Investigative analysis
Fordham University CISC 6680 Intrusion Detection & Network Forensics
Professor: Ravi Tanikella
Packet Analysis Assignment 3
Scenario You are working as an analyst reviewing suspicious network events at Fictitious Corporations’ Security Operations Center (SOC). Things have been quiet for a while. However, you notice several alerts occur within minutes of each other on separate hosts.
Your were able to retrieve a pcap of network traffic, and you have a list of Snort and Suricata events from the activity. You are also able to capture the following image
Your Report Submission
You'll need to write a report. Your report should include with detailed screen shots with marking identifying each of the items listed below.
• When did the event take place? E.G. Date and time range of the traffic in question. • IP address, MAC address, and host name for each of the computers. • Description of the activity for each of the computers (what happened, if the host became
infected, any details, etc.). • A screenshot for each infected host with filters applied so you only see traffic for that host • Infection vector and payload if present. Correlate with all files to confirm your findings. • A conclusion with recommendations for any follow-up actions.