SOC Analyst Skills - Wireshark Malicious Traffic Analysis

แชร์
ฝัง
  • เผยแพร่เมื่อ 29 ก.ย. 2024
  • In this video I walk through the analysis of a malicious PCAP file. PCAP files are captured network traffic, and analysis of it is often done to understand what happened in an incident. Security Operations Center (SOC) Analysts often have to do use this tool and do this type of work.
    We pull a malicious PCAP file "Okay Boomer" from www.malware-tr... and open it with Wireshark. SOC analysts analyze endpoints and network traffic as part of their regular job duties. Knowing how to use Wireshark at a basic level will serve you well.
    Empower yourself to confiently share at a SOC anlayst interview that you have proactively done malicious network traffic analysis using Wireshark.
    Wireshark Download: wireshark.org
    Malware PCAP files: www.malware-tr...
    VirusTotal: www.virustotal...
    📱 Social Media
    LinkedIn: / geraldauger
    Twitter: / gerald_auger
    TH-cam: / geraldauger
    Discord: / discord
    Twitch: / gerald_auger_simplycyber
    🔥 My Curated Website of Free Cyber Resources
    SimplyCyber.io
    📷 🎙 💡 MY STUDIO SETUP
    📷 Camera / Video
    Sony Alpha a6400 amzn.to/2TZliEb
    Sigma 30mm F1.4 amzn.to/3hEJFA2
    Gonine AC-PW20 AC Adapter (for a6400) amzn.to/3wDZBqc
    Fotga 52mm Slim Fader amzn.to/3khne5w
    Boom Scissor Arm Stand amzn.to/3efSv5b
    Logitech C922 Pro Stream Webcam 1080P amzn.to/3i8AI0B
    BlueAVS HDMI to USB Video Capture Card 1080P amzn.to/3i5JAEk
    Anker USB C to HDMI Adapter amzn.to/3kjjoJ4
    60-Inch Lightweight Tripod amzn.to/36B5j1u
    5X 6.5ft Portable Green Screen Chromakey Collapsible amzn.to/3efW9Mp
    Glide Gear TMP100 Adjustable Teleprompter amzn.to/3B36DrZ
    🎙 Audio
    Blue Yeti Nano Premium USB Mic amzn.to/3efWcb3
    BOYA BY-M1 3.5mm Electret Condenser Microphone amzn.to/3AZzJIN
    Boom Scissor Arm Stand amzn.to/3efSv5b
    Neewer Professional Microphone Pop Filter Shield amzn.to/3ekdZOi
    💡 Lighting
    UBeesize 10’’ LED Ring Light amzn.to/3i23qAm
    Neewer Ring Light Kit:18"/48cm Outer 55W 5500K Dimmable LED Ring Light amzn.to/2U0slwo
    Fovitec 2-Light High-Power Fluorescent Studio Lighting Kit amzn.to/36zDS8A
    Neewer 2-Pack Dimmable 5600K USB LED amzn.to/3B0crCQ
    Neewer 480 RGB Led Light amzn.to/2Vzwmbf
    60-Inch Lightweight Tripod amzn.to/36B5j1u
    🧑🏻‍💻 Workstation
    2020 Apple Mac Mini with Apple M1 Chip amzn.to/3wybMVL
    Logitech MX Master 3 Advanced Wireless Mouse amzn.to/3xFCkWp
    Apple Magic Keyboard amzn.to/3ehMRiP
    Huanuo Dual Monitor Stand Mount amzn.to/3keFZqc
    Dell U2717D IPS 27" UltraSharp InfinityEdge Slim Widescreen amzn.to/36znqoG
    USB C to SD Card Reader amzn.to/2VG1RRd
    StarTech 2 Port USB C KVM Switchamzn.to/3efWoa7
    Toshiba Canvio Basics 1TB Portable External Hard Drive USB 3.0 amzn.to/3hZOK4A
    External Hard Drive Portable Carrying Case amzn.to/3r62XRM
    Mountable Surge Protector Power Strip with USB 5 Outlets 3 USB Ports amzn.to/3wDmlqv
    🥼 Raspberry Pi Lab
    Raspberry SC15184 Pi 4 Model B 2019 Quad Core 64 Bit WiFi Bluetooth (2GB) amzn.to/3i61EhI
    Miuzei Case for Raspberry Pi amzn.to/2Vzyrnz
    Micro Center 32GB Class 10 Micro SDHC Flash Memory Card with Adapter amzn.to/3B0Qm6X
    Micro HDMI to HDMI Cable 6FT amzn.to/3ekpiG3
    👉 Some product links are affiliate links which means if you buy something SimplyCyber receives a small commission (but it all costs the same to you, so consider it supporting the channel 😉 )
    🙌🏼 Donate
    Like the channel and got value? Please consider supporting the channel
    www.buymeacoff...
    😎 Merch 😎
    👉🏼 SimplyCyber Branded Gear: teespring.com/...
    🎥 Livestreams are produced through StreamYard.
    $10 credit using my referral link below if you ever upgrade to pro plan.
    streamyard.com?pal=6534222448689152
    Disclaimer: All content reflects the thoughts and opinions of Gerald Auger and the speakers themselves, and are not affiliated with the employer of those individuals unless explicitly stated.

