Network ForensicsIntermediateFree, no sign-up
Beacon in the Noise
A case from the PCAP Analysis Lab
Briefing
A network sensor on the OT segment of a fictional municipal utility flags periodic outbound traffic from an engineering workstation that should never talk to the internet, followed hours later by a burst of unusual name lookups. Work a decoded capture of over a thousand packets: confirm or refute the beaconing, find the real exfiltration channel, and quantify what left the plant.
1013 events9 log sourcesabout 45 min
Solve this case
Opens the lab with this case selected. Graded in the browser; nothing to install.
What you will practise
- Reading a decoded packet list and conversation view
- Recognising beaconing by timing rather than by signature
- Spotting covert channels inside ordinary-looking protocols
- Quantifying exfiltration from flow and payload sizes
Maps to these certifications
GCIAGNFAGCIHCySA+
Log sources in the corpus
TCP · TLS · HTTP · DNS · ARP · ICMP · NTP · Modbus · OPC-UA
How a case works
- Read the briefing: the alert as the analyst received it, the environment and the time window.
- Work the console: search, filter and pivot across every source; open raw lines; pin evidence.
- Fill the investigation form and write a short executive summary. Hints are available and cost points.
- Get graded per item with the evidence behind each answer, then share your result card.