SOC Analyst Skills - Wireshark Malicious Traffic Analysis

Поделиться
HTML-код
  • Опубликовано: 3 окт 2024
  • In this video I walk through the analysis of a malicious PCAP file. PCAP files are captured network traffic, and analysis of it is often done to understand what happened in an incident. Security Operations Center (SOC) Analysts often have to do use this tool and do this type of work.
    We pull a malicious PCAP file "Okay Boomer" from www.malware-tr... and open it with Wireshark. SOC analysts analyze endpoints and network traffic as part of their regular job duties. Knowing how to use Wireshark at a basic level will serve you well.
    Empower yourself to confiently share at a SOC anlayst interview that you have proactively done malicious network traffic analysis using Wireshark.
    Wireshark Download: wireshark.org
    Malware PCAP files: www.malware-tr...
    VirusTotal: www.virustotal...
    📱 Social Media
    LinkedIn: / geraldauger
    Twitter: / gerald_auger
    RUclips: / geraldauger
    Discord: / discord
    Twitch: / gerald_auger_simplycyber
    🔥 My Curated Website of Free Cyber Resources
    SimplyCyber.io
    📷 🎙 💡 MY STUDIO SETUP
    📷 Camera / Video
    Sony Alpha a6400 amzn.to/2TZliEb
    Sigma 30mm F1.4 amzn.to/3hEJFA2
    Gonine AC-PW20 AC Adapter (for a6400) amzn.to/3wDZBqc
    Fotga 52mm Slim Fader amzn.to/3khne5w
    Boom Scissor Arm Stand amzn.to/3efSv5b
    Logitech C922 Pro Stream Webcam 1080P amzn.to/3i8AI0B
    BlueAVS HDMI to USB Video Capture Card 1080P amzn.to/3i5JAEk
    Anker USB C to HDMI Adapter amzn.to/3kjjoJ4
    60-Inch Lightweight Tripod amzn.to/36B5j1u
    5X 6.5ft Portable Green Screen Chromakey Collapsible amzn.to/3efW9Mp
    Glide Gear TMP100 Adjustable Teleprompter amzn.to/3B36DrZ
    🎙 Audio
    Blue Yeti Nano Premium USB Mic amzn.to/3efWcb3
    BOYA BY-M1 3.5mm Electret Condenser Microphone amzn.to/3AZzJIN
    Boom Scissor Arm Stand amzn.to/3efSv5b
    Neewer Professional Microphone Pop Filter Shield amzn.to/3ekdZOi
    💡 Lighting
    UBeesize 10’’ LED Ring Light amzn.to/3i23qAm
    Neewer Ring Light Kit:18"/48cm Outer 55W 5500K Dimmable LED Ring Light amzn.to/2U0slwo
    Fovitec 2-Light High-Power Fluorescent Studio Lighting Kit amzn.to/36zDS8A
    Neewer 2-Pack Dimmable 5600K USB LED amzn.to/3B0crCQ
    Neewer 480 RGB Led Light amzn.to/2Vzwmbf
    60-Inch Lightweight Tripod amzn.to/36B5j1u
    🧑🏻‍💻 Workstation
    2020 Apple Mac Mini with Apple M1 Chip amzn.to/3wybMVL
    Logitech MX Master 3 Advanced Wireless Mouse amzn.to/3xFCkWp
    Apple Magic Keyboard amzn.to/3ehMRiP
    Huanuo Dual Monitor Stand Mount amzn.to/3keFZqc
    Dell U2717D IPS 27" UltraSharp InfinityEdge Slim Widescreen amzn.to/36znqoG
    USB C to SD Card Reader amzn.to/2VG1RRd
    StarTech 2 Port USB C KVM Switchamzn.to/3efWoa7
    Toshiba Canvio Basics 1TB Portable External Hard Drive USB 3.0 amzn.to/3hZOK4A
    External Hard Drive Portable Carrying Case amzn.to/3r62XRM
    Mountable Surge Protector Power Strip with USB 5 Outlets 3 USB Ports amzn.to/3wDmlqv
    🥼 Raspberry Pi Lab
    Raspberry SC15184 Pi 4 Model B 2019 Quad Core 64 Bit WiFi Bluetooth (2GB) amzn.to/3i61EhI
    Miuzei Case for Raspberry Pi amzn.to/2Vzyrnz
    Micro Center 32GB Class 10 Micro SDHC Flash Memory Card with Adapter amzn.to/3B0Qm6X
    Micro HDMI to HDMI Cable 6FT amzn.to/3ekpiG3
    👉 Some product links are affiliate links which means if you buy something SimplyCyber receives a small commission (but it all costs the same to you, so consider it supporting the channel 😉 )
    🙌🏼 Donate
    Like the channel and got value? Please consider supporting the channel
    www.buymeacoff...
    😎 Merch 😎
    👉🏼 SimplyCyber Branded Gear: teespring.com/...
    🎥 Livestreams are produced through StreamYard.
    $10 credit using my referral link below if you ever upgrade to pro plan.
    streamyard.com?pal=6534222448689152
    Disclaimer: All content reflects the thoughts and opinions of Gerald Auger and the speakers themselves, and are not affiliated with the employer of those individuals unless explicitly stated.