ความคิดเห็น • 70

  • @xboutdattime89
    @xboutdattime89 4 ปีที่แล้ว +17

    Hell yeah man, I'm studying for the sec+ and can't find many good videos on the tools I'll be using so thank you for this! Definitely gonna sub & check out your other videos after this one

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว +1

      Happy to help! Best wishes on Sec+.

  • @christophercahall3092
    @christophercahall3092 9 หลายเดือนก่อน

    such a young buckgrow up so fast

  • @yankeesouth
    @yankeesouth 2 ปีที่แล้ว +11

    I am preparing for a SOC I technical interview. This is at least the 3rd video of yours that I have found extremely helpful. Thank you for continuing to make amazing content.

    • @SimplyCyber
      @SimplyCyber  2 ปีที่แล้ว +1

      I hope the interview went wonderful. Any similar questions come up??

    • @mohameddaud3899
      @mohameddaud3899 ปีที่แล้ว

      How was the technical interview? were u asked about wireshark?

  • @satishrkulkarni114
    @satishrkulkarni114 6 หลายเดือนก่อน

    How long should traffic be captured which is indicative of malware, RAT,?
    Do malware send beacons if the phone is idle yet connected to the internet ?
    Kindly advice.

  • @Anandroid
    @Anandroid ปีที่แล้ว +1

    Is there anyone on TH-cam that worked each exercise? Can't find anyone or a playlist. Would be awesome.

    • @SimplyCyber
      @SimplyCyber  ปีที่แล้ว

      Not that I know of but a fun content idea. Thx

    • @Anandroid
      @Anandroid ปีที่แล้ว

      @@SimplyCyber YOU SHOULD!!! It would be a game changer.

  • @thuglife896
    @thuglife896 4 ปีที่แล้ว +3

    You can run malicious files inside a Sandbox such as VirtualBox / VMware etc ... As long as you disable VM to host sharing it should be safe

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว +2

      ThugLife another great option. Just measure twice cut once. 😉

  • @johnvardy9559
    @johnvardy9559 8 หลายเดือนก่อน

    Around Tshark tcpdump are important tools as analyst?

  • @leandrokogan141
    @leandrokogan141 4 ปีที่แล้ว +7

    This is pure gold!!!

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว

      Thanks for the kind words! Appreciate you taking the time.

  • @xboutdattime89
    @xboutdattime89 4 ปีที่แล้ว +3

    Any chance you could do videos on other tools and how to get practice at home? Can't find anything like that

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว +4

      Based on the response from this video, sure. I do more than just tools in order to support many angles/needs for folks in the field but I hear you. Was thinking of doing a reverse engineering one, more useful for security researchers , but still fun and can be done at home. Thoughts?

    • @xboutdattime89
      @xboutdattime89 4 ปีที่แล้ว +2

      @@SimplyCyber absolutely do that. That'd be super interesting to see that process. And something like that might spark interest in people who aren't in this field already!

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว +1

      @@xboutdattime89 Coming back now after making a few more tech tool videos. I did do one on reversing: th-cam.com/video/n5j6uJXtJW8/w-d-xo.html and I did one on malware research tools: th-cam.com/video/x0mGxucyZmk/w-d-xo.html

  • @nym4960
    @nym4960 4 ปีที่แล้ว +3

    Great video as someone who wants to get into an SOC analyst role!

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว +1

      Thanks for taking the time to comment. Glad you enjoyed it.

  • @nitricdx
    @nitricdx 4 ปีที่แล้ว +3

    amazing video. subbed.

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว +1

      Thanks so much for the feedback.

  • @robertlemonsjr
    @robertlemonsjr 4 ปีที่แล้ว +2

    Love your content man. Very insightful. Thanks so much

  • @atharvakadlag1937
    @atharvakadlag1937 3 ปีที่แล้ว +1

    great video but bad resolution... my eyes gave up.

    • @SimplyCyber
      @SimplyCyber  3 ปีที่แล้ว

      Thanks for feedback. I've been working on trying to make screen caps better. Its hard to tell when filming what it will look like to audience. I'll keep working at it.

    • @atharvakadlag1937
      @atharvakadlag1937 3 ปีที่แล้ว

      @@SimplyCyber it's alright. The content you are giving is extremely good.

  • @Dalai33
    @Dalai33 ปีที่แล้ว

    You’re simply the best! Just wanted to comment something for the algorithm 🙏🏻🙏🏻♾️

  • @NeuroScientician
    @NeuroScientician 2 ปีที่แล้ว

    You should consider paying someone to market you around TH-cam or something. Your content is incredible. I stumbled on your channel by accident/error. I was about to click on David Bombals video and missed. Instant subscibe.

  • @Saikiran-ln3uw
    @Saikiran-ln3uw 4 ปีที่แล้ว +1

    I'm just curious, how did you find that Website ?

