:02:29,328 --> 00:02:31,140
And then we have Info, which will give you some information

70
00:02:31,140 --> 00:02:32,678
that's being captured from the header

71
00:02:32,678 --> 00:02:34,110
of each of these packets.

72
00:02:34,110 --> 00:02:36,200
In this case, you can see the flag that's being set,

73
00:02:36,200 --> 00:02:38,187
and you can see here that, that is the SYN flag,

74
00:02:38,187 --> 00:02:40,805
and we don't see any ACK flags or SYN-ACKs.

75
00:02:40,805 --> 00:02:43,319
And then we see the Sequence, the Window, the Length,

76
00:02:43,319 --> 00:02:46,196
the MSS, the SPort, which is your source port,

77
00:02:46,196 --> 00:02:48,627
and your Dport, which is your destination port.

78
00:02:48,627 --> 00:02:50,976
So, now I'm going to count down from ten to zero,

79
00:02:50,976 --> 00:02:51,853
and when I get to zero,

80
00:02:51,853 --> 00:02:53,907
I'm going to tell you what type of attack we're seeing

81
00:02:53,907 --> 00:02:55,578
inside of this packet capture,

82
00:02:55,578 --> 00:02:56,753
but I'm hoping you'll be able to figure out

83
00:02:56,753 --> 00:02:58,427
in the next 10 seconds.

84
00:02:58,427 --> 00:02:59,260
Ten,

85
00:02:59,260 --> 00:03:00,093
nine,

86
00:03:00,093 --> 00:03:00,926
eight,

87
00:03:00,926 --> 00:03:01,759
seven,

88
00:03:01,759 --> 00:03:02,592
six,

89
00:03:02,592 --> 00:03:03,425
five,

90
00:03:03,425 --> 00:03:04,258
four,

91
00:03:04,258 --> 00:03:05,091
three,

92
00:03:05,091 --> 00:03:05,924
two,

93
00:03:05,924 --> 00:03:07,082
one.

94
00:03:07,082 --> 00:03:08,621
All right. Did you figure it out?

95
00:03:08,621 --> 00:03:10,620
This is actually a port scan.

96
00:03:10,620 --> 00:03:12,250
Now, in fact, this is actually a port scan

97
00:03:12,250 --> 00:03:14,007
of the top 19 ports,

98
00:03:14,007 --> 00:03:16,666
and this scan actually was going on to the top 100 ports

99
00:03:16,666 --> 00:03:18,582
using an Nmap scanner.

100
00:03:18,582 --> 00:03:21,909
But, in this packet capture, I only showed you the first 19.

101
00:03:21,909 --> 00:03:23,376
You'll notice the first port being scanned

102
00:03:23,376 --> 00:03:25,137
is the Dport of 80,

103
00:03:25,137 --> 00:03:28,460
which is HTTP, or the Hypertext Transfer Protocol.

104
00:03:28,460 --> 00:03:30,996
The second one is Port 23, which is Telnet,

105
00:03:30,996 --> 00:03:33,559
which is an insecure version of remote access.

106
00:03:33,559 --> 00:03:36,896
The third one is Port 22, which is going to be for SSH,

107
00:03:36,896 --> 00:03:39,217
which is a Secure Remote Shell Capability.

108
00:03:39,217 --> 00:03:42,147
The fourth one is FTP at Port 21.

109
00:03:42,147 --> 00:03:46,238
The fifth one is Port 443 with HTTPS, and so on.

110
00:03:46,238 --> 00:03:48,917
As you can see, each time a SYN packet was being sent,

111
00:03:48,917 --> 00:03:51,895
it was being sent with a single SYN and a port

112
00:03:51,895 --> 00:03:52,772
going to there

113
00:03:52,772 --> 00:03:55,368
to basically see if that port was open on the remote server,

114
00:03:55,368 --> 00:04:00,123
which in this case was the destination of 11.22.33.44.