Комментарии • 70

  • @yankeesouth
    @yankeesouth 2 года назад +10

    I am preparing for a SOC I technical interview. This is at least the 3rd video of yours that I have found extremely helpful. Thank you for continuing to make amazing content.

    • @SimplyCyber
      @SimplyCyber  2 года назад +1

      I hope the interview went wonderful. Any similar questions come up??

    • @mohameddaud3899
      @mohameddaud3899 Год назад

      How was the technical interview? were u asked about wireshark?

  • @xboutdattime89
    @xboutdattime89 4 года назад +16

    Hell yeah man, I'm studying for the sec+ and can't find many good videos on the tools I'll be using so thank you for this! Definitely gonna sub & check out your other videos after this one

    • @SimplyCyber
      @SimplyCyber  4 года назад +1

      Happy to help! Best wishes on Sec+.

  • @leandrokogan141
    @leandrokogan141 4 года назад +7

    This is pure gold!!!

    • @SimplyCyber
      @SimplyCyber  4 года назад

      Thanks for the kind words! Appreciate you taking the time.

  • @Dalai33
    @Dalai33 Год назад

    You’re simply the best! Just wanted to comment something for the algorithm 🙏🏻🙏🏻♾️

  • @nym4960
    @nym4960 4 года назад +3

    Great video as someone who wants to get into an SOC analyst role!

    • @SimplyCyber
      @SimplyCyber  4 года назад +1

      Thanks for taking the time to comment. Glad you enjoyed it.

  • @robertlemonsjr
    @robertlemonsjr 4 года назад +2

    Love your content man. Very insightful. Thanks so much

  • @NeuroScientician
    @NeuroScientician 2 года назад

    You should consider paying someone to market you around RUclips or something. Your content is incredible. I stumbled on your channel by accident/error. I was about to click on David Bombals video and missed. Instant subscibe.

  • @kashifrashid9968
    @kashifrashid9968 4 года назад +1

    Great video. You've made it really easy to understand. Thank you

    • @SimplyCyber
      @SimplyCyber  4 года назад

      Yes! Thats my goal. Thanks for sharing.

  • @dodedodedo22
    @dodedodedo22 2 года назад +1

    thanks man I actually have an SOC 2 interview on Monday I'm gunna smash this malware traffic analysis site all weekend.

    • @SimplyCyber
      @SimplyCyber  2 года назад

      It will ready you up. Both practically and if you happen to drop ur doing pcap analysis on the side

  • @thuglife896
    @thuglife896 4 года назад +3

    You can run malicious files inside a Sandbox such as VirtualBox / VMware etc ... As long as you disable VM to host sharing it should be safe

    • @SimplyCyber
      @SimplyCyber  4 года назад +2

      ThugLife another great option. Just measure twice cut once. 😉

  • @nitricdx
    @nitricdx 4 года назад +3

    amazing video. subbed.

    • @SimplyCyber
      @SimplyCyber  4 года назад +1

      Thanks so much for the feedback.

  • @Jotin8664
    @Jotin8664 3 года назад

    I love this channel!!

  • @GracieGarage
    @GracieGarage 4 года назад +1

    Jerry, Tremendous!

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Thanks Gracie. Did you dig into the PCAPS? Appreciate the kind words.

  • @jeyav
    @jeyav 3 года назад

    You are super cool and this excerise is very useful.. keep posting more videos👍🏻

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      Thanks Jeyapaul! Appreciate the support and I'm pushing every monday at noon.

  • @stark6314
    @stark6314 3 года назад

    Thaks sir this will helo me alot in ctfs

  • @ibrahimabdeltawab6418
    @ibrahimabdeltawab6418 3 года назад

    Thanks so much! So helpful ❤️

  • @zackzayco9135
    @zackzayco9135 3 года назад

    Great resourceful video

  • @christophercahall3092
    @christophercahall3092 10 месяцев назад

    such a young buckgrow up so fast

  • @satishrkulkarni114
    @satishrkulkarni114 6 месяцев назад

    How long should traffic be captured which is indicative of malware, RAT,?
    Do malware send beacons if the phone is idle yet connected to the internet ?
    Kindly advice.

  • @Anandroid
    @Anandroid Год назад +1

    Is there anyone on RUclips that worked each exercise? Can't find anyone or a playlist. Would be awesome.

    • @SimplyCyber
      @SimplyCyber  Год назад

      Not that I know of but a fun content idea. Thx

    • @Anandroid
      @Anandroid Год назад

      @@SimplyCyber YOU SHOULD!!! It would be a game changer.

