Project Part 1: Network SurveyProject Part 2: Network Design Final Project: Network Security Plan

profileNavaneeth
Netwitness_File_Capture.pdf

NetWitness Investigator Navigation View Cipher Name (2 items)

aes256-ctr (3) - rsa-with-rc4-128-md5 (1)

Database Name (5 items) msdb (1) - master (1) - fe_db (1) - discovery_db (1) - ? (1)

E-mail Address (2 items) [email protected] (1) - [email protected] (1)

Attachment (1 item) creditcards.txt (1)

Directory (1 item) /samplepage/ (2)

Extension (3 items) <none> (4) - pdf (3) - jpg (2)

Filename (7 items) anyconnect_adminguide.pdf (3) - an (3) - nw-world.jpg (1) - nw-news.jpg (1) - nw-header.jpg (1) - nw-footer.jpg (1) - <none> (1)

Password [open]

Action Event (6 items) login (9) - put (6) - get (3) - sendto (2) - sendfrom (2) - attach (2)

Client Application (2 items) mozilla/4.0 (2) - https (1)

Content Type (4 items) image/jpeg (2) - text/html (1) - message/rfc822 (1) - mail (1)

Link to Data [open]

Stream Info (2 items) 2 (61) - 1 (9)

Destination Domain (3 items) cox.net (21) - intermedia.net (2) - kimsufi.com (1)

Ethernet Protocol (2 items) IP (67) - ARP (3)

Page 1 of 3

9/26/2020res://C:\Program Files\RSA\NetWitness Investigator 11.4\NwInvestigator.exe/153

Hostname Aliases (12 items) besespecially.com (4) - protectedreally.com (3) - definitelyfriendly.com (3) - bestremarkably.com (3) - www.netwitness.com (2) - truly- secure.com (1) - securetruly.com (1) - securereally.com (1) - resolution-sharp.com (1) - definitelysociable.com (1) - decision-intelligent.com (1) - bright-decision.com (1)

Source IP Address (12 items) 172.30.0.2 (27) - 10.21.3.35 (20) - 172.30.0.8 (3) - 172.16.20.99 (3) - 172.16.8.99 (3) - 10.21.3.39 (3) - 10.21.2.52 (3) - 192.168.88.4 192.168.1.112 (1) - 192.168.1.80 (1) - 192.168.1.79 (1) - 64.57.248.132 (1)

Destination IP address (17 items) 172.30.0.8 (21) - 68.100.16.30 (20) - 172.30.0.255 (3) - 172.30.0.200 (3) - 172.30.0.2 (3) - 172.16.20.5 (3) - 172.16.8.5 (3) - 64.78.4.164 (2) - 208.239.76.99 (1) - 192.168.1.70 (1) - 168.75.65.78 (1) - 87.98.217.43 (1) - 68.1.17.2 (1) - 65.54.228.55 (1) - 63.228.228.8 (1) 10.21.4.100 (1) - 10.21.3.40 (1)

IP Aliases (20 of 131+ items) 62.182.74.248 (7) - 212.15.147.61 (6) - 89.169.17.245 (6) - 87.228.112.123 (6) - 87.228.66.14 (6) - 80.128.218.122 (6) - 79.207.129.237 (6) - 79.113.49.138 (6) - 78.94.93.114 (6) - 124.51.106.152 (5) - 99.248.119.110 (5) - 91.66.73.128 (5) - 89.252.10.154 (5) - 80.217.188.185 (5) - 80.171.120.103 (5) - 195.138.107.171 (4) - 195.24.148.53 (4) - 189.3.102.153 (4) - 87.122.166.45 (4) - 84.51.87.10 (4) [more]

Ethernet Source (10 items) FA:42:2C:EF:F8:7B (36) - 00:16:CB:9E:16:A8 (20) - 02:A7:C3:A4:DA:FC (3) - 00:11:0A:A4:3C:98 (3) - 00:0B:DB:0F:46:C1 (3) - 00:B0:D0:A5:87:AB (1) - 00:50:DA:04:EF:7F (1) - 00:1F:C6:2B:FA:F6 (1) - 00:1A:70:8E:69:0D (1) - 00:01:03:C5:66:6A (1)

Ethernet Destination (9 items) 00:1A:70:8E:69:0D (26) - 02:A7:C3:A4:DA:FC (21) - 32:15:6E:AD:85:EF (9) - FF:FF:FF:FF:FF:FF (6) - FA:42:2C:EF:F8:7B (3) - 00:05:32:83:23:CF (2) - 00:A0:CC:51:A9:C9 (1) - 00:0F:B5:0E:B5:A3 (1) - 00:04:F2:05:6C:C0 (1)

IP Protocol (3 items) TCP (31) - UDP (30) - ICMP (6)

Service Type (12 items) OTHER (30) - DNS (20) - FTP (6) - TFTP (3) - SSH (3) - HTTP (2) - IRC (1) - RTP (1) - TDS (1) - MSN IM (1) - SSL (1) - POP3 (1)

TCP Source Port (17 items) 1587 (3) - 1586 (3) - 1585 (3) - 1584 (3) - 1583 (3) - 1580 (3) - 1579 (3) - 8240 (1) - 8239 (1) - 6141 (1) - 4556 (1) - 4230 (1) - 3605 (1) 3594 (1) - 1752 (1) - 1267 (1) - 1082 (1)