115
00:04:00,123 --> 00:04:01,910
And it kept doing that over and over and over again

116
00:04:01,910 --> 00:04:04,429
so that my Nmap software was able to see

117
00:04:04,429 --> 00:04:06,736
are there any ports open as part of my reconnaissance

118
00:04:06,736 --> 00:04:08,653
during a penetration test?

119
00:04:08,653 --> 00:04:11,243
Let's go ahead and move on to our second packet capture.

120
00:04:11,243 --> 00:04:12,958
Now, here's our second packet capture,

121
00:04:12,958 --> 00:04:15,061
and you'll see that we have a couple of dot dot dots

122
00:04:15,061 --> 00:04:16,226
in between.

123
00:04:16,226 --> 00:04:17,817
So, as we're going down the first column

124
00:04:17,817 --> 00:04:18,913
with the packet numbers,

125
00:04:18,913 --> 00:04:20,853
you'll see I have the first five packets shown.

126
00:04:20,853 --> 00:04:23,797
Then I skip down to packets 100 through 102,

127
00:04:23,797 --> 00:04:27,422
and then I skip down again to packets 1000 to 1002.

128
00:04:27,422 --> 00:04:29,164
All those dot dots are saying

129
00:04:29,164 --> 00:04:30,968
is there's other packets happening here,

130
00:04:30,968 --> 00:04:33,293
but I'm not showing it to you in this log snippet.

131
00:04:33,293 --> 00:04:35,815
And you'll see this used on the exam as well.

132
00:04:35,815 --> 00:04:37,180
As we go through, you can see

133
00:04:37,180 --> 00:04:41,579
that this whole packet capture happened within 0.1 seconds.

134
00:04:41,579 --> 00:04:43,012
So, this is actually a pretty fast packet capture

135
00:04:43,012 --> 00:04:45,115
to get 1000 packets through.

136
00:04:45,115 --> 00:04:47,627
You'll see the source and you'll see the destination.

137
00:04:47,627 --> 00:04:50,530
Now in this case, we're looking at the protocol as TCP,

138
00:04:50,530 --> 00:04:51,810
the length is 74,

139
00:04:51,810 --> 00:04:54,221
and again, we see a whole bunch of SYN packets there,

140
00:04:54,221 --> 00:04:56,052
and we don't actually see the port numbers associated

141
00:04:56,052 --> 00:04:57,187
with them.

142
00:04:57,187 --> 00:04:58,755
So, if you are looking at this

143
00:04:58,755 --> 00:05:00,978
and you see all these SYN packets happening,

144
00:05:00,978 --> 00:05:04,063
from packet one, all the way through to packet 1002

145
00:05:04,063 --> 00:05:05,192
and continuing,

146
00:05:05,192 --> 00:05:06,961
because there's still three dots there at the bottom,

147
00:05:06,961 --> 00:05:08,619
what do you think this is?

148
00:05:08,619 --> 00:05:10,146
I'm going to go ahead and count down from 10 again

149
00:05:10,146 --> 00:05:11,593
and see if you can guess.

150
00:05:11,593 --> 00:05:12,426
Ten,

151
00:05:12,426 --> 00:05:13,259
nine,

152
00:05:13,259 --> 00:05:14,092
eight,

153
00:05:14,092 --> 00:05:14,925
seven,

154
00:05:14,925 --> 00:05:15,758
six,

155
00:05:15,758 --> 00:05:16,591
five,

156
00:05:16,591 --> 00:05:17,424
four,

157
00:05:17,424 --> 00:05:18,257
three,

158
00:05:18,257 --> 00:05:19,090
two,

159
00:05:19,090 --> 00:05:19,923
one.

160
00:05:19,923 --> 00:05:20,907
Did you guess it?

161
00:05:20,907 --> 00:05:22,482
This is actually a type of Denial of Service Attack

162
00:05:22,482 --> 00:05:24,309
known as a SYN flood.