  • @erenkorcan5458
    @erenkorcan5458 Год назад

    thank you mannn

  • @johnvardy9559
    @johnvardy9559 8 месяцев назад

    Around Tshark tcpdump are important tools as analyst?

  • @xboutdattime89
    @xboutdattime89 4 года назад +3

    Any chance you could do videos on other tools and how to get practice at home? Can't find anything like that

    • @SimplyCyber
      @SimplyCyber  4 года назад +4

      Based on the response from this video, sure. I do more than just tools in order to support many angles/needs for folks in the field but I hear you. Was thinking of doing a reverse engineering one, more useful for security researchers , but still fun and can be done at home. Thoughts?

    • @xboutdattime89
      @xboutdattime89 4 года назад +2

      @@SimplyCyber absolutely do that. That'd be super interesting to see that process. And something like that might spark interest in people who aren't in this field already!

    • @SimplyCyber
      @SimplyCyber  4 года назад +1

      @@xboutdattime89 Coming back now after making a few more tech tool videos. I did do one on reversing: ruclips.net/video/n5j6uJXtJW8/видео.html and I did one on malware research tools: ruclips.net/video/x0mGxucyZmk/видео.html

  • @zyeuh2565
    @zyeuh2565 4 года назад +1

    Any chance we can get a video like this but on the Kali box we built in AWS ? Thanks ! Keep up the great work

    • @SimplyCyber
      @SimplyCyber  4 года назад

      Thanks for the comment and request. Great idea! I'll drop an episode June 8th that uses the Kali box we built in the AWS video. Really appreciate you watching.

    • @SimplyCyber
      @SimplyCyber  4 года назад +1

      Today’s show is reversing a firmware using......the kali box

    • @SimplyCyber
      @SimplyCyber  4 года назад

      Just seeing this comment but yes absolutely. I may even do a kali in aws series. Would that be interesting?

    • @SimplyCyber
      @SimplyCyber  4 года назад

      Guess I did see this comment months ago, but still the question sustains today. Let me know

  • @atharvakadlag1937
    @atharvakadlag1937 3 года назад +1

    great video but bad resolution... my eyes gave up.

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Thanks for feedback. I've been working on trying to make screen caps better. Its hard to tell when filming what it will look like to audience. I'll keep working at it.

    • @atharvakadlag1937
      @atharvakadlag1937 3 года назад

      @@SimplyCyber it's alright. The content you are giving is extremely good.

  • @gkess7106
    @gkess7106 2 года назад

    “Per say“?

  • @mehrdadjoker
    @mehrdadjoker 3 года назад

    why i can't find download video option ?

  • @Saikiran-ln3uw
    @Saikiran-ln3uw 4 года назад +1

    I'm just curious, how did you find that Website ?

    • @SimplyCyber
      @SimplyCyber  4 года назад +1

      I knew I wanted a PCAP with malicious traffic. I just googled 'malicious pcaps' and clicked on the first result. Pretty awesome resource.

    • @SuperBoinger
      @SuperBoinger 3 года назад

      @@SimplyCyber Search for Brad Duncan. He teaches excellent malware analysis courses at Bsides. He works for Palo Alto, Unit 42.

  • @joevilleneuve1524
    @joevilleneuve1524 3 года назад

    how do you get dark mode for wireshark? also, is this available for windows

    • @SimplyCyber
      @SimplyCyber  3 года назад

      Windows download _ www.wireshark.org/#download
      I do not believe dark mode is a feature in Windows version at this time.

  • @johnvardy9559
    @johnvardy9559 Год назад

    how i become good at wireshark?

    • @SimplyCyber
      @SimplyCyber  Год назад +1

      Do a bunch of the exercises at that site

    • @johnvardy9559
      @johnvardy9559 Год назад

      @@SimplyCyber yes i think exercise it the key.your interractions with us is so amazing thank we learn a lot of you.Also i see people speak among wireshark with Tshark or tcpdump evenso and zeep.Due to overwhelming what do you thing are important for everyday job all of these stuffs?

  • @NastyaSousa
    @NastyaSousa Год назад

    Can you explain please how do I add Cname string column?

  • @enochkay7833
    @enochkay7833 3 года назад

    How do you know it’s endpoint

    • @SimplyCyber
      @SimplyCyber  3 года назад +1

      Kay, Not sure what you are referencing here, but taking a guess at what you are asking. An endpoint is a host system on the network, so a laptop, server, IOT, Ring doorbell, smart bulb, etc. They all are assigned IP addresses on the network, and the IP (and MAC address) are what allows endpoints to communicate with other endpoints and network services. If that was your question I hope it answers it.

    • @enochkay7833
      @enochkay7833 3 года назад

      @@SimplyCyber thank you soo much