TCP Destination Port (14 items) 21 (ftp) (6) - 22 (ssh) (4) - 1039 (3) - 1038 (3) - 1037 (3) - 23 (telnet) (3) - 80 (http) (2) - 6667 (irc) (1) - 6346 (gnuetella) (1) - 1863 (msn im) (1) - 1433 (ms-sql-s) (1) - 443 (https) (1) - 110 (pop3) (1) - 81 (1)

UDP Source Port (20 of 3+ items) 1589 (3) - 1047 (3) - 138 (netbios-dgm) (3) - 62131 (1) - 62129 (1) - 62128 (1) - 62127 (1) - 62126 (1) - 62124 (1) - 62122 (1) - 62121 62120 (1) - 62119 (1) - 62117 (1) - 62116 (1) - 62115 (1) - 62113 (1) - 62112 (1) - 62111 (1) - 62110 (1) [more]

UDP Target Port (5 items) 53 (domain) (20) - 1047 (3) - 138 (netbios-dgm) (3) - 69 (tftp) (3) - 2236 (1)

Source City (1 item) atlanta (1)

Destination City (7 items) fairfax (20) - mountain view (2) - san jose (1) - miami (1) - macon (1) - longmont (1) - andover (1)

Source Organization (1 item) quality technology services, llc. (1)

Page 2 of 3

9/26/2020res://C:\Program Files\RSA\NetWitness Investigator 11.4\NwInvestigator.exe/153

Destination Organization (7 items) cox communications (21) - intermedia.net (2) - ovh sas (1) - microsoft hosting (1) - kampung communications (1) - clearblue technologies (1) - centurylink (1)

Source Country (1 item) united states (1)

Destination Country (2 items) united states (27) - france (1)

Top Level Domains (2 items) net (23) - com (23)

User Account (4 items) student (6) - sa (1) - joann.sample (1) - bobby (1)

The following report(s) contain 0 results for the active query: ATT&CK Tactic, ATT&CK Technique, Certificate Thumbprint, Certificate Common Name, Certificate Subject, Certificate Authority, Function, Source E-mail Address, Destination E-mail Address, Machine State, Registry Key, Registry Value, File Entropy, File Type, File Category, File Category Source, File Category Destination, Filename Source, Filename Destination, Source File Directory, Target File Directory, Source Checksum, Target Checksum, Task Name, File Vendor, Accesses, Domain OU, Host Role, Owner, User Account, Source User Account, Destination User Account, Organization, Logon Type, Description of Logon Type, Behaviors of Compromise, Indicators of Compromise, Enablers of Compromise, Event Category Name, Event Activity, Event Outcome, Event Subject, Event Theme, File Analysis, Service Analysis, Session Analysis, Investigation Category, Investigation Context, Autorun Type, Category, Checksum, Context, Context Destination, Context Source, Device Name, Errors, Event Description, Event Hostname, Reference ID, Event Source, Event State, Event Type, Filter, Found Search, Languages, Object Name, Object Type, Operating System, Policy Name, Process, Parameter, Source Parameter, Target Parameter, Result, Result Code, Risk, Server Application, TCP Flags Description, Agent Id, User Agent, Versions, Virus Name, Traffic Flow Direction, Source Domain, Domain, Source Hostname, Destination Hostname, Hostname Originating, Source Interface, IP Address Originating, Source IPv6 Address, Destination IPv6 address, IPv6 Aliases, IP Address v6 Originating, Network Name, Non-Protocol Specific Source Port, Non-Protocol Specific Destination Port, Port Generic, Port Translated Source, Port Translated Destination, Service Name, Decoder Source, Event Source Group, Device Class, Device Host, Device IP, Device IPv6, Device Type, Event Relay IPv4 Address, Event Relay IPv6 Address, Collector ID, Message ID, Parse Error, Source Filename, Alerts, Threat Category, Threat Description, Threat Source, Event Time, Time Start, Time Zone, FQDN, Access Point, JA3 Fingerprint, JA3S Fingerprint, Active Directory Workstation Destination, Active Directory Workstation Source, Active Directory Domain Destination, Active Directory Domain Source, Active Directory Username Destination, Active Directory Username Source, Alert ID, Translated Destination Port, Event Classification, IP Address, Destination Port, IP Source Port, IP V6 Protocol, Network Port, Originating IP Address, Device Address, Risk: Informational, Risk: Suspicious, Risk: Warning, Site Category, Translated Source Port, Directory Path, Directory Path Source, Directory Path Destination, All Domain Keys, All Event Catagorization Keys, All Email Address Keys, All Ethernet Address Keys, All Analysis Keys, All Filename Keys, All IPv4 Keys, All IPv6 Keys, All Port Keys, All Source Port Keys, All Destination Port Keys, All User Keys, All Hostname Keys, All Checksum Keys, All Directory Keys, All Client Keys, All Context Keys, All Directory Path Keys, All Parameter Keys

Page 3 of 3

9/26/2020res://C:\Program Files\RSA\NetWitness Investigator 11.4\NwInvestigator.exe/153