Capture, analyze, and report, network forensics exercises for C2 beaconing and covert exfiltration channels
The network sensor at Tidewater Municipal Utility flags periodic outbound traffic from HMI-ENG01, an engineering workstation on the OT network. Analyze a rendered packet list, Zeek conn/dns/ssl logs, and a decoded proxy log to determine whether the traffic is benign telemetry or command-and-control beaconing, identify the exfiltration channel, and quantify what left the network.
A network-attached office printer at Fenwick Legal Group starts scanning the internal subnet on Telnet port 23 and appears in an external threat-intel feed's list of hosts joining a known IoT botnet. Analyze conn.log, notice.log, and a Telnet session capture to determine how the printer was compromised and what it has been doing since.
A developer workstation at Larkspur FinTech shows recurring HTTPS traffic to a legitimate, widely-used code-paste service, well within normal developer behavior on its face. A SOC analyst notices the requests never change destination and always occur exactly ten minutes apart. Determine whether a legitimate developer habit is hiding a dead-drop command-and-control channel.
At the Wrenfield Water Treatment Plant, an operator notices the chlorine dosing pump's flow rate display briefly shows an unexpected value before snapping back. The plant's OT network taps a Modbus/TCP segment feeding the dosing PLC. Analyze the protocol-level Modbus traffic to determine whether an unauthorized write command reached the PLC, from where, and whether it succeeded.
A workstation at Halden Biotech makes routine-looking HTTPS connections to a reputable CDN edge domain already on the corporate allow-list. A TLS-inspecting proxy log shows the encrypted HTTP Host header inside those connections names a domain nobody recognizes. Analyze Zeek ssl.log, the decrypted proxy log, and passive DNS/WHOIS to determine whether this is legitimate multi-tenant CDN hosting or a domain-fronted command-and-control channel.
At Corvid Analytics, a domain controller alert fires when one workstation's service account authenticates against three other workstations within two minutes. Analyze Zeek smb_mapping.log, smb_files.log, and dce_rpc.log captured on an internal SPAN port, alongside Windows service-creation events, to reconstruct how a single compromised workstation used SMB to move laterally and what it deployed on its targets.
A firewall at Marrow Creek Financial logs an unusual volume of outbound ICMP echo requests from a finance workstation to an external host, far more requests than matching replies. Analyze Zeek conn.log and raw tshark ICMP payload/timing fields to determine whether this is a misbehaving diagnostic tool or a covert exfiltration channel hidden inside ping traffic.
At Thessaly Insurance, an analyst reviewing egress traffic finds a claims-processing workstation sending large, sustained UDP/443 QUIC traffic to an IP with no reverse DNS and an unfamiliar SNI. Zeek's QUIC log captures handshake metadata but nothing at the HTTP layer. Determine what can, and cannot, be concluded from the visibility actually available, and how to close the gap.
At Alder Point Logistics, an NDR platform flags a warehouse management server for beacon-like outbound HTTPS traffic recurring every 15 minutes overnight, every night. Analyze Zeek conn.log and ssl.log alongside the software asset inventory to determine whether this matches the profile of C2 beaconing or a legitimate, if under-documented, backup agent.
At Sable Ridge Manufacturing, users on one office VLAN report intermittent trouble reaching the file server, and one user's browser throws a certificate warning for an internal HR portal that never showed one before. Analyze an arpwatch alert, a raw ARP capture, and a switch's Dynamic ARP Inspection log to determine whether an on-path attacker is intercepting traffic on this VLAN.