163
00:05:24,309 --> 00:05:25,727
Notice in this packet capture,

164
00:05:25,727 --> 00:05:27,658
we are not seeing any acknowledgements coming back

165
00:05:27,658 --> 00:05:30,220
from that destination server to our source,

166
00:05:30,220 --> 00:05:32,793
and we're not seeing any SYN-ACKs going from our source

167
00:05:32,793 --> 00:05:34,393
back to our destination.

168
00:05:34,393 --> 00:05:35,226
So what we have here

169
00:05:35,226 --> 00:05:37,320
is the first step in a three-way handshake,

170
00:05:37,320 --> 00:05:40,614
but the second and third steps are not being completed.

171
00:05:40,614 --> 00:05:41,895
Now, the reason I'm showing you this

172
00:05:41,895 --> 00:05:43,746
is because this is another type of attack

173
00:05:43,746 --> 00:05:45,837
that you're going to see commonly used in your logs,

174
00:05:45,837 --> 00:05:47,429
where an attacker will use a SYN packet

175
00:05:47,429 --> 00:05:49,404
as a way to start a half-open connection

176
00:05:49,404 --> 00:05:51,560
and they won't finish the connection.

177
00:05:51,560 --> 00:05:52,399
When this happens,

178
00:05:52,399 --> 00:05:55,000
it eats up resources on that destination server,

179
00:05:55,000 --> 00:05:57,160
and eventually, that server can actually crash

180
00:05:57,160 --> 00:05:59,362
if there's too many open requests.

181
00:05:59,362 --> 00:06:01,605
Let's move on to our third packet capture.

182
00:06:01,605 --> 00:06:02,753
Now, our third packet capture

183
00:06:02,753 --> 00:06:05,208
actually has over 3,500 packets,

184
00:06:05,208 --> 00:06:07,704
but again, I'm only showing you about 10 of them here,

185
00:06:07,704 --> 00:06:09,864
and I'm using a bunch of dot dots to be able

186
00:06:09,864 --> 00:06:10,697
to hide the fact

187
00:06:10,697 --> 00:06:12,421
that there are a bunch of things that are missing.

188
00:06:12,421 --> 00:06:13,822
Now, as we go through here,

189
00:06:13,822 --> 00:06:16,142
you're going to see it looks very similar to the last one,

190
00:06:16,142 --> 00:06:16,975
so you're probably thinking

191
00:06:16,975 --> 00:06:18,972
it's some kind of a Denial of Service Attack,

192
00:06:18,972 --> 00:06:20,535
and you'd be right.

193
00:06:20,535 --> 00:06:21,560
Now, as you look through,

194
00:06:21,560 --> 00:06:23,189
one of the differences of this one

195
00:06:23,189 --> 00:06:24,706
versus the last packet capture

196
00:06:24,706 --> 00:06:27,432
is that we all have the same destination being targeted,

197
00:06:27,432 --> 00:06:29,771
but we're using different sources.

198
00:06:29,771 --> 00:06:31,471
Notice that the first 1000 packets

199
00:06:31,471 --> 00:06:34,721
were all being used from 192.168.1.101.

200
00:06:35,854 --> 00:06:37,789
Now, they were trying to do a SYN flood

201
00:06:37,789 --> 00:06:39,279
as a Denial of Service Attack,

202
00:06:39,279 --> 00:06:40,424
and it appears that that wasn't successful

203
00:06:40,424 --> 00:06:42,612
because the server was still responding,

204
00:06:42,612 --> 00:06:44,094
so they started bringing in other hosts as well

205
00:06:44,094 --> 00:06:45,909
to start sending traffic.

206
00:06:45,909 --> 00:06:50,226
So you'll see that the first one was 192.168.1.101.

207
00:06:50,226 --> 00:06:52,053
If we drop down to packet 1500,

208
00:06:52,053 --> 00:06:56,616
we can see that the source there is 192.168.1.102.

209
00:06:56,616 --> 00:07:01,516
If we go down to Packet 2000, we see 192.168.1.103.