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว +1

      I knew I wanted a PCAP with malicious traffic. I just googled 'malicious pcaps' and clicked on the first result. Pretty awesome resource.

    • @SuperBoinger
      @SuperBoinger 3 ปีที่แล้ว

      @@SimplyCyber Search for Brad Duncan. He teaches excellent malware analysis courses at Bsides. He works for Palo Alto, Unit 42.

  • @zyeuh2565
    @zyeuh2565 4 ปีที่แล้ว +1

    Any chance we can get a video like this but on the Kali box we built in AWS ? Thanks ! Keep up the great work

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว

      Thanks for the comment and request. Great idea! I'll drop an episode June 8th that uses the Kali box we built in the AWS video. Really appreciate you watching.

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว +1

      Today’s show is reversing a firmware using......the kali box

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว

      Just seeing this comment but yes absolutely. I may even do a kali in aws series. Would that be interesting?

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว

      Guess I did see this comment months ago, but still the question sustains today. Let me know

  • @johnvardy9559
    @johnvardy9559 ปีที่แล้ว

    how i become good at wireshark?

    • @SimplyCyber
      @SimplyCyber  ปีที่แล้ว +1

      Do a bunch of the exercises at that site

    • @johnvardy9559
      @johnvardy9559 ปีที่แล้ว

      @@SimplyCyber yes i think exercise it the key.your interractions with us is so amazing thank we learn a lot of you.Also i see people speak among wireshark with Tshark or tcpdump evenso and zeep.Due to overwhelming what do you thing are important for everyday job all of these stuffs?

  • @GracieGarage
    @GracieGarage 4 ปีที่แล้ว +1

    Jerry, Tremendous!

    • @SimplyCyber
      @SimplyCyber  3 ปีที่แล้ว

      Thanks Gracie. Did you dig into the PCAPS? Appreciate the kind words.

  • @mehrdadjoker
    @mehrdadjoker 3 ปีที่แล้ว

    why i can't find download video option ?

  • @stark6314
    @stark6314 3 ปีที่แล้ว

    Thaks sir this will helo me alot in ctfs

  • @jeyav
    @jeyav 3 ปีที่แล้ว

    You are super cool and this excerise is very useful.. keep posting more videos👍🏻

    • @SimplyCyber
      @SimplyCyber  3 ปีที่แล้ว +1

      Thanks Jeyapaul! Appreciate the support and I'm pushing every monday at noon.

  • @joevilleneuve1524
    @joevilleneuve1524 3 ปีที่แล้ว

    how do you get dark mode for wireshark? also, is this available for windows

    • @SimplyCyber
      @SimplyCyber  3 ปีที่แล้ว

      Windows download _ www.wireshark.org/#download
      I do not believe dark mode is a feature in Windows version at this time.

  • @ibrahimabdeltawab6418
    @ibrahimabdeltawab6418 3 ปีที่แล้ว

    Thanks so much! So helpful ❤️

  • @erenkorcan5458
    @erenkorcan5458 ปีที่แล้ว

    thank you mannn

  • @gkess7106
    @gkess7106 2 ปีที่แล้ว

    “Per say“?

  • @zackzayco9135
    @zackzayco9135 3 ปีที่แล้ว

    Great resourceful video

    • @SimplyCyber
      @SimplyCyber  3 ปีที่แล้ว

      Glad it was helpful!

  • @Jotin8664
    @Jotin8664 3 ปีที่แล้ว

    I love this channel!!

  • @dodedodedo22
    @dodedodedo22 2 ปีที่แล้ว +1

    thanks man I actually have an SOC 2 interview on Monday I'm gunna smash this malware traffic analysis site all weekend.

    • @SimplyCyber
      @SimplyCyber  2 ปีที่แล้ว

      It will ready you up. Both practically and if you happen to drop ur doing pcap analysis on the side

  • @enochkay7833
    @enochkay7833 3 ปีที่แล้ว

    How do you know it’s endpoint

    • @SimplyCyber
      @SimplyCyber  3 ปีที่แล้ว +1

      Kay, Not sure what you are referencing here, but taking a guess at what you are asking. An endpoint is a host system on the network, so a laptop, server, IOT, Ring doorbell, smart bulb, etc. They all are assigned IP addresses on the network, and the IP (and MAC address) are what allows endpoints to communicate with other endpoints and network services. If that was your question I hope it answers it.

    • @enochkay7833
      @enochkay7833 3 ปีที่แล้ว

      @@SimplyCyber thank you soo much

  • @kashifrashid9968
    @kashifrashid9968 4 ปีที่แล้ว +1

    Great video. You've made it really easy to understand. Thank you

    • @SimplyCyber
      @SimplyCyber  4 ปีที่แล้ว

      Yes! Thats my goal. Thanks for sharing.

  • @NastyaSousa
    @NastyaSousa ปีที่แล้ว

    Can you explain please how do I add Cname string column?

    • @SimplyCyber
      @SimplyCyber  ปีที่แล้ว

      Can you rephrase the question?