210
00:07:01,516 --> 00:07:04,599
We go to 2,500, we see 192.168.1.104,

211
00:07:05,467 --> 00:07:08,133
and every 500, we're going to another system

212
00:07:08,133 --> 00:07:10,198
and using a different IP address.

213
00:07:10,198 --> 00:07:11,276
So, what this is showing us

214
00:07:11,276 --> 00:07:13,515
is this is a Distributed Denial of Service Attack

215
00:07:13,515 --> 00:07:15,922
where we have multiple systems all going and attacking

216
00:07:15,922 --> 00:07:17,394
the same server.

217
00:07:17,394 --> 00:07:18,824
Now, in the case of this packet capture,

218
00:07:18,824 --> 00:07:21,144
we can see that we had 3,500 packets being sent

219
00:07:21,144 --> 00:07:23,428
in about 1.75 seconds

220
00:07:23,428 --> 00:07:26,276
from across multiple different IP addresses.

221
00:07:26,276 --> 00:07:28,437
And so as we went into something at scale,

222
00:07:28,437 --> 00:07:30,677
you might see hundreds or hundreds of thousands

223
00:07:30,677 --> 00:07:33,320
of these packets from various IP addresses

224
00:07:33,320 --> 00:07:35,522
that are all attacking you as part of a botnet

225
00:07:35,522 --> 00:07:37,818
inside of this type of a packet capture.

226
00:07:37,818 --> 00:07:38,859
But, what we're trying to demonstrate here

227
00:07:38,859 --> 00:07:40,210
is the idea that you could see

228
00:07:40,210 --> 00:07:41,909
a Distributed Denial of Service Attack

229
00:07:41,909 --> 00:07:43,759
inside of a packet capture.

230
00:07:43,759 --> 00:07:45,245
Now, for the exam, it is possible

231
00:07:45,245 --> 00:07:48,293
that you would get a packet capture that has 5, 10, 15,

232
00:07:48,293 --> 00:07:49,710
or 20 lines like this.

233
00:07:49,710 --> 00:07:52,274
And often, those people who already work in the field

234
00:07:52,274 --> 00:07:54,209
look at this and go, "I don't have enough information

235
00:07:54,209 --> 00:07:55,309
to make a decision."

236
00:07:55,309 --> 00:07:56,142
And you're right.

237
00:07:56,142 --> 00:07:56,975
In the real world,

238
00:07:56,975 --> 00:07:59,281
I wouldn't call this a Distributed Denial of Service Attack

239
00:07:59,281 --> 00:08:01,844
just by seeing these 10 or 15 lines,

240
00:08:01,844 --> 00:08:04,450
but again, you have to ask yourself on the exam,

241
00:08:04,450 --> 00:08:07,723
"What are they trying to show me in 5 or 10 or 15 lines?"

242
00:08:07,723 --> 00:08:09,456
And the most obvious thing here would be

243
00:08:09,456 --> 00:08:11,357
that we have a Distributed Denial of Service Attack

244
00:08:11,357 --> 00:08:13,315
because we are doing these half-open connections

245
00:08:13,315 --> 00:08:15,488
to eat up resources on the same server,

246
00:08:15,488 --> 00:08:18,142
and all of the destinations are the same server IP,

247
00:08:18,142 --> 00:08:20,616
but the sources are coming from different places.

248
00:08:20,616 --> 00:08:23,179
So, this would be a Distributed Denial of Service Attack.

249
00:08:23,179 --> 00:08:24,581
Whereas when we looked at number two,

250
00:08:24,581 --> 00:08:26,552
all of the sources were one computer

251
00:08:26,552 --> 00:08:28,795
and all the destination was one server,

252
00:08:28,795 --> 00:08:30,875
so that was a regular Denial of Service Attack.

253
00:08:30,875 --> 00:08:32,630
Keep this in mind as you're taking the exam,

254
00:08:32,630 --> 00:08:33,642
and you'll do really well

255
00:08:33,642 --> 00:08:35,373
when you're looking at these packet captures.

